Hackers Register Domains to Target 2026 FIFA World Cup in Cyberattack
## Cybersecurity: Malicious Domain Registrations for FIFA World Cup 2026
Cybersecurity: Malicious Domain Registrations for FIFA World Cup 2026
An investigation has identified a significant increase in malicious domain registrations associated with the FIFA World Cup 2026, with cybercriminals preparing well in advance to exploit the event.
Research conducted by PreCrime Labs, part of BforeAI, indicates that fraudulent domains are being systematically registered to exploit the global interest in the 2026 FIFA World Cup.
Conducted in August 2025, the study analyzed 498 suspicious domains containing terms related to FIFA, football, and the World Cup, revealing a sophisticated strategy by threat actors.
The upcoming event, hosted across the United States, Canada, and Mexico, presents a notable target due to its scale and audience.
It was observed that domains are being registered well ahead of major sporting events, allowing them to appear more legitimate when attacks are launched. Domains for events as distant as 2030 and 2034 have already been registered, showing long-term planning by these actors.
The investigation identified alarming patterns in domain registration. A notable spike was recorded between August 8-12, 2025, with approximately 299 domains registered within five days.
The primary registrars involved include GoDaddy.com LLC, Namecheap Inc., Gname.com Pte. Ltd., Dynadot Inc., and Wix.
The upcoming event, hosted across the United States, Canada, and Mexico, presents a notable target due to its scale and audience.
Domains specifically targeted certain themes, with 173 containing "FIFA," 212 using "football," and 129 incorporating "worldcup." Some domains also referenced host cities such as Dallas, Atlanta, Kansas City, Philadelphia, and Texas.
Key threat categories identified include:
Merchandise Fraud: 56 domains are linked to counterfeit World Cup merchandise. Illegal Streaming: 55 domains offer unauthorized access to World Cup matches, often delivering malware. Gambling Exploitation: 32 domains concern betting and gambling, some using "generator scam" formats.
Technical Infrastructure and Evasion Tactics
Threat actors employ sophisticated evasion techniques, with .com extensions being the most common (58.9%), followed by .online (7.1%) and .football (4.7%).
Typosquatting strategies include domains like "fifaworldcupstadiucom" designed to exploit user errors.
Geographic targeting is evident, with domains tailored to specific regions and languages, including Chinese and Spanish content.
Some domains are registered years in advance, such as 41 for 2026, 10 for 2030, and one for 2034, allowing time to establish legitimacy.
The cryptocurrency angle involves fake "FIFA coin" ICOs, with fabricated statistics to create false legitimacy.
Security experts advise FIFA, sponsors, and host cities to implement proactive domain monitoring for suspicious registrations and consider defensive domain registration across known malicious domains.
Fans should purchase tickets through official channels, avoid unofficial streaming sites, and be cautious of unsolicited messages related to the World Cup.
These insights highlight the evolving cybersecurity landscape around major sporting events, calling for vigilance from all stakeholders.
Based on reporting by GBHackers.
