2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare) — Threadlinqs Intelligence
As of 2026-05-30, 2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare) is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0569 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Flare researchers documented a distributed phishing ecosystem targeting the 2026 FIFA World Cup that has expanded to 222 typosquatting domains (206 active) hosted across 203 unique IP addresses —
PHISHING ECOSYSTEM OVERVIEW
On May 22, 2026 Flare published an expanded analysis (shared with Cyber Security News) of an ongoing phishing operation built around the 2026 FIFA World Cup tournament. Where an earlier report identified 79 typosquatting domains on 14 hosting IPs, the broadened dataset — built from passive DNS, Certificate Transparency (CT) logs, and WHOIS enrichment — now confirms 222 domains, 206 currently active, resolving to 203 unique IP addresses. The operation is fueled by tournament-driven urgency: fans searching for tickets, merchandise, and official streaming hubs are funneled to convincing fifa.com clones that harvest credentials, payment card data, and personal information.
FOUR OPERATOR CLUSTERS (SHARED TEMPLATES, INDEPENDENT INFRASTRUCTURE)
Flare's clustering analysis (page-template fingerprints, TLS certificate reuse, WHOIS overlaps, registrar choice) identifies four distinct operator groups that share the same phishing kit but operate independently:
- Cluster A — The largest cluster (~86 domains). Domains directly mimic the fifa.com address using typosquatting tricks: hyphenated variants (fifa-com.store, fifa-com.site, fifa-com.shop, fifa-com.one), prefix/suffix mutations (www-fifaworldcup.*), and TLD swaps (.shop, .site, .store, .one, .vip, .top). Heavy reliance on GNAME.COM and GoDaddy registrars.
- Cluster B — 14 .shop domains with generic, non-FIFA names (e.g. dustdigitalsw.shop, originally registered 2015 and repurposed for World Cup fraud) that nonetheless serve the same fraudulent landing page. Registrant identity is the placeholder 'Bill John / Newark'. Designed to evade brand-keyword monitoring that only watches fifa* lookalikes.
- Cluster C — 3 .cn ccTLD domains (https-fifa.cn, ww-fifaweb.cn, fifawebsite.cn) all registered March 28, 2026 via a single Gmail address. The .cn footprint and Gmail registration pattern suggest a China-based independent actor working with the same shared scam kit.
- Cluster D — Uses the fake registrant organization '888 shi jie bei guan li you xian gong si' ('888 World Cup Management Co Ltd') and openly references the tournament. Observed domains include www-fifaworldcup.one, www-fifaworldcup.vip, and fifa-com.one.
PAGE TEMPLATES AND VICTIM EXPERIENCE
Victims arriving at any cluster's domain receive one of three template variants: (1) a fake ticketing portal that mimics the fifa.com ticketing UI and collects PII plus payment card data at checkout; (2) a fake merchandise store impersonating the official FIFA Store; (3) a credential harvest form that silently accepts any input — usernames or emails are stored regardless of password validity, and victims are redirected to the legitimate fifa.com to mask the theft. All templates load the same shared CSS and JavaScript assets, leaving a consistent DOM-level fingerprint across clusters.
HOSTING AND REGISTRATION PATTERNS
80.6% of campaign IPs sit behind Cloudflare's reverse proxy, hiding origin servers and complicating takedown coordination. Five hosting IPs each front multiple campaign domains, with 38.246.249.74 alone hosting 8 separate fraudulent sites. GNAME.COM (~94 domains, 42%) and GoDaddy (~42 domains, 19%) collectively control 61% of campaign domains — Flare recommends prioritizing bulk abuse reporting to those two registrars as the fastest takedown lever. Registration velocity is sharply increasing: 52 domains in the first 17 days of April 2026 with new domains appearing almost daily, and three concentrated registration dates (March 27 2026, March 28 2026, November 17 2025) account for >36% of all known registrations.
TLS CERTIFICATE REUSE AS DETECTION SIGNAL
Four SHA-1 certificate fingerprints are reused across multiple campaign domains (one cert fronts 3 domains, three more front 2 domains each). This certificate reuse is a strong cross-domain pivot for hunters: any newly observed CT log entry sharing one of these fingerprints can be treated as part of the active campaign.
INDEPENDENT VALIDATION
C
Weaknesses (CWE)
CWE-290, CWE-451, CWE-601, CWE-1021
Target sectors: consumer, retail, sports-entertainment, ticketing, ecommerce, hospitality, financial-services
Target regions: Global, North America, Europe, Latin America, Middle East, Asia
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1589.001, T1589.002, T1583, T1583.001, T1583.002, T1583.004, T1583.006, T1585.002, T1588.004