2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)
2026 FIFA World Cup Phishing Campaign (TL-2026-0569), also tracked as FIFA World Cup 2026 Typosquat Network, is a high-severity phishing campaign, first published 2026-05-22. It has no confirmed attribution, affects FIFA fifa.com brand and ticketing portal (impersonated), maps to 25 MITRE ATT&CK techniques (T1041, T1056, T1056.003), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-0569
- Threat ID
- TL-2026-0569
- Also known as
- FIFA World Cup 2026 Typosquat Network, Flare 2026 World Cup Phishing Report
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-05-22
- Last reviewed
- 2026-05-22
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumer, retail, sports-entertainment, ticketing, ecommerce, hospitality, financial-services
- Target regions
- Global, North America, Europe, Latin America, Middle East, Asia
- Detection rules
- 9
- Indicators of compromise
- 26
Flare researchers documented a distributed phishing ecosystem targeting the 2026 FIFA World Cup that has expanded to 222 typosquatting domains (206 active) hosted across 203 unique IP addresses — nearly 2.8x the domains and 14x the hosting footprint of an earlier 79-domain report. Four distinct operator clusters share fifa.com page templates that serve fake ticketing portals, copycat stores, and credential-harvesting login forms that silently accept any input. 80.6% of campaign IPs sit behind Cloudflare as a reverse proxy and Cloudflare has independently flagged at least three campaign domains as suspected phishing.
How 2026 FIFA World Cup Phishing Campaign works
PHISHING ECOSYSTEM OVERVIEW
On May 22, 2026 Flare published an expanded analysis (shared with Cyber Security News) of an ongoing phishing operation built around the 2026 FIFA World Cup tournament. Where an earlier report identified 79 typosquatting domains on 14 hosting IPs, the broadened dataset — built from passive DNS, Certificate Transparency (CT) logs, and WHOIS enrichment — now confirms 222 domains, 206 currently active, resolving to 203 unique IP addresses. The operation is fueled by tournament-driven urgency: fans searching for tickets, merchandise, and official streaming hubs are funneled to convincing fifa.com clones that harvest credentials, payment card data, and personal information.
FOUR OPERATOR CLUSTERS (SHARED TEMPLATES, INDEPENDENT INFRASTRUCTURE)
Flare's clustering analysis (page-template fingerprints, TLS certificate reuse, WHOIS overlaps, registrar choice) identifies four distinct operator groups that share the same phishing kit but operate independently:
- Cluster A — The largest cluster (~86 domains). Domains directly mimic the fifa.com address using typosquatting tricks: hyphenated variants (fifa-com.store, fifa-com.site, fifa-com.shop, fifa-com.one), prefix/suffix mutations (www-fifaworldcup.*), and TLD swaps (.shop, .site, .store, .one, .vip, .top). Heavy reliance on GNAME.COM and GoDaddy registrars. - Cluster B — 14 .shop domains with generic, non-FIFA names (e.g. dustdigitalsw.shop, originally registered 2015 and repurposed for World Cup fraud) that nonetheless serve the same fraudulent landing page. Registrant identity is the placeholder 'Bill John / Newark'. Designed to evade brand-keyword monitoring that only watches fifa* lookalikes. - Cluster C — 3 .cn ccTLD domains (https-fifa.cn, ww-fifaweb.cn, fifawebsite.cn) all registered March 28, 2026 via a single Gmail address. The .cn footprint and Gmail registration pattern suggest a China-based independent actor working with the same shared scam kit. - Cluster D — Uses the fake registrant organization '888 shi jie bei guan li you xian gong si' ('888 World Cup Management Co Ltd') and openly references the tournament. Observed domains include www-fifaworldcup.one, www-fifaworldcup.vip, and fifa-com.one.
PAGE TEMPLATES AND VICTIM EXPERIENCE
Victims arriving at any cluster's domain receive one of three template variants: (1) a fake ticketing portal that mimics the fifa.com ticketing UI and collects PII plus payment card data at checkout; (2) a fake merchandise store impersonating the official FIFA Store; (3) a credential harvest form that silently accepts any input — usernames or emails are stored regardless of password validity, and victims are redirected to the legitimate fifa.com to mask the theft. All templates load the same shared CSS and JavaScript assets, leaving a consistent DOM-level fingerprint across clusters.
HOSTING AND REGISTRATION PATTERNS
80.6% of campaign IPs sit behind Cloudflare's reverse proxy, hiding origin servers and complicating takedown coordination. Five hosting IPs each front multiple campaign domains, with 38.246.249.74 alone hosting 8 separate fraudulent sites. GNAME.COM (~94 domains, 42%) and GoDaddy (~42 domains, 19%) collectively control 61% of campaign domains — Flare recommends prioritizing bulk abuse reporting to those two registrars as the fastest takedown lever. Registration velocity is sharply increasing: 52 domains in the first 17 days of April 2026 with new domains appearing almost daily, and three concentrated registration dates (March 27 2026, March 28 2026, November 17 2025) account for >36% of all known registrations.
TLS CERTIFICATE REUSE AS DETECTION SIGNAL
Four SHA-1 certificate fingerprints are reused across multiple campaign domains (one cert fronts 3 domains, three more front 2 domains each). This certificate reuse is a strong cross-domain pivot for hunters: any newly observed CT log entry sharing one of these fingerprints can be treated as part of the active campaign.
INDEPENDENT VALIDATION
Cloudflare has independently flagged three campaign domains (fifa-com.store, fifa-com.site, fifa-com.shop) as suspected phishing, validating the malicious classification through a third party that controls a large slice of the campaign's edge infrastructure.
DEFENSIVE GUIDANCE
Detection must operate at the campaign level rather than domain by domain — naming patterns alone miss Cluster B's generic .shop domains. Effective controls combine: (1) brand-keyword and IDN-homoglyph monitoring against fifa*, *fifa*, *worldcup* lookalikes plus the .one/.vip/.top/.shop/.site/.store TLDs; (2) Certificate Transparency monitoring keyed on the four shared SHA-1 fingerprints; (3) WHOIS-based alerting on registrant artifacts ('Bill John', 'Newark', '888 World Cup Management', the two Gmail addresses); (4) network blocking of the five high-density hosting IPs and bulk abuse reporting to GNAME.COM and GoDaddy; (5) DNS RPZ entries for the confirmed domains and category-level filtering on newly registered domains containing fifa/worldcup tokens.
MITRE ATT&CK techniques used in TL-2026-0569
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Collection
Credential Access
T1056.003 Input Capture: Web Portal Capture; T1539 Steal Web Session Cookie
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090.004 Proxy: Domain Fronting; T1102 Web Service
Initial Access
T1566 Phishing; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service
Resource Development
T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.002 Acquire Infrastructure: DNS Server; T1583.004 Acquire Infrastructure: Server; T1583.006 Acquire Infrastructure: Web Services; T1585.002 Establish Accounts: Email Accounts; T1588.004 Obtain Capabilities: Digital Certificates; T1608.001 Upload Malware; T1608.004 Stage Capabilities: Drive-by Target; T1608.005 Stage Capabilities: Link Target
Reconnaissance
T1589 Gather Victim Identity Information; T1589.001 Gather Victim Identity Information: Credentials; T1589.002 Gather Victim Identity Information: Email Addresses
Impact
Affected products and versions in 2026 FIFA World Cup Phishing Campaign
- FIFA — fifa.com brand and ticketing portal (impersonated)
Vulnerable versions: all customer-facing properties including ticketing, store, accounts - Cloudflare — Reverse Proxy / CDN (abused as origin-hiding layer)
Vulnerable versions: any tenant accepting the operator''s sign-ups - GNAME.COM — Domain Registrar (abused for ~94 campaign domains)
Vulnerable versions: bulk registration without strict KYC - GoDaddy — Domain Registrar (abused for ~42 campaign domains)
Vulnerable versions: bulk registration channel
Remediation for 2026 FIFA World Cup Phishing Campaign
Immediate actions
- Block the five high-density campaign hosting IPs (38.246.249.74, 154.39.81.213, 148.178.16.48, 154.86.0.33, 104.225.235.49) at the egress proxy and firewall
- Add Cloudflare-flagged domains (fifa-com.store, fifa-com.site, fifa-com.shop) and Cluster C/D domains (https-fifa.cn, ww-fifaweb.cn, fifawebsite.cn, www-fifaworldcup.one, www-fifaworldcup.vip, fifa-com.one) to DNS RPZ and web filtering categories
- Submit bulk abuse reports to GNAME.COM (registrar of ~94 domains, 42% of campaign) and GoDaddy (~42 domains, 19%) to accelerate takedown of the largest share of the network
- Push a brand-awareness alert to employees and customers: official FIFA ticketing is only fifa.com/tickets — flag any *.shop / *.site / *.store / *.one / *.vip / *.top alternatives
Workarounds
- Disable URL preview rewriting that strips hyphenation — hyphens in suspicious domains (e.g. fifa-com.store) are the primary typosquatting signal and must remain visible
- Force-route DNS through a filtered resolver (e.g. Cloudflare for Families, Quad9, internal RPZ) that consumes newly-registered-domain and phishing feeds
- Apply browser policy to block downloads from newly-registered domains and require explicit click-through on uncategorized sites referencing payment forms
Longer-term hardening
- Deploy Certificate Transparency monitoring keyed on the four shared SHA-1 certificate fingerprints (1b02595c..., fc1db8de..., 3b8bb763..., fb0498ab...) to alert on every new domain that reuses those certificates
- Stand up WHOIS/registration alerting on registrant indicators: organization '888 shi jie bei guan li you xian gong si' / '888 World Cup Management Co Ltd', contact 'Bill John / Newark', the two associated Gmail registrant addresses
- Implement newly-registered-domain (NRD) blocking or strict scoring for domains <30 days old containing fifa/worldcup/2026 tokens, especially under .shop/.site/.store/.one/.vip/.top/.cn TLDs
- Integrate page-template fingerprinting (DOM hash / shared JS-CSS asset hashes) into the brand-protection feed so Cluster B's non-FIFA-keyword domains are caught by visual/structural similarity
- Enroll the organization in FIFA's official brand-protection program and forward confirmed domains to the FIFA legal/anti-fraud channel for coordinated takedown
Weaknesses (CWE) in 2026 FIFA World Cup Phishing Campaign
CWE-290, CWE-451, CWE-601, CWE-1021
Timeline of 2026 FIFA World Cup Phishing Campaign
- First major domain registration spike — this date alone accounts for a large share of campaign domains (one of three dates representing >36% of all registrations).
- Second concentrated registration day — combined with March 28 and Nov 17 2025 these three dates account for >36% of all known campaign domain registrations.
- Cluster C — three .cn domains (https-fifa.cn, ww-fifaweb.cn, fifawebsite.cn) registered on this single day via one Gmail address, indicating a China-based independent operator.
- Start of the first-17-days-of-April velocity window during which 52 new campaign domains were registered, with new additions appearing almost daily.
- End of the documented 17-day April registration window. Cumulative count for the window reaches 52 new domains.
- Earlier Flare investigation publicly documented 79 typosquatting domains across only 14 hosting IPs — the baseline before expanded passive DNS / CT log enrichment.
- Threadlinqs Intelligence Researcher ingests the campaign as TL-2026-0569 for detection engineering and brand-protection distribution.
- Cloudflare independently flags three campaign domains (fifa-com.store, fifa-com.site, fifa-com.shop) as suspected phishing, providing third-party validation of the malicious classification.
- Flare publishes the expanded report (shared with Cyber Security News): 222 domains, 206 active, 203 unique IPs, 80.6% Cloudflare-fronted, four operator clusters identified.
- As of 2026-05-29, this FIFA World Cup 2026 typosquat phishing ecosystem is intensely active and escalating ahead of the June 11 kickoff, with the FBI/IC3 issuing a PSA (May 27) and fresh Flare, Group-IB, Malwarebytes and ESET reporting (May 22-28) showing growth, not takedown. No arrests, sinkholing, or registrar cleanup have neutralized it; new lookalike domains appear almost daily.
Sources cited for 2026 FIFA World Cup Phishing Campaign
- World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses
- Flare Threat Research — FIFA World Cup 2026 Phishing Ecosystem (report shared with Cyber Security News)
- FIFA Official — Ticketing Portal (legitimate brand reference)
- Cloudflare Phishing Protection — Reporting URLs
- ICANN — Domain Abuse Reporting
- APWG — Anti-Phishing Working Group Reporting
- MITRE ATT&CK T1566 Phishing
- MITRE ATT&CK T1583.001 Acquire Infrastructure: Domains
Threats related to 2026 FIFA World Cup Phishing Campaign
- GHOST STADIUM — FIFA World Cup 2026 Phishing Operation: 4,300+ Fraudulent Domains and 300+ Cloned fifa.com PingIdentity SSO Credential-Theft Sites
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs
- Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brands
- Winter Olympics 2026 Domain Impersonation and Phishing Infrastructure Campaign
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains
- AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass
Detection coverage for TL-2026-0569
As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0569 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.