← FIFA World Cup 2026 Crypto Phishing and Typosquatting Infrastructure1 decision on this page
Audit log
Every state-changing event for FIFA World Cup 2026 Crypto Phishing and Typosquatting Infrastructure: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-09 12:35:38ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
Ei79r9weWmbR…CZD1RbFksha256 → base58
verifying row…canonical bytes (29485 B) ▸
{"actor":"system:backfill","investigation_id":"5566a9ec-65a2-4c42-a2f4-af1d01a2beee","kind":"publish","page_slug":"fifa-world-cup-2026-crypto-phishing-and-typosquatting-infrastructure","published_at":"2026-08-09T12:35:38.378Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"FIFA World Cup 2026 Crypto Phishing and Typosquatting Infrastructure","sections":[{"content":"Between January and May 2026, FortiGuard Labs documented more than 13,000 World Cup-themed domains registered, with approximately 8.8% classified as malicious or suspicious. A separate count by Intel 471 and Help Net Security placed the total as high as 19,000 FIFA-themed domains created since January 2026 alone. Group-IB's GHOST STADIUM investigation identified 4,300+ fraudulent FIFA domains registered since August 2025, of which approximately 300 were actively serving malicious content and roughly 3,800 remained parked and dormant, pre-positioned for future activation. CybelAngel identified 344 domains specifically cloning the official FIFA 2026 ticketing website, of which 125 were live as of June 9, 2026. In the single month of March 2026, 78 domain registrations were recorded; on April 29 alone, 30 new registrations were observed in a single day. The FBI's IC3 PSA (Alert I-052726-PSA, issued May 27, 2026) listed more than 40 fraudulent domains by name, including fifa[.]cab, fifa[.]pink, fifa[.]click, fifa-2026[.]xyz, fifaworldcup26[.]sale, worldcup2026-tickets.com[.]mx, and 2026fifaworldcuptickets[.]online.","heading":"Scale of Domain Infrastructure","severity":"critical","sources":[{"credibility":2,"name":"FortiGuard Labs: Cybercriminals Are Targeting the FIFA World Cup 2026","type":"research","url":"https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026"},{"credibility":2,"name":"Help Net Security: Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup","type":"news_article","url":"https://www.helpnetsecurity.com/2026/06/08/fifa-world-cup-cyber-threats/"},{"credibility":2,"name":"Group-IB: GHOST STADIUM — The Score: Billions At Stake At The World's Largest Football Tournament","type":"research","url":"https://www.group-ib.com/blog/ghost-stadium-football-fraud/"},{"credibility":2,"name":"CybelAngel: FIFA World Cup 2026 Fraud — 468 IOCs and Four Active Threat Vectors","type":"research","url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"credibility":1,"name":"FBI IC3: PSA I-052726-PSA — Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup","type":"regulatory","url":"https://www.ic3.gov/PSA/2026/PSA260527"}]},{"content":"The most technically sophisticated cluster in this infrastructure has been designated GHOST STADIUM by Group-IB and independently analyzed by Hunt.io. The actor is assessed as Chinese-speaking and financially motivated, first observed in November 2025. The campaign deploys a custom React-based single-page phishing application built on Layui 2.7.6, a Chinese open-source UI library virtually unknown outside the Chinese developer community. The kit replicates FIFA's PingIdentity SSO authentication flow with near-pixel-perfect fidelity, including use of the legitimate FIFA SSO client_id (35072598-fc20-4142-a469-1b940db47e6f) copied directly from the official site. The kit auto-detects browser locale and supports 11 languages plus three Chinese variants. After harvesting credentials, the kit requests password reset permissions (_p1:reset:userPassword_), locking victims out of their legitimate accounts, then silently redirects to the real FIFA website to disguise the attack as a successful login. Infrastructure analysis identified 14 hosting IP nodes, shared SSL certificates connecting the domain cluster, and registration waves concentrated around November 17, 2025, and March 20-31, 2026. Registrars identified include Beijing Lanhai Jiye Technology, Alibaba Cloud/HiChina, and GoDaddy. Operator code contains simplified Chinese comments including the string for 'language detection.' Meta Pixel IDs 927432823410218, 1842358649811605, and 1569148414168343 are shared across the fraudulent domain cluster, linking the sites to a single advertising and tracking operation. Group-IB estimated 47,400 alleged victims and projected losses from premium ticket fraud alone of between $71 million and $474 million USD.","heading":"GHOST STADIUM Threat Actor and Phishing Kit","severity":"critical","sources":[{"credibility":2,"name":"Group-IB: GHOST STADIUM — The Score: Billions At Stake At The World's Largest Football Tournament","type":"research","url":"https://www.group-ib.com/blog/ghost-stadium-football-fraud/"},{"credibility":2,"name":"Hunt.io: Chinese-speaking Operators Clone FIFA's World Cup 2026 Ticketing Site","type":"research","url":"https://hunt.io/blog/fifa-world-cup-2026-ticket-phishing-kit"},{"credibility":2,"name":"The Hacker News: FIFA World Cup 2026 Scams Are Already Live","type":"news_article","url":"https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html"},{"credibility":2,"name":"Cybersecurity News: GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans With 300+ Fake Domains","type":"news_article","url":"https://cybersecuritynews.com/ghost-stadium-phishing-campaign-targets-fifa-world-cup-fans/amp/"}]},{"content":"Cryptocurrency payment demands are integrated across multiple layers of the fraud infrastructure. TRM Labs identified four cryptocurrency wallet addresses directly associated with World Cup scam operations as of mid-2026: a Polygon address (also deployed on Ethereum) that received approximately $1,562, primarily on April 1, 2026; a Bitcoin address attached to a live phishing site with no confirmed victim payments recorded at the time of reporting; and two additional addresses linked to fixed-match betting fraud that routed small payments across four transaction windows between January and May 2026 into custodial exchange deposit accounts. Fund flows observed by TRM Labs move proceeds from Polygon into Tron via cross-chain bridges, and from Bitcoin into custodial exchange accounts for cash-out. GHOST STADIUM operators accepted payments through five channels: direct payment card capture using order ID format 'FWC2026XXXXXXXXX'; third-party gateways (pay[.]zfxupi[.]net, offering Cash App and Chime); P2P money transfers (documented Chime cashtag $Paramjit-Bains; Nequi number 3202059757); region-specific processors for Mexico; and cryptocurrency conversions via Alchemy Pay converting $195 USD card payments into approximately 185 USDT on Binance Smart Chain. Forcepoint X-Labs identified a separate crypto wallet drainer campaign impersonating the Stake.com gambling platform under the lure of a 'World Cup 2026 Token Farming' event. Phishing emails routed victims through Vercel (a legitimate development platform) as an intermediary to bypass email security filters, with the final destination at hxxps://get[.]rpc-stake[.]com/farm — a page that solicited cryptocurrency wallet connections and executed irreversible asset transfers once access was granted. CybelAngel documented that all four major fraud vectors (ticketing, travel, betting, and employment) utilized irreversible cryptocurrency payments — Bitcoin, Litecoin, and Monero — specifically to eliminate chargeback possibilities. The site usavisaworldcup[.]com, which fraudulently solicited passport scans from visitors seeking a non-existent 'World Cup visa,' explicitly demanded cryptocurrency payments; the same IP address hosted at least 20 additional event-themed malicious domains.","heading":"Cryptocurrency Payment Integration and Wallet Drainers","severity":"critical","sources":[{"credibility":2,"name":"TRM Labs: Tracking Crypto Scammers Ahead of the 2026 World Cup","type":"research","url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"credibility":2,"name":"Forcepoint X-Labs: World Cup 2026 Scams — Phishing, Crypto Drainers and Ticket Fraud","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"CybelAngel: FIFA World Cup 2026 Fraud — 468 IOCs and Four Active Threat Vectors","type":"research","url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"credibility":2,"name":"KuCoin: Crypto Scams Target 2026 FIFA World Cup with Fake Tickets and Memecoins","type":"news_article","url":"https://www.kucoin.com/news/flash/crypto-scams-target-2026-fifa-world-cup-with-fake-tickets-and-memecoins"}]},{"content":"Two Android banking trojans were identified spreading through fake World Cup streaming and IPTV applications. The first, Massiv, targets financial and cryptocurrency applications. The second, Perseus, is built on leaked Cerberus source code; it reads note-taking applications for saved passwords and cryptocurrency wallet recovery phrases, exploits Android accessibility services to overlay fake banking login screens, intercepts SMS-based one-time passwords, and exfiltrates credentials. A third Android application, 'BTMOB,' was distributed through fake streaming content portals promoting alleged World Cup broadcast access. Additionally, the malware family 1xbet.exe was observed in associated infrastructure, showing signs of persistence, encrypted communications, and alleged ransomware behavior. Infostealers including Vidar, LummaC2, and RedLine are documented in stealer malware logs connected to this event: FortiGuard Labs identified 4,600+ URLs associated with FIFA credentials in stealer logs, 260+ FIFA employee credentials compromised, and an estimated 270,000+ user and fan credentials from FIFA-related websites. Group-IB documented approximately 130,000 infostealer logs containing FIFA references from mass malware campaigns. Approximately 2,513 FIFA account credential pairs were found circulating in dark-web markets priced at $5 to $50 per pair. Arctic Wolf Labs documented an adversary-in-the-middle (AiTM) phishing kit targeting accounts that defeats conventional MFA by relaying one-time codes in real time, including Microsoft Authenticator number-match push notifications.","heading":"Android Banking Malware and Seed-Phrase Theft","severity":"critical","sources":[{"credibility":2,"name":"The Hacker News: FIFA World Cup 2026 Scams Are Already Live","type":"news_article","url":"https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html"},{"credibility":2,"name":"FortiGuard Labs: Cybercriminals Are Targeting the FIFA World Cup 2026","type":"research","url":"https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026"},{"credibility":2,"name":"Arctic Wolf Labs: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup","type":"research","url":"https://arcticwolf.com/resources/blog/aitm-qr-code-phishing-and-infostealers-at-the-2026-fifa-world-cup/"},{"credibility":2,"name":"Help Net Security: Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup","type":"news_article","url":"https://www.helpnetsecurity.com/2026/06/08/fifa-world-cup-cyber-threats/"}]},{"content":"TRM Labs identified a 'World Cup Coin DApp' impersonation kit designed to drain cryptocurrency wallets by harvesting seed phrases, private keys, and wallet connection flows. A separate token, $WORLDCUP (listed on LBank as 'World Cup Commemorative Coin'), was framed as a fan-made project with explicit FIFA non-affiliation disclaimers and identified by TRM Labs as a standard pump-and-dump structure. A second token, WCUP (World Cup PvP), launched on June 10, 2026, reached approximately $50 million in market capitalization on its first day after promotion by multiple crypto influencers on X; the token's supply was reported to be 95% controlled by insiders, and the majority of promoting influencers allegedly did not disclose paid arrangements to their followers. Both token schemes were listed on lower-tier exchanges. Fund flows from scam operations in this category were observed moving across cross-chain bridges, consistent with a broader pattern documented by TRM Labs in which approximately $1.9 billion in scam-origin funds have historically been moved through bridges.","heading":"Memecoin and Fake Token Schemes","severity":"high","sources":[{"credibility":2,"name":"TRM Labs: Tracking Crypto Scammers Ahead of the 2026 World Cup","type":"research","url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"credibility":2,"name":"AMBCrypto: 2026 FIFA World Cup is now live, but so are crypto scams","type":"news_article","url":"https://ambcrypto.com/2026-fifa-world-cup-is-now-live-but-so-are-crypto-scams-heres-what-trm-labs-found/"},{"credibility":2,"name":"Bitcoin Foundation: FIFA World Cup Crypto Scams Started Before 2026 Tournament","type":"news_article","url":"https://bitcoinfoundation.org/news/crimes-and-fraud-news/fifa-world-cup-crypto-scams-started-before-2026-tournament-data-shows/"}]},{"content":"FortiGuard Labs identified more than 1,700 suspected FIFA-related impersonation accounts across social media platforms, with approximately 90% concentrated on Facebook and Instagram. Traffic from fraudulent domains is sourced through Facebook advertising, Telegram channels, WhatsApp, and manipulation of search engine results. CybelAngel documented a fake betting platform, '2026[.]com,' operating Telegram channels that posed as an official sports betting service and used fabricated withdrawal messages as social proof for potential victims. The travel and visa fraud category used TikTok (handle: visa.applications.usa) to amplify traffic to the usavisaworldcup[.]com credential and passport harvesting site. Criminal forum listings on dark-web marketplaces advertised World Cup tickets at 22% of face value in cryptocurrency. A network of 33 World Cup-themed merchandise scam domains was connected to approximately 2,500 online advertisements designed to impersonate official FIFA merchandise outlets.","heading":"Social Media Impersonation and Distribution","severity":"high","sources":[{"credibility":2,"name":"FortiGuard Labs: Cybercriminals Are Targeting the FIFA World Cup 2026","type":"research","url":"https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026"},{"credibility":2,"name":"CybelAngel: FIFA World Cup 2026 Fraud — 468 IOCs and Four Active Threat Vectors","type":"research","url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"credibility":2,"name":"Paubox: FIFA World Cup phishing wave hits 1,100 suspicious domains","type":"news_article","url":"https://www.paubox.com/blog/fifa-world-cup-phishing-wave-hits-1100-suspicious-domains"}]},{"content":"On April 27, 2026, a threat actor claiming links to ShinyHunters published an alleged data leak on a prominent cybercrime forum targeting the Asian Football Confederation (AFC) and Al Nassr FC. The alleged dataset contains passport scans, contracts, email records, and AFC registration files spanning approximately 69,000 players and 81,000 staff members, for a total of approximately 150,000 affected records. The compromised data creates a high-value package for targeted social engineering, financial fraud, and impersonation attacks, including against athletes who are citizens of AFC member nations competing in the 2026 World Cup (South Korea, Japan, Australia, Iran, Saudi Arabia). This breach is alleged; neither AFC nor Al Nassr FC had made a public confirmation of the full scope as of reporting. Separately, FortiGuard Labs documented 1,500+ FIFA employee records in historical breach datasets unrelated to the April 2026 incident, and more than 260 FIFA employee credentials specifically identified in active stealer malware logs.","heading":"Associated Data Breaches and Credential Markets","severity":"high","sources":[{"credibility":2,"name":"TechRadar: Hackers allegedly breach Cristiano Ronaldo's Saudi team and AFC governing body","type":"news_article","url":"https://www.techradar.com/pro/security/is-this-the-largest-breach-in-football-history-hackers-allegedly-breach-cristiano-ronaldos-saudi-team-and-afc-governing-body-leak-passports-contracts-and-emails-online"},{"credibility":2,"name":"SC Media: Asian Football Confederation reportedly suffers massive data breach","type":"news_article","url":"https://www.scworld.com/brief/asian-football-confederation-reportedly-suffers-massive-data-breach"},{"credibility":2,"name":"FortiGuard Labs: Cybercriminals Are Targeting the FIFA World Cup 2026","type":"research","url":"https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026"},{"credibility":2,"name":"Dataminr: Cyber Intel Brief — Al Nassr FC and AFC Database Allegedly Leaked","type":"news_article","url":"https://www.dataminr.com/resources/intel-brief/al-nassr-fc-and-afc-database-llegedly-leaked/"}]},{"content":"The FBI's Internet Crime Complaint Center (IC3) issued Public Service Announcement I-052726-PSA on May 27, 2026, formally warning consumers that cybercriminals are creating fraudulent websites impersonating FIFA to exploit World Cup fans. The FBI confirmed identification of at least 36 fraudulent domains spoofing legitimate FIFA websites and documented the use of typosquatting and alternative top-level domains as the primary technical method. The announcement specifically noted that these sites are designed to collect personally identifiable information including names, home addresses, phone numbers, email addresses, and banking information. The FBI explicitly noted that when fraud involves financial transactions, cryptocurrency addresses should be included in reports filed at ic3.gov. The AARP, FindLaw, and multiple consumer protection outlets have amplified the FBI warning targeting older demographics and international fans. No regulatory enforcement actions against identified operators had been publicly announced as of the reporting date.","heading":"FBI Warning and Regulatory Response","severity":"critical","sources":[{"credibility":1,"name":"FBI IC3: PSA I-052726-PSA — Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup","type":"regulatory","url":"https://www.ic3.gov/PSA/2026/PSA260527"},{"credibility":2,"name":"AARP: FBI Warns Soccer Fans About World Cup Ticket Scams","type":"news_article","url":"https://www.aarp.org/money/scams-fraud/world-cup-ticket-scams/"},{"credibility":2,"name":"Bitdefender: FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup","type":"news_article","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-fifa-scams-2026-world-cup"},{"credibility":2,"name":"Moneywise: FBI warns cybercriminals are spoofing FIFA's ticketing site to scam World Cup 2026 fans","type":"news_article","url":"https://moneywise.com/news/top-stories/fbi-warning-fifa-world-cup-2026-ticket-scams"}]},{"content":"A fourth fraud category documented by CybelAngel targets individuals seeking tournament-related employment. Attackers post fraudulent FIFA recruitment listings and direct applicants to counterfeit login pages designed to harvest Google and other credentials. The same phishing kit infrastructure used for ticket fraud has been re-skinned to impersonate Netflix, Spotify, Hilton, and UEFA recruitment portals. CybelAngel noted that task-scam reports as a share of all World Cup fraud have risen from 1.6% at Qatar 2022 to 38.8% by 2024, suggesting a structural shift in this category. Victims are typically enrolled in fake micro-task schemes, paid small initial amounts to build trust, and then pressured to deposit funds to unlock further earnings — a classic advance-fee structure.","heading":"Employment and Task Fraud","severity":"high","sources":[{"credibility":2,"name":"CybelAngel: FIFA World Cup 2026 Fraud — 468 IOCs and Four Active Threat Vectors","type":"research","url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"credibility":2,"name":"FortiGuard Labs: Cybercriminals Are Targeting the FIFA World Cup 2026","type":"research","url":"https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026"}]}],"sources_used":[{"credibility":1,"name":"FBI IC3 PSA I-052726-PSA — Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup","type":"regulatory","url":"https://www.ic3.gov/PSA/2026/PSA260527"},{"credibility":2,"name":"Group-IB: GHOST STADIUM — The Score: Billions At Stake At The World's Largest Football Tournament","type":"research","url":"https://www.group-ib.com/blog/ghost-stadium-football-fraud/"},{"credibility":2,"name":"FortiGuard Labs: Cybercriminals Are Targeting the FIFA World Cup 2026","type":"research","url":"https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026"},{"credibility":2,"name":"CybelAngel: FIFA World Cup 2026 Fraud — 468 IOCs and Four Active Threat Vectors","type":"research","url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"credibility":2,"name":"TRM Labs: Tracking Crypto Scammers Ahead of the 2026 World Cup","type":"research","url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"credibility":2,"name":"Hunt.io: Chinese-speaking Operators Clone FIFA's World Cup 2026 Ticketing Site","type":"research","url":"https://hunt.io/blog/fifa-world-cup-2026-ticket-phishing-kit"},{"credibility":2,"name":"The Hacker News: FIFA World Cup 2026 Scams Are Already Live","type":"news_article","url":"https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html"},{"credibility":2,"name":"Forcepoint X-Labs: World Cup 2026 Scams — Phishing, Crypto Drainers and Ticket Fraud","type":"research","url":"https://www.forcepoint.com/blog/x-labs/world-cup-2026-scams"},{"credibility":2,"name":"Help Net Security: Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup","type":"news_article","url":"https://www.helpnetsecurity.com/2026/06/08/fifa-world-cup-cyber-threats/"},{"credibility":2,"name":"Arctic Wolf Labs: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup","type":"research","url":"https://arcticwolf.com/resources/blog/aitm-qr-code-phishing-and-infostealers-at-the-2026-fifa-world-cup/"},{"credibility":2,"name":"TechRadar: Hackers allegedly breach Cristiano Ronaldo's Saudi team and AFC governing body","type":"news_article","url":"https://www.techradar.com/pro/security/is-this-the-largest-breach-in-football-history-hackers-allegedly-breach-cristiano-ronaldos-saudi-team-and-afc-governing-body-leak-passports-contracts-and-emails-online"},{"credibility":2,"name":"Cybersecurity News: GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans With 300+ Fake Domains","type":"news_article","url":"https://cybersecuritynews.com/ghost-stadium-phishing-campaign-targets-fifa-world-cup-fans/amp/"},{"credibility":2,"name":"Bitdefender: FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup","type":"news_article","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-fifa-scams-2026-world-cup"},{"credibility":2,"name":"AMBCrypto: 2026 FIFA World Cup is now live, but so are crypto scams — Here's what TRM Labs found","type":"news_article","url":"https://ambcrypto.com/2026-fifa-world-cup-is-now-live-but-so-are-crypto-scams-heres-what-trm-labs-found/"},{"credibility":2,"name":"Cybernews: FBI warns World Cup fans over fake FIFA ticket scams","type":"news_article","url":"https://cybernews.com/cybercrime/fbi-world-cup-fifa-ticket-scam-warning/"},{"credibility":2,"name":"SC Media: Asian Football Confederation reportedly suffers massive data breach","type":"news_article","url":"https://www.scworld.com/brief/asian-football-confederation-reportedly-suffers-massive-data-breach"},{"credibility":2,"name":"DeXpose: World Cup 2026 Threat Report — Scams and Access Flaw","type":"research","url":"https://www.dexpose.io/world-cup-2026-threat-report-scams-and-access-flaw/"},{"credibility":2,"name":"Malwarebytes: The 2026 World Cup scam economy is already running before the first whistle","type":"research","url":"https://www.malwarebytes.com/blog/threat-intel/2026/05/the-2026-world-cup-scam-economy-is-already-running-before-the-first-whistle"},{"credibility":2,"name":"Infosecurity Magazine: Thousands of Fake FIFA Domains Target World Cup Fans","type":"news_article","url":"https://www.infosecurity-magazine.com/news/ghost-stadium-fifa-world-cup-fraud/"},{"credibility":2,"name":"Fox News: FBI warns of fake FIFA World Cup 2026 ticket sites stealing fan data","type":"news_article","url":"https://www.foxnews.com/tech/world-cup-ticket-scams-target-desperate-fans"}],"summary":"A coordinated, multi-actor scam infrastructure emerged around the 2026 FIFA World Cup (hosted across Canada, Mexico, and the United States, June 11 to July 19, 2026), comprising more than 13,000 to 19,000 registered World Cup-themed domains of which approximately 8.8% have been flagged as malicious or suspicious. The infrastructure combines typosquatted FIFA domains, AI-generated fake ticketing portals, cryptocurrency wallet drainers, seed-phrase phishing kits, and Android banking trojans, with at least one threat actor cluster — designated GHOST STADIUM — attributed to Chinese-speaking operators. The FBI issued a formal public service announcement on May 27, 2026, warning consumers and reporting at least 36 confirmed fraudulent domains spoofing official FIFA web properties.","timeline":[{"date":"2025-08-01","event":"GHOST STADIUM begins registering fraudulent FIFA domains; Group-IB first observes the threat actor cluster","source":"Group-IB Blog","source_url":"https://www.group-ib.com/blog/ghost-stadium-football-fraud/"},{"date":"2025-11-17","event":"First major GHOST STADIUM domain registration wave identified by Hunt.io infrastructure analysis","source":"Hunt.io","source_url":"https://hunt.io/blog/fifa-world-cup-2026-ticket-phishing-kit"},{"date":"2026-01-01","event":"FortiGuard Labs begins observing rapid accumulation of World Cup-themed domain registrations; count reaches 13,000+ by May","source":"Fortinet FortiGuard Labs","source_url":"https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026"},{"date":"2026-03-20","event":"Second major GHOST STADIUM domain registration wave, March 20-31; 78 domain registrations recorded in March overall","source":"CybelAngel Threat Report","source_url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"date":"2026-04-01","event":"TRM Labs-tracked Polygon wallet address receives approximately $1,562 from fake ticketing scam victims","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/tracking-crypto-scammers-ahead-of-the-2026-world-cup"},{"date":"2026-04-27","event":"Threat actor claiming ShinyHunters affiliation publishes alleged AFC and Al Nassr FC database containing 150,000+ passport records and player contracts on a cybercrime forum","source":"TechRadar","source_url":"https://www.techradar.com/pro/security/is-this-the-largest-breach-in-football-history-hackers-allegedly-breach-cristiano-ronaldos-saudi-team-and-afc-governing-body-leak-passports-contracts-and-emails-online"},{"date":"2026-04-29","event":"Single-day peak: 30 fraudulent FIFA domain registrations observed in one day","source":"CybelAngel Threat Report","source_url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"date":"2026-05-27","event":"FBI IC3 issues PSA I-052726-PSA formally warning consumers about FIFA website spoofing and identifying at least 36 fraudulent domains","source":"FBI Internet Crime Complaint Center","source_url":"https://www.ic3.gov/PSA/2026/PSA260527"},{"date":"2026-06-08","event":"Help Net Security reports Intel 471 assessment that 2026 FIFA World Cup represents 'the largest and most complex cyberattack surface in sporting history'; total domain count cited at 19,000+","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/06/08/fifa-world-cup-cyber-threats/"},{"date":"2026-06-09","event":"CybelAngel publishes threat report documenting 468 indicators of compromise across four fraud vectors, with 125 clone domains actively live","source":"CybelAngel","source_url":"https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/"},{"date":"2026-06-09","event":"Arctic Wolf Labs publishes research on adversary-in-the-middle (AiTM) phishing kit defeating all FIFA account MFA methods in real time","source":"Arctic Wolf Labs","source_url":"https://arcticwolf.com/resources/blog/aitm-qr-code-phishing-and-infostealers-at-the-2026-fifa-world-cup/"},{"date":"2026-06-10","event":"WCUP (World Cup PvP) memecoin launches; reaches approximately $50 million market cap on day one following alleged undisclosed paid promotions by crypto influencers on X","source":"TRM Labs / AMBCrypto","source_url":"https://ambcrypto.com/2026-fifa-world-cup-is-now-live-but-so-are-crypto-scams-heres-what-trm-labs-found/"},{"date":"2026-06-11","event":"2026 FIFA World Cup tournament begins; scam infrastructure already fully operational across all documented vectors","source":"The Hacker News","source_url":"https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision b19490b5-e3e8-432a-93f4-9ba16cfcb3e3
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.