Trend Micro Tracks 35,538 Fake Sites Exploiting the 2026 World Cup

Summary
Trend Micro tracked 35,538 World Cup-related malicious sites from January to June 2026. The scams included fake merchandise shops, ticket-site clones stealing payment details and one-time passwords, and bogus streaming pages that harvested data or redirected users.
Key points
- Trend Micro identified 35,538 World Cup-related malicious sites between January and June 2026 and recorded about 1.48 million visits from Japan.
- The scams included fake merchandise stores, cloned ticket and hospitality sites, and fake match-streaming pages.
- Ticket-site clones stole login credentials and captured card details and one-time passwords in real time, enabling fraudulent payments despite multi-factor authentication.
- Fake streaming results used SEO poisoning and pages embedded on a compromised US university research institute website to funnel users to scam sites.
- Fake streams did not show match footage; play-button clicks triggered redirects, while registration pages could collect personal and payment information or enroll users in recurring subscriptions.
- Trend Micro advises using official sites and broadcasters, checking URLs and payment details, and never entering an unexpected one-time password.
Article Details
- Attack Vectors
- Attackers used SEO poisoning to draw users to fake World Cup merchandise shops and live-streaming pages.
- A cloned FIFA hospitality site collected login credentials, credit card details, and one-time passwords; attackers used the card details and codes in real time to complete fraudulent payments.
- Fake streaming search results led through pages on a compromised US university research institute website and blogging-platform relay pages to fake streaming sites.
- Fake play buttons redirected visitors through a malicious ad network. Some streaming sites instead sent users to registration pages that collected personal and card details or enrolled them in recurring subscriptions.
- Defensive Notes
- Navigate directly to official sites for tickets and merchandise rather than following search results or social media ads; inspect the domain of sites reached through search.
- Use official broadcasters or streaming services, and do not provide account or card details to unofficial sites offering free streams.
- Before entering a payment one-time password, verify that the merchant and amount in the message match the intended purchase; stop and contact the card company or bank if they do not.
- Use a different password for each service and consider trusted security software with anti-scam features.