Researchers uncover FIFA World Cup 2026 ticket phishing sites linked to Chinese-speaking operators

· Original article ↗

Summary

Hunt.io analyzed a campaign of cloned FIFA World Cup ticket sites designed to harvest fan credentials and payment details. Shared code and infrastructure fingerprints help identify the sites; Chinese-language clues support, but do not prove, attribution.

Key points

  • The campaign cloned FIFA’s ticketing portal across a fleet of lookalike domains, using ticket-sale urgency to lure fans into fake login and checkout flows.
  • The pages are designed to collect FIFA credentials, payment-card details, and personal information. This is inferred from the front-end markup; researchers did not capture submissions or inspect the back end.
  • In a 35-site sample, researchers found recurring fingerprints including a re-hosted /fifa/ build, the Layui framework, an operator script, and a shared favicon on 34 sites.
  • Chinese-language code comments, Chinese locale handling, Layui, and registration and hosting patterns support the assessment of a Chinese-speaking operator, but do not confirm the operator’s identity.
  • Most domains were behind Cloudflare; researchers identified several suspected origin IPs and recommend using structural indicators rather than rotating domains or proxy IPs to hunt for clones.
  • Fans should access ticketing through FIFA’s official site or app and avoid entering credentials on non-fifa.com domains. Defenders can hunt for the shared kit markers and block confirmed domains.

Article Details

Attack Vectors
  • Operators deployed near-identical clones of FIFA's World Cup 2026 ticketing portal on lookalike domains, using a copied front end re-hosted under /fifa/.
  • A “BUY NOW” pop-up directs visitors into a fake ticket-purchase flow.
  • FIFA-branded sign-in and registration links resolve on the lookalike host rather than FIFA's authentication host. Credential collection is strongly inferred from the crawled markup; researchers did not observe the POST request or back end.
  • The fake checkout requests payment-card and billing details through paths on the lookalike host. Card collection is inferred from the front-end flow rather than an observed payment submission.
  • The kit embeds a Meta Pixel to measure visitor activity and adds a translation layer intended to make the pages appear local to visitors.
Defensive Notes
  • Direct fans to FIFA's official site or app through a bookmark rather than search results or forwarded links; do not enter FIFA credentials on a non-FIFA host.
  • Hunt for the combined structural markers of the cloned /fifa/ build, Layui dependency, operator script, and same-origin sign-in, rather than relying on rotating domains or copied FIFA identifiers alone.
  • Use the copied favicon only alongside a phishing-specific marker, because FIFA's genuine site also uses that favicon.
  • Treat the reported origin IPs and AS25820 hosting pattern as pivots requiring FIFA-themed and structural confirmation; shared hosting can include unrelated sites.
  • Block confirmed phishing domains and submit them for takedown, prioritizing sites with live payment flows.

Indicators of compromise

TypeIndicatorContext
DOMAINdt-fifa26[.]shopListed FIFA ticket-phishing clone domain.
DOMAINfc-fifa26[.]shopListed FIFA ticket-phishing clone domain.
DOMAINfifa-com-26[.]shopListed FIFA ticket-phishing clone domain.
DOMAINfifa-com[.]comListed FIFA ticket-phishing clone domain.
DOMAINfifa-com[.]idListed FIFA ticket-phishing clone domain.
DOMAINfifa-com[.]servicesListed FIFA ticket-phishing clone domain.
DOMAINfifa-com[.]vipListed FIFA ticket-phishing clone domain.
DOMAINfifa-com[.]xyzListed FIFA ticket-phishing clone domain.
DOMAINfifa-online[.]meListed FIFA ticket-phishing clone domain.
DOMAINfifa-web[.]coListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]blackListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]cafeListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]cashListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]centerListed FIFA ticket-phishing clone domain; reported to resolve to a suspected origin.
DOMAINfifa[.]cityListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]cyouListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]fundListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]goldListed FIFA ticket-phishing clone domain; reported to resolve to a suspected origin.
DOMAINfifa[.]kimListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]marketListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]redListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]saleListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]shoppingListed FIFA ticket-phishing clone domain; reported behind a suspected shared origin.
DOMAINfifa[.]skiListed FIFA ticket-phishing clone domain.
DOMAINfifa[.]websiteListed FIFA ticket-phishing clone domain.
DOMAINfifaofficial[.]helpListed FIFA ticket-phishing clone domain.
DOMAINfifawebsite[.]cnListed FIFA ticket-phishing clone domain.
DOMAINfifawebsite[.]netListed FIFA ticket-phishing clone domain.
DOMAINhttps-fifa[.]cnListed FIFA ticket-phishing clone domain.
DOMAINlg-fifa26[.]shopListed FIFA ticket-phishing clone domain.
DOMAINww-fifa[.]comListed FIFA ticket-phishing clone domain.
DOMAINww-fifa[.]vipListed FIFA ticket-phishing clone domain.
DOMAINww-fifaweb[.]cnListed FIFA ticket-phishing clone domain.
DOMAINww-wfifa[.]comListed FIFA ticket-phishing clone domain.
DOMAINwww-fifa-com[.]vipListed FIFA ticket-phishing clone domain.
DOMAINwww-fifa[.]coListed FIFA ticket-phishing clone domain.
DOMAINwww-fifa[.]com[.]coListed FIFA ticket-phishing clone domain.
DOMAINwww-fifa[.]meListed FIFA ticket-phishing clone domain.
DOMAINwww-fifa[.]websiteListed FIFA ticket-phishing clone domain.
HOSTNAMEwww[.]fifa[.]cafeListed FIFA ticket-phishing clone hostname.
HOSTNAMEwww[.]fifa[.]kimListed FIFA ticket-phishing clone hostname.
HOSTNAMEwww[.]fifa[.]saleListed FIFA ticket-phishing clone hostname; reported behind a suspected shared origin.
HOSTNAMEwww[.]fifa[.]shoppingListed FIFA ticket-phishing clone hostname.
HOSTNAMEwww[.]ww-fifa[.]comListed FIFA ticket-phishing clone hostname.
IPV4104[.]225[.]235[.]49Suspected origin IP for FIFA-clone sites; reported as flagged by IOC Hunter.
IPV465[.]49[.]223[.]138Second suspected shared origin reported behind fifa[.]shopping and www.fifa[.]sale.
IPV489[.]208[.]250[.]38Suspected origin IP for the clone infrastructure; reported as flagged by IOC Hunter.

MITRE ATT&CK

Vendors

Tools

Countries

Industries

Related Articles