Researchers uncover FIFA World Cup 2026 ticket phishing sites linked to Chinese-speaking operators

Summary
Hunt.io analyzed a campaign of cloned FIFA World Cup ticket sites designed to harvest fan credentials and payment details. Shared code and infrastructure fingerprints help identify the sites; Chinese-language clues support, but do not prove, attribution.
Key points
- The campaign cloned FIFA’s ticketing portal across a fleet of lookalike domains, using ticket-sale urgency to lure fans into fake login and checkout flows.
- The pages are designed to collect FIFA credentials, payment-card details, and personal information. This is inferred from the front-end markup; researchers did not capture submissions or inspect the back end.
- In a 35-site sample, researchers found recurring fingerprints including a re-hosted /fifa/ build, the Layui framework, an operator script, and a shared favicon on 34 sites.
- Chinese-language code comments, Chinese locale handling, Layui, and registration and hosting patterns support the assessment of a Chinese-speaking operator, but do not confirm the operator’s identity.
- Most domains were behind Cloudflare; researchers identified several suspected origin IPs and recommend using structural indicators rather than rotating domains or proxy IPs to hunt for clones.
- Fans should access ticketing through FIFA’s official site or app and avoid entering credentials on non-fifa.com domains. Defenders can hunt for the shared kit markers and block confirmed domains.
Article Details
- Attack Vectors
- Operators deployed near-identical clones of FIFA's World Cup 2026 ticketing portal on lookalike domains, using a copied front end re-hosted under /fifa/.
- A “BUY NOW” pop-up directs visitors into a fake ticket-purchase flow.
- FIFA-branded sign-in and registration links resolve on the lookalike host rather than FIFA's authentication host. Credential collection is strongly inferred from the crawled markup; researchers did not observe the POST request or back end.
- The fake checkout requests payment-card and billing details through paths on the lookalike host. Card collection is inferred from the front-end flow rather than an observed payment submission.
- The kit embeds a Meta Pixel to measure visitor activity and adds a translation layer intended to make the pages appear local to visitors.
- Defensive Notes
- Direct fans to FIFA's official site or app through a bookmark rather than search results or forwarded links; do not enter FIFA credentials on a non-FIFA host.
- Hunt for the combined structural markers of the cloned /fifa/ build, Layui dependency, operator script, and same-origin sign-in, rather than relying on rotating domains or copied FIFA identifiers alone.
- Use the copied favicon only alongside a phishing-specific marker, because FIFA's genuine site also uses that favicon.
- Treat the reported origin IPs and AS25820 hosting pattern as pivots requiring FIFA-themed and structural confirmation; shared hosting can include unrelated sites.
- Block confirmed phishing domains and submit them for takedown, prioritizing sites with live payment flows.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | dt-fifa26[.]shop | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fc-fifa26[.]shop | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-com-26[.]shop | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-com[.]com | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-com[.]id | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-com[.]services | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-com[.]vip | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-com[.]xyz | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-online[.]me | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa-web[.]co | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]black | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]cafe | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]cash | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]center | Listed FIFA ticket-phishing clone domain; reported to resolve to a suspected origin. |
| DOMAIN | fifa[.]city | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]cyou | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]fund | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]gold | Listed FIFA ticket-phishing clone domain; reported to resolve to a suspected origin. |
| DOMAIN | fifa[.]kim | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]market | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]red | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]sale | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]shopping | Listed FIFA ticket-phishing clone domain; reported behind a suspected shared origin. |
| DOMAIN | fifa[.]ski | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifa[.]website | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifaofficial[.]help | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifawebsite[.]cn | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | fifawebsite[.]net | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | https-fifa[.]cn | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | lg-fifa26[.]shop | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | ww-fifa[.]com | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | ww-fifa[.]vip | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | ww-fifaweb[.]cn | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | ww-wfifa[.]com | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | www-fifa-com[.]vip | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | www-fifa[.]co | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | www-fifa[.]com[.]co | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | www-fifa[.]me | Listed FIFA ticket-phishing clone domain. |
| DOMAIN | www-fifa[.]website | Listed FIFA ticket-phishing clone domain. |
| HOSTNAME | www[.]fifa[.]cafe | Listed FIFA ticket-phishing clone hostname. |
| HOSTNAME | www[.]fifa[.]kim | Listed FIFA ticket-phishing clone hostname. |
| HOSTNAME | www[.]fifa[.]sale | Listed FIFA ticket-phishing clone hostname; reported behind a suspected shared origin. |
| HOSTNAME | www[.]fifa[.]shopping | Listed FIFA ticket-phishing clone hostname. |
| HOSTNAME | www[.]ww-fifa[.]com | Listed FIFA ticket-phishing clone hostname. |
| IPV4 | 104[.]225[.]235[.]49 | Suspected origin IP for FIFA-clone sites; reported as flagged by IOC Hunter. |
| IPV4 | 65[.]49[.]223[.]138 | Second suspected shared origin reported behind fifa[.]shopping and www.fifa[.]sale. |
| IPV4 | 89[.]208[.]250[.]38 | Suspected origin IP for the clone infrastructure; reported as flagged by IOC Hunter. |
MITRE ATT&CK
T1056.003 · Web Portal CaptureA FIFA-branded login is served on the lookalike host, positioning it to capture entered credentials; collection is inferred from markup, not an observed POST.T1583.001 · DomainsThe operators registered FIFA-lookalike domains in reported batches to host the cloned ticketing sites.T1656 · ImpersonationThe lookalike sites impersonate FIFA's World Cup 2026 ticketing portal and present FIFA-branded sign-in and checkout flows.
Vendors
16clouds104.225.235[.]49 and 89.208.250[.]38, both on AS25820 (Cluster Logic Inc), both with reverse DNS under 16clouds.com (104.225.235.49.16clouds.com and 89.208.250.38.16clouds.com). 16clouds is a small China-orientedAlibaba Cloud / HiChinaregistrars are concentrated. Three names dominate: Beijing Lanhai Jiye Technology Co., Ltd and Alibaba Cloud / HiChina (www.net.cn), both Chinese, alongside GoDaddy. The split is consistent, with the NovemberBeijing Lanhai Jiye Technology Co., LtdThe registrars are concentrated. Three names dominate: Beijing Lanhai Jiye Technology Co., Ltd and Alibaba Cloud / HiChina (www.net.cn), both Chinese, alongside GoDaddy. The split is consistent, with the NovemberCloudflareEverything below comes directly from the Hunt.io crawl data for the sample. Most sites returned a cloudflare server header and resolved to Cloudflare ranges (104.21.0.0/16, 172.67.0.0/16), which hides the true originCluster Logic Incpoint to suspected origin infrastructure: 104.225.235[.]49 and 89.208.250[.]38, both on AS25820 (Cluster Logic Inc), both with reverse DNS under 16clouds.com (104.225.235.49.16clouds.com andGoDaddyLanhai Jiye Technology Co., Ltd and Alibaba Cloud / HiChina (www.net.cn), both Chinese, alongside GoDaddy. The split is consistent, with the November premium-TLD wave largely on the Chinese registrars and theHunt.ioUsing Hunt.io's HuntSQL, we identified and analysed a fleet of fake websites that are all built from one shared toolkit.
Tools
HuntSQLBefore walking through the kit's code and the HuntSQL queries built from it, here is what the hunt turned up.IOC Hunterchoice rather than proof of who is behind it. The detail that matters for hunting is that Hunt.io's IOC Hunter has already flagged both of these addresses, while every Cloudflare front IP in the set is clean.