NewsPREMIUM

Cyberscammers target Fifa World Cup ticket sales

Cybersecurity firm Check Point uncovers more than 4,300 fake websites mimicking Fifa and host city portals as sales begin

Picture: 123RF/TOMASZ TRYBUS
Picture: 123RF/TOMASZ TRYBUS

South Africans looking to buy tickets to the upcoming Fifa World Cup should beware of online scammers and fraudsters creating fake sales websites that mirror the legitimate portals with the intention of defrauding unsuspecting football fans. 

New research from cybersecurity firm Check Point Software Technologies has revealed a co-ordinated campaign to establish thousands of fake domains, botnets and phishing tools, all masquerading as legitimate Fifa and host city assets.

The data shows that more than 4,300 fake domains are already online.

According to Fifa’s financial reports, revenue generated from ticket sales for the 2022 edition of the World Cup in Qatar was $685.9m (R11.9bn). This was out of a total $929m, which also included hospitality rights, showing how lucrative the market is for fraudsters who succeed in syphoning off some of the funds. 

This use of fake domains and other tools is part of a deceptive tactic known in cybersecurity as “spoofing”, in which cybercriminals disguise their communication, system or identity as a known, trusted source to trick an individual or system.

The aim of this tactic is to gain victims’ trust, leading them to grant unauthorised access, provide sensitive information such as passwords or banking details, or download malware. This is a fundamental technique used in many social engineering and network attacks.

Fifa’s first ticketing phase for the 2026 World Cup, set to be hosted across the US, Canada and Mexico from June, is already under way.

What we’re seeing isn’t isolated cybercrime, its infrastructure being built, at scale, to exploit global interest before the World Cup even kicks off.

—  Amit Weigman, security evangelist at Check Point

Fans who entered the early presale draw in September 9-19 were to be notified of their results on September 29, with ticket purchases opening for selected users on October 1. 

Check Point says this window presents an ideal opportunity for fraud. 

Since August 1, the firm has identified more than 4,300 newly registered domains spoofing Fifa, “World Cup”, or tournament host cities such as Dallas, Miami, Toronto and Mexico City.

“These registrations are not organic, they come in synchronised waves, often using identical DNS infrastructure, and are tightly clustered across a handful of bulk-friendly registrars like GoDaddy, Namecheap, Dynadot and Gname,” Check Point said.  

Scammers are expected to flood inboxes and search engines with phishing emails, spoofed ticket confirmations and fake queue portals, all timed to coincide with real Fifa communications. The likelihood of success increases when urgency is high, and expectations are real.

“What we’re seeing isn’t isolated cybercrime, its infrastructure being built, at scale, to exploit global interest before the World Cup even kicks off,” said Amit Weigman, security evangelist at Check Point. “Threat actors are not waiting for 2026. They are matching their timeline to Fifa’s.”

Worryingly, “many of these domains are designed for long-term use, including references to Fifa 2030 and 2034”, the company said. 

According to Check Point, this “domain ageing” strategy allows fraudsters to build passive credibility over time, a tactic often seen in targeted brand abuse.

gavazam@businesslive.co.za


Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.

Comment icon