World Cup Phishing Campaign Nearly Triples With 203 Unique IPs

Threat actors are rapidly scaling their efforts to exploit the 2026 FIFA World Cup, with malicious infrastructure expanding far beyond initial estimates.

A recently discovered phishing campaign has nearly tripled in size, growing from an initial 79 typosquatting domains to a confirmed total of 222 malicious sites.

The hosting footprint has seen an even more dramatic increase, exploding from just 14 IP addresses to 203 unique IPs. This massive ecosystem is carefully designed to mimic official FIFA platforms, featuring fake ticketing portals, copycat merchandise stores, and credential-harvesting login pages.

Initial investigations focused solely on domains directly impersonating the official FIFA website.

However, by leveraging broader passive DNS analysis, certificate transparency logs, and WHOIS data, researchers uncovered a much larger threat landscape.

Roughly 10 percent of the expanded dataset contains operator-identifying information where WHOIS privacy redaction failed or was skipped entirely, providing security teams with concrete handles for ongoing tracking.

The campaign is actively expanding as the tournament approaches.

World Cup Phishing Surges (Source: flare)
World Cup Phishing Surges (Source: flare)

World Cup Phishing Surges

The expanded data reveals that this is not a single, centrally managed operation. Instead, it is a distributed network of independent threat actors exploiting the same global event.

These groups share scam kit templates but maintain entirely distinct registration patterns and operational signatures.

Researchers have identified four specific operator clusters driving this fraud network:

  • The Typosquat Core: The most visible group controls roughly 86 domains directly mimicking the “fifa.com” URL. They rely heavily on Cloudflare to mask their origin servers and primarily use the GNAME.COM registrar.
  • The Repurposed Shops: This cluster operates 14 generic “.shop” domains tied to a single email address and the placeholder name “Bill John.” Instead of registering fresh typosquats, they repurpose aged, legitimate-looking domains to defeat security filters that block newly created sites.

According to Flare research, the technical setup of this campaign presents significant hurdles for takedown efforts.

Over 80 percent of the 203 unique IP addresses sit securely behind Cloudflare’s reverse proxy, effectively hiding the real origin servers from investigators.

The use of Cloudflare means that the small number of shared IP clusters observed are almost certainly pointing at actual origin infrastructure rather than coincidental shared hosting.

Furthermore, obtaining and deploying identical TLS certificates across multiple domains strongly implies a unified deployment strategy within individual clusters.

Cloudflare has already flagged a handful of these domains as suspected phishing sites, validating the campaign’s malicious nature.

However, hundreds of similar domains remain active, highlighting the need for campaign-level detection rather than analyzing sites one by one.

This concentration offers a strategic advantage for defenders. A single, well-documented bulk abuse report submitted to GNAME.COM could instantly cripple nearly half of the known infrastructure.

As the 2026 World Cup draws closer, relying on simple keyword detection will no longer be enough.

Organizations must continuously monitor typosquatting trends, leverage automated takedown workflows, and trace shared hosting fingerprints to protect consumers from these sophisticated fraud rings.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories