A Check Point Research report reveals the early infrastructure behind a global fraud campaign targeting the world’s most-watched sporting event
As the countdown to the 2026 FIFA World Cup begins, threat actors are already on the field, building digital infrastructure designed to exploit fan excitement, disrupt ticketing, and siphon revenue from one of the world’s largest sporting events.
New research from Check Point Research, the threat intelligence arm of Check Point® Software Technologies, reveals a coordinated campaign to establish thousands of fake domains, botnets, and phishing tools, all masquerading as legitimate FIFA and host city assets.
This isn’t speculation. The campaign has already begun.
The Early Play: Fraud Infrastructure in Motion
Since August 1, 2025, Check Point has identified more than 4,300 newly registered domains spoofing FIFA, “World Cup,” or tournament host cities like Dallas, Miami, Toronto, and Mexico City. These registrations are not organic, they come in synchronised waves, often using identical DNS infrastructure, and are tightly clustered across a handful of bulk-friendly registrars like GoDaddy, Namecheap, Dynadot, and Gname.
Worryingly, many of these domains are designed for long-term use, including references to FIFA 2030 and 2034. This “domain aging” strategy allows fraudsters to build passive credibility over time, a tactic often seen in targeted brand abuse.
Real-Time Risk: Presale Phishing Incoming
FIFA’s first ticketing phase is already underway. Fans who entered the early presale draw (Sept. 9–19) will be notified of their results on September 29, with ticket purchases opening for selected users on October 1.
This window presents an ideal opportunity for fraud.
Threat actors are expected to flood inboxes and search engines with phishing emails, spoofed ticket confirmations, and fake queue portals, all timed to coincide with real FIFA communications. The likelihood of success increases when urgency is high, and expectations are real.
“What we’re seeing isn’t isolated cybercrime. Its infrastructure being built, at scale, to exploit global interest before the World Cup even kicks off,” said Amit Weigman,
Evangelist at Check Point Software Technologies. “Threat actors are not waiting for 2026. They are matching their timeline to FIFA’s.”
What Check Point Research Found
- 4,300+ FIFA-related domains registered in less than 60 days, with peak activity between August 8–12 and again in early September.
- Registrar concentration across GoDaddy, Namecheap, Gname, and Dynadot enables bulk automation and rapid deployment.
- Linguistic targeting splits by audience: English for streaming, Spanish and Portuguese for ticketing and merchandise, French for European markets.
- Top-level domains include .com, .shop, .store, .online, and .football — often chosen for low cost and low friction.
- DNS overlaps suggest centralised control by small numbers of semi-professional operators using scripted fraud kits.
- Telegram channels and dark-web forums are already promoting fake tickets, counterfeit gear, and payment fraud toolkits.
Ticketing Disruption & Botnet Abuse
Beyond simple scams, Check Point uncovered evidence of systemic attacks designed to destabilise FIFA’s ticketing infrastructure.
Botnets are being trained to flood pre-sale queues, scoop up high-demand inventory, and manipulate dynamic pricing models. On underground markets, customised toolkits and proxy farms are being sold with FIFA-specific instructions, an echo of tactics used to disrupt major ticketing platforms like Ticketmaster.
The Bigger Threat Landscape
- Fans face exposure to phishing, financial fraud, and malware through fake ticket sites and livestreaming scams.
- FIFA and sponsors face brand abuse, lost traffic, and counterfeit commerce.
- Host cities and venues may see travelers targeted with geo-specific scams tied to accommodation, transport, or hospitality.
- The internet ecosystem, including ad networks, registrars, and messaging platforms, risks becoming a distribution layer for fraud.
- Follow Check Point via:
LinkedIn: https://www.linkedin.com/company/check-point-software-technologies
X: https://www.twitter.com/checkpointsw
Facebook: https://www.facebook.com/checkpointsoftware
Blog: https://blog.checkpoint.com
YouTube: https://www.youtube.com/user/CPGlobal
About Check Point Research
Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyses global cyber-attack data stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcementand various CERTs.
About Check Point Software Technologies Ltd.
Check Point Software Technologies Ltd. (www.checkpoint.com) is a leading protector of digital trust, utilising AI-powered cyber security solutions to safeguard over 100,000 organisations globally. Through its Infinity Platform and an open garden ecosystem, Check Point’s prevention-first approach delivers industry-leading security efficacy while reducing risk. Employing a hybrid mesh network architecture with SASE at its core, the Infinity Platform unifies the management of on-premises, cloud, and workspace environments to offer flexibility, simplicity and scale for enterprises and service providers.
Legal Notice Regarding Forward-Looking Statements
This press release contains forward-looking statements. Forward-looking statements generally relate to future events or our future financial or operating performance. Forward-looking statements in this press release include, but are not limited to, statements related to our expectations regarding future growth, the expansion of Check Point’s industry leadership, the enhancement of shareholder value and the delivery of an industry-leading cyber security platform to customers worldwide. Our expectations and beliefs regarding these matters may not materialise, and actual results or events in the future are subject to risks and uncertainties that could cause actual results or events to differ materially from those projected. The forward-looking statements contained in this press release are also subject to other risks and uncertainties, including those more fully described in our filings with the Securities and Exchange Commission, including our Annual Report on Form 20-F filed with the Securities and Exchange Commission on April 2, 2024. The forward-looking statements in this press release are based on information available to Check Point as of the date hereof, and Check Point disclaims any obligation to update any forward-looking statements, except as required by law.



