TrendLife

From FIFA 2026 to every major event: the scam playbook

    From FIFA 2026 to every major event: the scam playbook
    iStock

    This article is based on TrendLife research into scams observed during the FIFA World Cup 2026. FIFA and its services are not involved in these scams. All brand names are trademarks of their respective owners.

    The FIFA World Cup 2026 is over. The scams aren’t. They started months before the first match, and the infrastructure is still live.

    By late May, the FBI had flagged 36 spoofed FIFA domains in a public advisory. Counterfeit merchandise stores were already running paid TikTok ads. Fake streaming pages had been indexed in search results since March. And job sites advertising tournament positions were collecting passport scans from applicants in all three host countries: the US, Canada, and Mexico.

    None of this was improvised. Scam infrastructure is built around the event calendar, timed to specific gaps: when official tickets sell out, when legitimate streams require subscriptions, when seasonal hiring demand creates a rush of applicants. It’s a playbook, and it runs at every major event: the Olympics, championship games, global concert tours. Only the branding changes.

    Here’s how it works, what we observed during the World Cup, and what to watch for next.

    Three scams that show up at every big event

    Major events reliably produce three types of scams. Each one exploits a different moment of fan need, and each is designed to look indistinguishable from the real thing.

    Fake tickets and hospitality packages

    Scammers register domains that mimic official event sites and list VIP packages, hotel bundles, or last-minute tickets. Payment is collected upfront. The tickets never arrive.

    FIFA scam playbook_Fake FIFA website
    Fake FIFA website. Source: TrendLife

    During the World Cup, we observed clones of FIFA’s On Location hospitality portal (the official channel for premium packages) that replicated every verifiable detail: real phone numbers, correct social media links, verbatim copyright text, proper Visa branding. Cross-checking each element against the legitimate portal returned a match, because everything had been copied directly from it. The tell was directionality: the fake site linked to FIFA infrastructure, but nothing on fifa.com linked back.

    A second variant went further. Analysis of its checkout flow revealed a real-time connection to the operator’s payment backend. When a buyer entered card details, data was forwarded immediately. When the bank triggered a verification SMS, the fake page prompted for it, presented as a standard step. Every buyer received a confirmation, regardless of what happened on the backend.

    These sites appeared when the official portal was sold out. That’s the targeting window: fans with fewer options to verify, in a hurry, locked out of legitimate channels.

    FIFA scam playbook_Fake FIFA website 2
    Fake FIFA website. Source: TrendLife

    A separate operation cloned the entire official FIFA Store and drove traffic through paid TikTok ads. Fans who ordered received counterfeit goods or nothing.

    Fake live streams

    Search for “free stream” plus any major event name and you’ll find pages designed to look like they’re about to show the game. None of them deliver a stream. Every path ends at a form: email, password, credit card, or a fake subscription.

    What surprised us during the World Cup was the infrastructure behind them. Compromised legitimate websites, including a Zurich University researcher’s site and an Italian paper company, appeared in search results for FIFA livestream queries. Neither owner had any connection to the injected content. Blogspot accounts posing as “Education Information Today” served as redirect pages, with first entries dating to March.

    The operation used IP-based cloaking: visitors on Japanese mobile carrier IPs were rerouted to YouTube, while everyone else saw the real scam. Affiliate tracking parameters linked pages across compromised sites to a single operator. And the same Blogspot accounts also covered basketball. The infrastructure wasn’t FIFA-specific. FIFA was just the current payload.

    Fake jobs and volunteering

    Major events need thousands of temporary workers, and scammers know applicants are eager. Fake recruitment sites list roles like security guard, driver, or event staff, then collect government IDs and passport scans as part of the “application.”

    One operation registered jobs-fifa[.]com, a single hyphen separating it from the legitimate jobs.fifa.com. The FBI named it explicitly in their May advisory. Applications requested national ID photos and passport scans at the initial stage, with follow-up moving to WhatsApp.

    FIFA scam playbook_Fake FIFA job website
    Fake FIFA job recruitment website. Source: TrendLife

    Another went further: it impersonated a specific, named FIFA staff member, using her actual photo and name on a branded Calendly page to schedule fake interviews. She confirmed the impersonation publicly on LinkedIn. For the record, official FIFA recruitment uses emails only from fifa-careers@pinpoint.email or @fwc2026.org, scheduling only through Pinpoint ATS or Outlook. Never Calendly, never WhatsApp before a formal offer.

    The documents collected (government IDs, passport scans) are more valuable than a stolen card number. Misuse tends to surface months later with no visible connection to the original collection point.

    Why big events are perfect conditions for scammers

    These scams work because major events create the ideal combination of pressure, unfamiliarity, and scale.

    • Urgency. Tickets sell out. Streams start at a fixed time. Job openings close. These natural deadlines push people to act before they verify.

    • Unfamiliar territory. Most people don’t buy World Cup tickets or apply for tournament jobs regularly. Without a baseline for what the real process looks like, a convincing fake is harder to spot.

    • High demand, low supply. When something is hard to get, people are more willing to take a chance on an unfamiliar website or an offer that seems too good to pass up.

    • Global scale. Events that cross borders let scammers target multiple countries with the same infrastructure, swapping languages and currencies.

    How to protect yourself at any major event

    These tips apply whether it’s the World Cup, the Olympics, a music tour, or a championship game.

    • Buy tickets only from official sources. Go directly to the event’s website or authorized resellers. If a deal comes from a social media ad or a search result you’ve never seen before, verify the domain before entering any payment information.

    • Don’t search for free streams. If a match or concert isn’t available on a platform you already use, a random website offering it for free is almost certainly a trap. The “stream” is the bait, not the product.

    • Never upload identity documents to apply for event jobs. Legitimate employers don’t ask for your passport or national ID at the application stage. That request comes after a confirmed job offer, not before.

    • Check the URL before entering anything. Scam sites use domains that look close to the real thing. A misplaced hyphen, a misspelled name, or an unfamiliar extension (.stream, .cfd, .vip) is a warning sign.

    • Use Trend Micro ScamCheck. It flags suspicious websites and links before you share personal or financial details.

    The event ends, but the infrastructure doesn’t

    It doesn’t self-terminate. Job sites with closed postings continue to collect applications. Compromised websites with injected pages keep catching search traffic. Blogspot accounts with expired content persist. The fan who finds one of these pages in August assumes it’s current.

    FIFA-keyword domain registrations were flat through April and rose sharply from June 13, tracking the tournament calendar closely. At the time people encountered them, many scam domains had not yet been classified as malicious.

    The FIFA World Cup 2030 will span six countries (Spain, Portugal, Morocco, Argentina, Uruguay, and Paraguay) across at least four languages. The same demand gaps will exist. The same playbook will run. Domain registrations for 2030 have likely already started.

    FIFA scam playbook_New domains identified ahead of FIFA
    New domains with FIFA-related keywords identified ahead of FIFA. Source: TrendLife

    Knowing the playbook is the best defense. If you’ve followed TrendLife’s FIFA scam coverage, you’ve already seen every play.

    Read the full series

    Post a comment

    Your email address won't be shown publicly.

    0 Comments

      Copyright © 2026 Trend Micro Incorporated. All rights reserved.

      This website uses cookies for website functionality, traffic analytics, personalization, social media functionality and advertising. Our Cookie Notice provides more information and explains how to amend your cookie settings.