World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat

Threat intelligence has uncovered a significant increase in digital scams and phishing campaigns exploiting the FIFA World Cup 2026, specifically targeting mobile users. Three primary attack campaigns have been identified: The first uses typosquatting and institutional spoofing with fake domains like fifa-tickets[.]vip to deceive ticket buyers. The second mimics major sports retailers such as Nike and Adidas, hiding infrastructure behind Cloudflare to steal payment credentials. The third campaign, dubbed OffsideHire, exploits tournament hiring through sophisticated recruitment fraud using an Adversary-in-the-Middle platform targeting corporate Google Workspace accounts with real-time MFA bypass capabilities. These campaigns leverage emotional urgency, ticket scarcity, and mobile device usage patterns to bypass traditional security controls, posing risks to both individuals and enterprise environments through credential harvesting and session hijacking.

Pulse ID: 6a2b24146ff879b6eec74176
Pulse Link: https://otx.alienvault.com/pulse/6a2b24146ff879b6eec74176
Pulse Author: AlienVault
Created: 2026-06-11 21:09:40

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#AdversaryInTheMiddle #Cloud #CredentialHarvesting #CyberSecurity #Google #ICS #InfoSec #MFA #Mimic #OTX #OpenThreatExchange #Phishing #RAT #SocialEngineering #TypoSquatting #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange