Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup


The FBI is issuing this Public Service Announcement (PSA) to warn the public that cyber threat actors are conducting spoofing attacks against the Fédération Internationale de Football Association (FIFA) website in advance of the 2026 FIFA World Cup. A spoofed website is designed to pose as a legitimate website, with branding, product listings, etc., and malicious actors use them to further illegal activity like personal information theft and facilitating monetary scams.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • A new Android attack combines malware and ransomware in a cocktail of cybercrime

    September 11, 2026

    Unique malware variant spotted targeting Android users. When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. Rarely do we see all of these functionalities merged into a single entity, and even rarer – to have it target Android ...

  • ShinyHunters expose 6.4M in attack on medical supplier McKesson

    September 10, 2026

    McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP ...

  • Protecting organizations from AI-assisted executive impersonation and invoice fraud

    September 10, 2026

    Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their ...

  • Russian National Extradited to United States for Bank Account Takeover Fraud Scheme Causing Millions of Dollars in Losses

    September 8, 2026

    Sergei Anatolyevich Filimonov, 36, a Russian national and web developer who was allegedly involved in a transnational cyber‑fraud conspiracy responsible for large‑scale bank account takeover activity, was arraigned Friday in the Northern District of Georgia after being extradited from the Republic of Georgia. Filimonov was indicted by a federal grand jury on Nov. 4, 2025, ...

  • Two major security flaws are affecting more than six million WordPress websites

    September 7, 2026

    More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms – two popular WordPress plugins. Elementor Pro is a commercial plugin that allows users to build websites using ...

  • More than 1 million users affected in Mathspace data breach across Australia and New Zealand

    September 7, 2026

    More than a million people, including students, school staff, and parents, have been affected following a data breach at Mathspace, according to the learning provider. The company said, in a blog post, “unauthorised parties had accessed an internal reporting system used by Mathspace” and the exposed information included names and email addresses. It said the attackers accessed ...