World cup scams fuel credential theft ahead of 2026

The Hacker News ↗

The gist

Cybercriminals are hijacking FIFA World Cup 2026 hype with a blitz of fake ticket sites and malware, exposing millions to credential theft and financial fraud.

What to know

  • Sophisticated infostealer malware like StealC and Amadey are harvesting passwords from fans’ browsers, wallets, and messaging apps, fueling targeted banking attacks.
  • Credential chaos is rampant: poor password hygiene and reuse enabled the FortiBleed campaign to compromise over 86,000 devices in 194 countries.
  • Experts warn that only robust identity-centric security—think zero trust and continuous access governance—can outpace these AI-powered phishing and credential-stealing threats.

Fake Sites Flood World Cup

Cybercriminals are embedding themselves early with a surge of fake ticketing sites and FIFA-themed scams, exploiting fan excitement and poor password habits to steal credentials and cash in on World Cup fever.

As the FIFA World Cup 2026 approaches, cybercriminals have swiftly capitalized on fan enthusiasm by launching a wave of fraudulent domains and fake ticket sales websites designed to deceive supporters eager to secure their spots at the event. These phishing sites not only exploit the excitement surrounding the tournament but also prey on poor password hygiene and the urgency fans feel, creating fertile ground for credential theft and financial scams. This early surge in fake sites underscores how threat actors are embedding themselves deeply into the World Cup’s digital ecosystem well before kickoff.

Beyond phishing, the threat landscape has escalated with the deployment of sophisticated banking malware campaigns targeting both individual fans and organizations involved with the World Cup. Infostealer malware families like StealC and Amadey have been identified as primary tools in these operations, enabling attackers to harvest stolen login credentials and financial data with alarming efficiency. This dual-pronged approach—combining fake websites with advanced malware—places millions at immediate risk of fraud and identity theft, highlighting the critical need for enhanced cybersecurity vigilance during the tournament period.

Cybercriminals are exploiting fundamental security weaknesses such as reused or stolen login credentials alongside the proliferation of fake FIFA-themed websites to orchestrate a variety of scams and banking malware attacks. This strategy leverages the simplicity of compromised credentials to bypass defenses, amplifying the impact of their campaigns on both fans and organizations. As the event draws nearer, these tactics reveal a calculated effort to exploit not just technological vulnerabilities but also human factors, emphasizing the importance of robust password practices and awareness.

Sources
freeCodeCamp.orgSMB Tech & Cybersecurity Leadership NewsletterPaul's Security Weekly (Video)The Hacker News

Old Passwords, New Breaches

Neglected credentials, default passwords, and forgotten accounts are fueling global attacks like FortiBleed, proving that operational lapses—not just tech flaws—are the real weak link in tournament cybersecurity.

The persistence of poor password hygiene and credential reuse remains a critical vulnerability exploited by cybercriminals, as demonstrated by the FortiBleed campaign that compromised over 86,000 Fortinet devices across 194 countries by leveraging reused credentials and brute-force attacks. Despite the availability of patches and multi-factor authentication, attackers continue to harvest credentials from infostealer databases, rendering password complexity largely ineffective once credentials are leaked. This trend underscores that weak and default passwords, combined with stale accounts and lack of operational controls, create fertile ground for large-scale intrusions.

Governance failures and operational execution gaps, rather than technological shortcomings, are often at the heart of credential-related breaches. The Klue Battlecards app incident, linked to the Icarus extortion group, originated from a legacy credential tied to a long-forgotten pilot project left active for four years, illustrating how neglected identity relationships and unreviewed OAuth tokens can cascade into supply chain compromises. As cybersecurity analyst James emphasizes, the battlefield remains dominated by preventable issues like default credentials and unauthenticated endpoints, highlighting that disciplined patch management and access governance are essential defenses.

In the context of the FIFA World Cup 2026, the already rampant poor password hygiene—characterized by widespread use of default and weak passwords—has been weaponized by threat actors deploying banking malware and stolen login credentials to ensnare fans and organizations. This surge in credential theft scams reflects a broader cybersecurity reality where maintaining credential hygiene is no longer optional but vital, especially as attackers accelerate their tactics with AI and automation, outpacing organizations that fail to enforce basic operational controls.

Sources
Enterprise Security Weekly (Audio)CISO Talk by James AzarCISO Talk by James AzarThe Hacker NewsCISO Talk by James Azar

Infostealers Power Credential Crime

StealC and Amadey malware are quietly siphoning passwords from browsers and apps, enabling attackers to move from identity theft to large-scale financial fraud before defenders even know they've been breached.

Sophisticated infostealer malware such as StealC and Amadey have become pivotal tools in harvesting sensitive credentials from a variety of digital touchpoints including browsers, cryptocurrency wallets, messaging apps, and gaming platforms. Microsoft highlights that while StealC directly extracts this data, Amadey functions as a loader, delivering StealC and other malicious payloads, thereby amplifying the threat landscape. This multi-vector approach allows attackers to seamlessly pivot from credential theft to downstream attacks like ransomware, underscoring the complex ecosystem of modern cyber threats.

The insidious nature of these infostealers is further compounded by their stealthy infection patterns, often initiating breaches outside of tightly controlled enterprise environments. Microsoft warns that defenders frequently remain unaware of the compromise until attackers have already exploited valid credentials, enabling fraudulent activities and identity theft. This lag in detection is particularly perilous as it allows a single compromised endpoint—via vulnerable browsers, email clients, or chat applications—to cascade into widespread identity compromises, dramatically increasing the scale and impact of attacks.

As the FIFA World Cup 2026 approaches, these sophisticated infostealer malware strains are actively fueling a surge in banking malware scams and credential theft targeting fans and organizations alike. Reports confirm that StealC and Amadey are being exploited to harvest credentials that facilitate immediate fraud and identity theft, putting both individuals and businesses at heightened risk. This alarming trend highlights the urgent need for enhanced cybersecurity vigilance during major global events, where attackers capitalize on heightened online activity and often lax password hygiene.

Sources
SMB Tech & Cybersecurity Leadership Newsletter

Zero Trust: The New Playbook

AI-fueled identity attacks and rampant credential leaks are forcing organizations to adopt zero trust identity management, making passwordless authentication and continuous access controls essential for defending World Cup supply chains.

By mid-2026, cyber threats have decisively shifted toward identity-first attacks, where compromised credentials and user trust serve as primary entry points, especially in complex third-party ecosystems like manufacturing supply chains. Doppel's analysis highlights how credential leaks dominate attack vectors, enabling access to critical resources such as supplier portals, VPNs, and cloud services, while legacy access patterns and distributed vendor networks amplify these risks, underscoring the urgent need for zero trust identity management to mitigate supply chain exposure.

Zero trust identity management emerges as a cornerstone defense strategy, significantly reducing risks associated with admin privileges by making unauthorized escalation more difficult and noisy, thereby increasing the likelihood of detection. As one expert notes, organizations need not be unhackable but must be harder targets than their peers, a principle that aligns with Portnox’s emphasis on continuous, identity-level enforcement at both user and device layers—especially crucial in AI-intensive environments where traditional perimeter defenses fall short.

The rise of AI-driven access risks compounds identity-centric security challenges, as AI agents exploit broken access controls and overpermissioned accounts at machine speed, often evading traditional SIEM tools. Portnox stresses that holistic governance and automated identity and access management are essential to prevent exposures from shadow AI and non-human identities, including legacy service accounts, while passwordless authentication is repositioned from a mere usability feature to a strategic element within zero-trust frameworks, enhancing control over both human and machine identities.

Sophisticated phishing campaigns continue to bypass conventional safeguards like two-factor authentication through man-in-the-middle techniques, enabling prolonged unauthorized access as seen in a Google Workspace breach that went undetected for 121 days. This delayed detection underscores the critical need for enhanced identity-centric security measures and continuous monitoring to rapidly identify and respond to credential theft before attackers can entrench themselves deeply within organizational systems.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.