Fake World Cup ticket sites beat card checks by stealing passcodes

The scam sites built around the 2026 FIFA World Cup did not just sell fake shirts. The most effective ones cloned the tournament's official ticket and hospitality site closely enough to take a shopper's card details, then talk them into handing over the one-time passcode their bank had sent to stop precisely that kind of fraud.

Trend Micro counted 35,538 malicious or unverifiable sites carrying the keywords "fifa" or "worldcup" between January and June 2026, and recorded roughly 1.48 million visits to them from inside Japan alone. Traffic climbed sharply in June as the tournament kicked off on June 11, co-hosted by the United States, Canada and Mexico. The tally was published on July 29 by Kenichiro Motono, the company's chief fraud prevention analyst, with research contributions from Shingo Matsugaya and Makoto Shimamura.

How the passcode theft works

Researchers found a near-perfect copy of FIFA's official hospitality site, where fans buy match tickets and packages. The clone reproduced the branding and layout, loaded videos and images directly from the official site's own servers to look authentic, linked out to FIFA's real social accounts and policy documents, and even offered automatic translation so it could work on speakers of any language. Its login page had no connection to FIFA's account system at all: an email address and password typed there went straight to the attackers.

Checkout is where the money moves. The victim enters their card details, the attacker receives them in real time and immediately attempts a fraudulent payment somewhere else. The victim's bank sends a one-time passcode to verify that payment, the victim types it into the fake checkout page, and the attacker uses it within seconds to push the fraudulent transaction through. A fake order confirmation appears and nothing looks wrong. One-time passcodes are a strong defense against stolen card numbers, but they fail completely when the victim is persuaded to enter the code on the attacker's page.

Fake shops and matches that never start

The same six months produced 6,251 counterfeit shopping sites using the FIFA name or the Japanese terms for World Cup and Japan national team, many registered well before the tournament. Goods bought there often never arrive, or arrive as counterfeits. A third cluster impersonated broadcasters: searches for free Japanese-language streams led to fake live-streaming pages, one of them hosted on the compromised website of a research institute at a US university, which held multiple fake pages embedded one per match. The video player was a mock-up, and researchers never saw a single match actually play. Every tap of the fake play button fired a redirect through a malicious ad network, sending users to legitimate trading and e-commerce signup pages whose affiliate programs were being milked for ad fraud, or to a registration page that harvested card details and quietly enrolled victims in recurring subscriptions.

Both the fake shops and the fake streams were pushed up search rankings by SEO poisoning, the same trick IntelFusions covered when scammers hijacked legitimate sites' rankings during the group stage, and when fake streaming pages funnelled fans into malware in June. Japanese users were measurably the primary target this time, which fits a broader pattern of fraud campaigns tuned per market (see our Japan cyber profile). The FBI's Internet Crime Complaint Center had warned about tournament scams in May in advisory I-052726-PSA.

What you should do

Trend Micro stresses that FIFA, its partners, and the legitimate broadcasters and streaming services being impersonated had no involvement in any of this. Full findings are in the original report.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions