The 2026 FIFA World Cup, co-hosted by the United States, Canada, and Mexico across 16 cities, is the largest in history—and it has created an equally large opportunity for cybercriminals. According to WIRED, AI-generated websites, deepfake videos, and convincing phishing campaigns are making scams increasingly difficult to detect. Unlike previous tournaments, where simple typos or suspicious email addresses were telltale signs, today's fraudsters use AI to produce professional-looking communications that mimic legitimate organizations.
The Scale of World Cup Fraud
Between January and May 2026, more than 13,000 FIFA-themed domains were registered. By early May, roughly one in 41 had already been flagged as suspicious or malicious, according to Tarek Jammoul, regional managing director at cybersecurity firm TrendAI. This activity occurred before a single match was played.
FIFA estimates that more than 6 million fans will fill stadiums, and over 150 million ticket requests flooded in within the first 15 days of the sales window—making this edition roughly 30 times oversubscribed compared to previous tournaments. Research led by cybersecurity firm Group-IB identified more than 4,300 fraudulent domains impersonating FIFA's official web presence, alongside six parallel fraud schemes and four independent threat actors operating ahead of the tournament.
Common scams include fake ticket sales, fraudulent immigration or visa-related services, misleading accommodation offers, and counterfeit merchandise. "The World Cup is the perfect opportunity for scammers—you couldn't create a better one," says David Holtzman, chief strategy officer at Naoris Protocol, a cybersecurity and blockchain company. "This is soccer. It feels fun and harmless, which lowers people's defenses."
The Role of AI in Modern Scams
AI is not inventing entirely new attack methods, but it is making attackers far more efficient. "There's been an astronomical increase in scams over the past two years, and AI is a big reason why," Holtzman says. By generating highly personalized, professional-looking emails at massive scale and helping create convincing fake websites, AI dramatically expands the threat landscape.
Spear phishing—a more targeted form of phishing where attackers use information from search engines and social media—presents an even bigger threat for World Cup fans this year. Jammoul notes that while the scams themselves have not changed dramatically, "the difference is the technology behind them." At Qatar 2022, threats included fake streaming domains and data-bait survey scams; now those same categories are "larger and more AI-polished."
| Scam Type | Qatar 2022 Examples | 2026 World Cup Evolution |
|---|---|---|
| Fake ticketing | Web pages with poor design | AI-generated, branded websites with real-looking QR codes |
| Phishing emails | Generic, with typos | Personalized, professional, AI-crafted |
| Fraudulent domains | Hundreds | Thousands, with AI-generated content |
Defense Strategies for Enterprises
While AI is amplifying attacks, it is also becoming a powerful defensive tool. By analyzing vast amounts of data and detecting unusual patterns, AI systems can help identify suspicious domains and anticipate emerging threats. However, technology alone is not enough. Companies are increasingly relying on collaboration between platforms, cybersecurity firms, and law enforcement to stay ahead.
For enterprise security teams, the World Cup serves as a cautionary tale. The tactics used against consumers—spear phishing, fake domains, AI-generated content—are equally applicable to corporate targets. Organizations should reinforce employee training, deploy AI-driven threat detection, and ensure that any third-party vendors or partners involved in World Cup-related activities (e.g., hospitality, travel, events) are vetted for cybersecurity hygiene.
As the World Cup proceeds, the volume of scams is likely to grow. The key takeaway from this report is that the old warning signs are disappearing. In an AI-powered threat landscape, vigilance must be data-driven and continuous.