A CSC report describes real-world scams where criminals impersonate executives and brands online to steal personal or payment information. Examples include fake CEOs contacting people on LinkedIn with bogus job offers, and lookalike “FIFA” domains used for fake ticket sales, travel offers, and giveaways. The report warns that AI is making these impersonation and brand-abuse scams faster to create and harder to spot.
Key findings
- CSC report highlights impersonation, phishing, and domain-name abuse as top online IP risks.
- A described Fashion Week scam offered high-end experiences and requested payment in Bitcoin/virtual currencies.
- Clients reported executive impersonation on LinkedIn, using fake job opportunities to collect personal information for later attacks.
- CSC found 65,590 third-party domains containing “FIFA” registered (Jan 2022–Apr 2026), some linked to fake ticketing/travel/merch/streaming/giveaways aimed at stealing personal or payment information.
- AI is enabling faster creation of convincing fraudulent content, including voice and other digital copies of assets.
Who’s being targeted
- Commonly targeted roles: All employees, HR/Recruiting, Finance (expense/travel payments), Marketing/Brand teams, Legal/IP teams, IT/Security teams.
- Affected industries: Brand owners (cross-industry), Retail/e-commerce, Pharmaceuticals, Automotive, Sports/events and ticketing, Marketing/advertising.
- Attack channels: linkedin, website.
- Impersonated: Company CEO / senior executive, FIFA / FIFA World Cup-related brand.
Awareness takeaways
- Treat unsolicited executive outreach (especially on LinkedIn) as high-risk and verify identity through a trusted, separate channel.
- Before entering payment or personal details, verify event/ticket/travel offers by checking the official organization website and domain carefully.
- Assume AI can make scams more convincing (including impersonation) and rely on verification steps, not “how real it sounds/looks.”
Red flags to watch for
- Unsolicited message from a ‘CEO’ account
- Pressure to share personal information quickly
- Profile or connection history doesn’t match a real executive
- Domain name looks unofficial despite containing “FIFA”
- Too-good-to-be-true ticket/giveaway offers
- Requests for payment or card details on an unfamiliar site
Read the video transcript
Imagine this: a LinkedIn DM, “Hi, I’m the CEO, I saw your profile and have a confidential opportunity.” CSC reports fake chief executives doing exactly this on LinkedIn, offering bogus jobs, then asking for your resume, phone, even ID details to use in later attacks. Same play with fake FIFA sites: CSC found over sixty-five thousand ‘FIFA’ domains, some selling fake tickets, travel, and giveaways to grab your card and personal data. Here’s the move: if a ‘CEO’ or ‘FIFA offer’ shows up out of nowhere, stop. Don’t reply or pay, open our official site or directory and verify through that, first.