Fake FIFA Ticket Sites Steal Cards and OTPs

Cyber Defense Magazine · Medium sophistication
Last updated July 30, 2026

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are buying legitimate tickets.

How the attack worked

Criminals built cloned versions of FIFA's official ticketing site, copying tournament news, match schedules, stadium information, and the ticket purchasing flow to make the pages look authentic. Fans arrived at these pages mainly through Facebook and Instagram ads and shared links rather than by navigating directly to an official source. Once a victim reached checkout, the fraudulent site captured card numbers, expiration dates, CVV codes, and one-time passwords (OTPs) in real time, giving attackers everything needed to complete unauthorized transactions.

Researchers observed this was not a single opportunistic site but an organized operation, with multiple operators using shared infrastructure. The FBI reported dozens of fraudulent domains impersonating FIFA, many relying on typosquatting: subtle misspellings or different domain extensions designed to pass a quick glance as the real thing.

Why it succeeded

Several factors made this scam effective:

  • The high demand and once-every-four-year timing of the World Cup pushed fans to move quickly, reducing the time spent scrutinizing a site before entering payment details.
  • Social media ads and shared links carried an implied trust that a typed-in official URL would not have needed to earn.
  • The cloned pages replicated real content like schedules and stadium details, so the visual experience matched expectations of a legitimate ticketing site.
  • Capturing the OTP alongside card data let attackers bypass a control (one-time passcodes) that many people assume makes a transaction safe.

What to watch for

  • A ticket-buying link that arrived through a social media ad, shared post, text message, or unsolicited email rather than a search for the official site.
  • A checkout page requesting an OTP when there is any uncertainty about whether the site is genuinely official.
  • A domain that looks almost right but has a misspelling or an unusual extension compared to the official FIFA site.
  • Deeply discounted tickets, unusually cheap VIP packages, or a seller creating urgency to purchase immediately.

How to build resistance

Organizations with staff who travel, manage events, or handle expense purchases should reinforce a few habits. Buy tickets only through official sources or authorized partners, and avoid third-party sellers that cannot be verified. Encourage people to type the official website address directly rather than clicking links shared on social platforms. Train finance teams and cardholders to treat OTP requests on unfamiliar checkout pages as a signal to stop and verify the site's legitimacy before entering any payment information.

Key findings

  • Attackers cloned FIFA’s official website to make fake ticket sites look legitimate.
  • The scam captures payment card details plus one-time passwords (OTPs) during checkout.
  • Traffic is driven heavily by Facebook and Instagram ads and shared links to fraudulent ticketing pages.
  • Researchers observed an organized operation with multiple active operators using shared infrastructure.
  • The FBI reported “dozens of fraudulent domains impersonating FIFA,” including typosquatted look-alike domains.

Who’s being targeted

  • Commonly targeted roles: All employees, Travel and events coordinators, Executive assistants, Finance (cardholders and expense submitters).
  • Affected industries: Sports and live events, Ticketing and event sales, Consumers/general public, Retail payments and cardholders.
  • Attack channels: website.
  • Impersonated: FIFA (official ticketing), FIFA ticketing / “official” World Cup ticket seller.

Red flags to watch for

  • Website is a look-alike/typosquatted FIFA domain or unusual domain extension
  • Checkout asks for an OTP while the site origin is uncertain
  • The page looks professional but is reached via an untrusted link rather than typing the official site directly
  • Ticket purchase link originates from a social media ad or shared post instead of an official source
  • Pressure tactics or “too good to be true” pricing for high-demand tickets
  • Unverified third-party seller posing as official
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake FIFA ticket sites steal payment information?

The phishing infrastructure captured payment card details, including card numbers, expiration dates, CVV codes, and one-time passwords (OTPs) during the checkout process on cloned FIFA ticketing pages.

How did victims end up on these fraudulent ticketing pages?

Much of the malicious traffic originated from Facebook and Instagram, where advertisements and shared links directed fans to fraudulent ticketing websites.

What is typosquatting and how did it play a role in this scam?

Attackers created look alike websites with subtle misspellings or different domain extensions to trick fans into believing they were visiting the official FIFA website.

How can fans avoid falling for World Cup ticket scams?

Purchase tickets directly from official platforms or authorized partners, avoid links shared on social media or in unsolicited messages, and treat unusually cheap tickets or urgent sales pitches as red flags.

Read the video transcript

You see a Facebook ad for World Cup tickets that looks totally official, FIFA logo, stadium pics, the works. You click through to a site that’s cloned FIFA’s real page, news, match schedules, stadium info, and a slick ticket checkout that asks for your card and an OTP texted to your phone. Here’s the trap: the FBI found dozens of fake FIFA domains with tiny misspellings and odd extensions. If you reached the checkout from a social media ad, and the URL isn’t exactly fifa.com or an official partner, that OTP box is a giant red flag. If you want tickets, don’t touch links in ads or posts. Type the official site address yourself and only buy through FIFA or verified partners.

Similar attacks