Fake FIFA Ticket Sites Steal Cards and OTPs

Cyber Defense Magazine · Medium sophistication
Last updated July 30, 2026

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are buying legitimate tickets.

How the attack worked

Criminals built cloned versions of FIFA's official ticketing site, copying tournament news, match schedules, stadium information, and the ticket purchasing flow to make the pages look authentic. Fans arrived at these pages mainly through Facebook and Instagram ads and shared links rather than by navigating directly to an official source. Once a victim reached checkout, the fraudulent site captured card numbers, expiration dates, CVV codes, and one-time passwords (OTPs) in real time, giving attackers everything needed to complete unauthorized transactions.

Researchers observed this was not a single opportunistic site but an organized operation, with multiple operators using shared infrastructure. The FBI reported dozens of fraudulent domains impersonating FIFA, many relying on typosquatting: subtle misspellings or different domain extensions designed to pass a quick glance as the real thing.

Why it succeeded

Several factors made this scam effective:

  • The high demand and once-every-four-year timing of the World Cup pushed fans to move quickly, reducing the time spent scrutinizing a site before entering payment details.
  • Social media ads and shared links carried an implied trust that a typed-in official URL would not have needed to earn.
  • The cloned pages replicated real content like schedules and stadium details, so the visual experience matched expectations of a legitimate ticketing site.
  • Capturing the OTP alongside card data let attackers bypass a control (one-time passcodes) that many people assume makes a transaction safe.

What to watch for

  • A ticket-buying link that arrived through a social media ad, shared post, text message, or unsolicited email rather than a search for the official site.
  • A checkout page requesting an OTP when there is any uncertainty about whether the site is genuinely official.
  • A domain that looks almost right but has a misspelling or an unusual extension compared to the official FIFA site.
  • Deeply discounted tickets, unusually cheap VIP packages, or a seller creating urgency to purchase immediately.

How to build resistance

Organizations with staff who travel, manage events, or handle expense purchases should reinforce a few habits. Buy tickets only through official sources or authorized partners, and avoid third-party sellers that cannot be verified. Encourage people to type the official website address directly rather than clicking links shared on social platforms. Train finance teams and cardholders to treat OTP requests on unfamiliar checkout pages as a signal to stop and verify the site's legitimacy before entering any payment information.

Key findings

  • Attackers cloned FIFA’s official website to make fake ticket sites look legitimate.
  • The scam captures payment card details plus one-time passwords (OTPs) during checkout.
  • Traffic is driven heavily by Facebook and Instagram ads and shared links to fraudulent ticketing pages.
  • Researchers observed an organized operation with multiple active operators using shared infrastructure.
  • The FBI reported “dozens of fraudulent domains impersonating FIFA,” including typosquatted look-alike domains.

Who’s being targeted

  • Commonly targeted roles: All employees, Travel and events coordinators, Executive assistants, Finance (cardholders and expense submitters).
  • Affected industries: Sports and live events, Ticketing and event sales, Consumers/general public, Retail payments and cardholders.
  • Attack channels: website.
  • Impersonated: FIFA (official ticketing), FIFA ticketing / “official” World Cup ticket seller.

Red flags to watch for

  • Website is a look-alike/typosquatted FIFA domain or unusual domain extension
  • Checkout asks for an OTP while the site origin is uncertain
  • The page looks professional but is reached via an untrusted link rather than typing the official site directly
  • Ticket purchase link originates from a social media ad or shared post instead of an official source
  • Pressure tactics or “too good to be true” pricing for high-demand tickets
  • Unverified third-party seller posing as official
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake FIFA ticket sites steal payment information?

The phishing infrastructure captured payment card details, including card numbers, expiration dates, CVV codes, and one-time passwords (OTPs) during the checkout process on cloned FIFA ticketing pages.

How did victims end up on these fraudulent ticketing pages?

Much of the malicious traffic originated from Facebook and Instagram, where advertisements and shared links directed fans to fraudulent ticketing websites.

What is typosquatting and how did it play a role in this scam?

Attackers created look alike websites with subtle misspellings or different domain extensions to trick fans into believing they were visiting the official FIFA website.

How can fans avoid falling for World Cup ticket scams?

Purchase tickets directly from official platforms or authorized partners, avoid links shared on social media or in unsolicited messages, and treat unusually cheap tickets or urgent sales pitches as red flags.

Read the video transcript

You see a Facebook ad for World Cup tickets that looks totally official, FIFA logo, stadium pics, the works. You click through to a site that’s cloned FIFA’s real page, news, match schedules, stadium info, and a slick ticket checkout that asks for your card and an OTP texted to your phone. Here’s the trap: the FBI found dozens of fake FIFA domains with tiny misspellings and odd extensions. If you reached the checkout from a social media ad, and the URL isn’t exactly fifa.com or an official partner, that OTP box is a giant red flag. If you want tickets, don’t touch links in ads or posts. Type the official site address yourself and only buy through FIFA or verified partners.

Similar attacks

Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Pink Vishing Tricks Staff Into Entra Passkeys

Pink Vishing Tricks Staff Into Entra Passkeys

The “Pink” data extortion group is running a real-world voice phishing campaign targeting employees in Microsoft 365 / Entra ID environments. Callers impersonate the internal IT helpdesk and direct staff to realistic lookalike login sites timed to Microsoft’s passkey-enrollment prompts, enabling…

July 16, 2026
Fake FBI ‘IC3 Help’ Scams Hit Victims Twice

Fake FBI ‘IC3 Help’ Scams Hit Victims Twice

The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social media messages, and even AI-generated videos to push victims to spoofed IC3 websites or to hand over more personal and financial information,…

July 21, 2026