A recent report from threat analysts at Hoxhunt reveals alarming statistics on the massive spike in cyberthreats surrounding the World Cup. Between April and June of 2026, phishing attacks themed around FIFA World Cup 2026 increased by nearly 500%, with a notable surge timed precisely to coincide with the kickoff of the tournament. This wave of attacks outpaces every prior entertainment or sporting event on record.
How the Attack Built Momentum
Attacks related to the World Cup built up slowly over several months before the extreme surge in malicious behavior, with quiet early activity detected as far back as February. The sharp acceleration of these attacks began in May, in the weeks leading up to the opening of the tournament.
The attacks related to the World Cup outweighed attacks observed around the Paris 2024 Olympics and Eurovision 2026, demonstrating the particular popularity of the event. The World Cup takes place in multiple countries, with dozens of teams participating and over 100 individual games. These factors create a landscape that is primed for bad actors to launch attacks.
Lures Crafted Around the Tournament
Threat actors taking advantage of the World Cup to carry out phishing attacks have been observed using a variety of lures designed to deceive targets. One type of campaign commonly seen involves attackers impersonating FIFA marketing and recruitment officials, often targeting professionals with fake offers of job opportunities. This attack led to a browser-in-the-browser page disguised as a Google sign-in prompt and designed to harvest credentials from its victims.
Another popular campaign type is prize and bundle scams impersonating official Coca-Cola promotion activity. Impersonating a leading brand that commonly sponsors global sporting events allows attackers to leverage sponsor trust to their advantage, especially as these false offers are often hidden among legitimate brand communications.
Beyond Email: The Mobile Underground
While the Hoxhunt report bases its findings on received and reported inbox threats, malicious activity related to the World Cup is not confined to email. A Zimperium report published in June explores the broader landscape of mobile threats around the tournament, focusing on three main campaigns:
- Fake ticket sites using typosquatting and spoofing to clone the real flow of FIFA’s purchase process, taking advantage of the desperation of fans looking to score high-value, scarce tickets.
- Counterfeit merchandise scams through WhatsApp, leveraging trust in brand names like Nike and Adidas, forcing viral propagation by requiring targets to share the lure in order to obtain a merchandise prize.
- OffsideHire and other fake careers portals built to intercept MFA in real time and deceive targets by impersonating FIFA’s real careers page.
The Psychology of Expected Urgency
One of the central tenets of social engineering tactics like phishing is a focus on making offers that seem time-sensitive for one reason or another. Temporal lures are 42% more likely to draw clicks than non-temporal ones, leveraging the psychological urgency that makes victims less cautious about clicking unauthenticated links.
Beyond taking advantage of users feeling the need to act on offers while they’re still good, the timing of attacks around the World Cup also means that fans and employees are already primed to expect the types of promotions, travel, and ticketing messages that malicious activity can hide among. In this way, legitimate World Cup communications provide cover for malicious ones, lulling targets into a false sense of security and trust.
AI Accelerating the Threat
Threats related to the World Cup are far from immune to the strongest attack accelerant of the last several years: attackers leveraging AI tools to increase the success rates and payouts of their campaigns. Hoxhunt observed a 14x surge in AI-generated phishing at the turn of 2025-26 as attackers increasingly lean on AI-enhanced methods for their malicious activity. With the help of AI tools, polishing and localizing phishing messages at scale is now trivial across languages and regions, enabling threat actors to launch higher volumes of far-reaching attacks.
Attackers treat major global events as reusable infrastructure for future campaigns, not one-off stunts. “Just as legitimate marketing teams use automation platforms to launch personalized campaigns around major cultural events and seasonal buying patterns, cybercriminals are using AI to orchestrate phishing campaigns around the moments that matter most to their targets,” says Mika Aalto, Co-Founder and CEO at Hoxhunt, a Helsinki-based Human Risk Management Platform. “The World Cup, tax season, annual bonus announcements, open enrollment, Black Friday—every event that drives legitimate communication now creates an opportunity for attackers to blend in.”
The Bigger Blind Spot
The large volume of attacks surrounding the World Cup is not an isolated incident, but a symptom of a much broader issue of attacks on the sports industry. According to a recent report by Darktrace, 84% of sports organizations have been hit by at least one cyber incident in the previous 12 months, and more than half (57%) have been hit more than once.
Darktrace also observed 19% more phishing attacks in sports sector inboxes than in other industries. When surveyed, nearly three in four (72%) sports professionals expect the continued presence and growth of AI to raise their level of cyber risk over the next 12 months.
Preparing for the Next Global Moment
Hoxhunt offers several recommendations for organizations to protect against the slew of threats that accompany major global events like this. Running event-themed simulations before and during high-attention windows can help employees recognize the types of attacks they’re likely to encounter. Role-based training for marketing, HR, travel, and executive functions can empower individuals to meet the specialized lures that may be deployed in their inboxes. Organizations should also base their awareness training and content on real-time threat reporting rather than static training windows.
The World Cup is not just a single event that invites a high volume of cyberattacks. It serves as a preview and demonstration of how major calendar events will continue to be exploited in the future. The immense spike in malicious activity is likely to be replicated in upcoming events.