FBI Warns of Fake FIFA Websites Ahead of 2026 World Cup Scams
FBI Warns of Fake FIFA Websites Ahead of 2026 World Cup

With excitement mounting for the 2026 FIFA World Cup, cybercriminals are exploiting the buzz by creating fake FIFA websites to steal personal data and peddle fraudulent tickets. The FBI has issued a public service announcement warning the public about these threats.

FBI Issues Warning on Spoofing Attacks

On May 27, the FBI released a public service announcement stating that threat actors are conducting spoofing attacks against FIFA-related websites. They create lookalike domains that closely mimic the official FIFA site. “The FBI has identified actors engaging in this activity to collect personal information, sell fake World Cup tickets and hospitality products, and to possibly facilitate other malicious activity,” the agency noted.

The legitimate FIFA website is hosted at fifa.com. However, scammers have registered numerous domain variations, including fifa-com[.]com and jobs-fifa[.]com, to trick users into believing they are interacting with official FIFA services.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Thousands of Fake FIFA Domains Detected

The scale of the campaign is significant. Cybersecurity firm Group-IB reported that it has identified more than 4,300 fraudulent domains impersonating FIFA’s official web presence since August 2025. The company also linked a Chinese-speaking scam group to over 300 of these domains. The operation allegedly uses a “pixel-perfect clone of the official FIFA website, complete with a replicated single sign-on (SSO) authentication flow, and multi-language support in 11 languages.”

According to Group-IB, the fraudulent websites have been promoted through Facebook advertisements and fake World Cup ticket offers to attract potential victims. The FBI explained that attackers often use typo squatting, where domains contain minor spelling changes or alternative domain extensions to imitate legitimate websites.

“This form of cyberattack — called typo squatting — relies on Internet users making mistakes, such as common typos, when visiting a URL. Threat actors may also register illegitimate websites such as jobs-fifa[.]com to impersonate legitimate subdomains,” the FBI added.

List of Fake FIFA Websites Identified by the FBI

The agency has identified dozens of suspicious domains impersonating FIFA, including:

  • fifa[.]cab
  • fifa[.]pink
  • fifa[.]blue
  • fifa[.]pub
  • FIFA[.]city
  • Fifa[.]bio
  • fifa[.]beer
  • fifa[.]click
  • fifa[.]cam
  • fifa[.]ceo
  • fifa[.]help
  • filfa[.]org
  • fifa-online[.]com
  • fifa-2026[.]xyz
  • jobs-fifa[.]com
  • fifa-hr[.]com
  • fifa-careerhub[.]com
  • fifaworldcup-careers[.]com
  • fifa-hiring[.]com
  • fifahiring[.]com
  • fifa-ticket[.]live
  • fifastore.us[.]com
  • fifaworldcup26[.]sale
  • fifaworldcup26.xcover-staging[.]com
  • worldcup2026-tickets.com[.]mx
  • worldcup26ticket[.]com
  • 2026fifaworldcuptickets[.]online
  • fwc2026[.]net
  • fwc2026.web[.]app
  • fifa2026p[.]com
  • fifa2026fworldcup[.]com
  • wvvw-fifa[.]com
  • ww-fifa[.]com
  • fifa-com[.]com
  • fifa-com[.]services
  • quiniela-fifa-2026.pages[.]dev

The FBI warned that additional fake websites are likely to appear before and during the tournament.

FBI Advises Caution When Searching for FIFA Websites

To reduce the risk of fraud, the FBI recommends typing fifa.com directly into a browser’s address bar instead of relying on search engine results. The agency also advised users to avoid clicking on sponsored search results, which could lead to imitation websites.

“If using a search engine, avoid any ‘sponsored’ results as these can be paid imitators looking to deter traffic from the legitimate FIFA website,” the FBI noted in its warning.

Other safety tips include using bookmarks to visit official websites, ensuring URLs end in “.com”, avoiding dubious links or advertisements, and never sharing sensitive information unless the legitimacy of a website is confirmed.

Victims of these scams or those who suffer financial losses should report the incident to the FBI through its Internet Crime Complaint Center (IC3) and provide as much information as possible, including the fake website, any personal information provided, and payment-related details when applicable.

Pickt after-article banner — collaborative shopping lists app with family illustration