The final whistle has blown on the world cup. Here are our winners and losers.
On July 19th, the World Cup came to a close at MetLife Stadium, with Spain crowned worthy champions after a tense extra-time win over Argentina.
But away from the pitch, cybercriminals were also on the attack.
As a billion fans watched, attackers set up over 13,000 fake websites. These ranged from fake merchandise stores to exact copies of FIFA’s site. One group may have stolen as much as $474 million from fans.
We recap what happened, what it cost, and what we can learn about preparing for the next time a global event turns excitement into exposure.
Game of the Tournament: excitement vs. judgment.
One theme ran across almost every attack this tournament: excitement overriding judgment.
The clearest example was a campaign offering free World Cup t-shirts to employees through a supposed FIFA partnership with their own organization. Seeing their own company’s branding on the shirt was enough to convince people it was genuine.
Driven by FOMO, (the fear of missing out), employees clicked the personalized link without a second thought, infecting their networks with a malware strain called Voidrift.
The email had slipped past three of the most widely used secure email gateways.
Breakout Performance: AI learned to speak every fan’s language.
One group, tracked by researchers under the name GHOST STADIUM, ran a single phishing kit across more than 300 live domains, cloning FIFA’s own login flow.
The kit auto-detected each visitor’s language and served the page in 11 languages, including three separate Chinese variants.
This is the campaign behind that $474 million figure, and AI-driven automation is what made that scale possible in the first place.

Biggest Disappointment: repeating the same mistakes.
None of this was a surprise. At the last two big global sporting events, Qatar 2022 and Paris 2024, we saw similar activity.
Both were treated as the story at the time, then filed away once the closing ceremony ended. Years later, the same playbook (fake ticketing sites, credential harvesting through official-looking portals, fraud at scale) ran again almost unchanged, just faster and better-dressed with AI.
The disappointment isn’t that criminals showed up. It’s that the lessons from last time clearly never made it into anyone’s plan for this one.
Goal of the Tournament: Make cyber defense a team game.
No single department caught these campaigns alone.
GHOST STADIUM, the operation behind hundreds of fake FIFA domains, was only fully mapped once brand protection teams, payment providers, and researchers started comparing notes: one confirmed fake domain was how the other 300 got found.
It took different teams, and in this case, different companies entirely, in the same room, working from the same picture.
Unsung Hero: the teams that trained, not just warned.
The organizations that came out ahead did the unglamorous work early.
They assumed their email gateway alone wouldn’t catch everything, so they trained and empowered people to report anything that looked personalized but slightly off, and those reports actually got acted on.
They tested their own public pages from outside the usual scanning locations, catching gaps before an attacker could. And they knew exactly how fast they could revoke a compromised login, because they’d rehearsed it before they ever needed it.
That preparation, done quietly and well ahead of kickoff, is exactly why it worked.
The Final Score.
So, as the curtain falls on another World Cup, what have we learned from this latest edition that we can take with us and keep us safe in the future?
Any event that builds real collective excitement also lowers collective awareness, and attackers know it well enough to plan around it months in advance.
That’s true whether it’s a football tournament, a global music tour, or whatever comes next. The organizations that came through this one well didn’t try to dampen the excitement. They trained their people before the crowd arrived, tested their own defenses ahead of time, and made sure security wasn’t working from a different picture than HR, comms, and everyone else.
Stay excited. Just make sure the whole team is ready first, and you’ll come out on top, just like Spain did.
This article was written by Cywareness, a company specializing in cybersecurity awareness.
As part of its mission, Cywareness continues to monitor emerging trends, analyze real-world attacks, and share practical insights to help organizations stay ahead in today’s evolving threat landscape.