'Fake FIFA Ticket Sites Steal Cards, Intercept OTPs in Global Scam Campaign'
CloudSEK, the cybersecurity firm, finds a global FIFA World Cup 2026 ticket scam using cloned websites, card skimming, and OTP interception to steal payments from fans
Football fans searching for FIFA World Cup 2026 tickets are being targeted by a sophisticated cybercrime operation that uses fake FIFA ticketing websites capable of stealing payment card details and intercepting one-time passwords (OTPs), according to cybersecurity firm CloudSEK.
Researchers uncovered at least 40 fraudulent FIFA-themed websites linked to a Chinese-origin threat network. Unlike conventional phishing campaigns, the operation reportedly functions as a real-time man-in-the-middle framework, allowing attackers to monitor victims during checkout, capture card information, and potentially bypass SMS-based two-factor authentication by relaying OTPs in real time.
CloudSEK said the scam infrastructure includes a rogue payment processing platform and supports at least 15 active criminal operators through a Chinese-language administrative backend. The fraudulent websites closely mimic official FIFA ticketing portals with realistic branding,...
Copyright of this story solely belongs to ciol.com. To see the full text click HERE