FIFA World Cup 2026 fans targeted by OTP-bypass scam: CloudSEK
Threat intelligence researchers at CloudSEK have identified a large-scale cyber fraud operation targeting football fans searching for FIFA World Cup 2026 tickets, warning that the campaign combines phishing, payment card theft and potential one-time password (OTP) interception capabilities.
According to the company’s findings, the operation leverages a network of fraudulent websites designed to closely mimic legitimate FIFA ticketing portals. Researchers believe the campaign is linked to threat actors of Chinese origin and operates through a scalable fraud-as-a-service model supporting multiple criminal operators.
The discovery comes as demand for FIFA World Cup 2026 tickets remains high, creating opportunities for cybercriminals to exploit fans seeking tickets and travel packages online.
Beyond traditional phishing
CloudSEK researchers noted that the operation differs from conventional phishing campaigns by functioning as a real-time man-in-the-middle (MitM) framework.
The fraudulent infrastructure is reportedly capable of monitoring victims throughout the ticket-purchasing process, capturing payment card information, including card numbers,...
Copyright of this story solely belongs to expresscomputer.in. To see the full text click HERE