FIFA World Cup 2026 fans targeted by OTP-bypass scam: CloudSEK

https://cdn1.expresscomputer.in/wp-content/uploads/2024/08/05150227/EC-cyber-security-technology-750.jpg

Threat intelligence researchers at CloudSEK have identified a large-scale cyber fraud operation targeting football fans searching for FIFA World Cup 2026 tickets, warning that the campaign combines phishing, payment card theft and potential one-time password (OTP) interception capabilities.

According to the company’s findings, the operation leverages a network of fraudulent websites designed to closely mimic legitimate FIFA ticketing portals. Researchers believe the campaign is linked to threat actors of Chinese origin and operates through a scalable fraud-as-a-service model supporting multiple criminal operators.

The discovery comes as demand for FIFA World Cup 2026 tickets remains high, creating opportunities for cybercriminals to exploit fans seeking tickets and travel packages online.

Beyond traditional phishing

CloudSEK researchers noted that the operation differs from conventional phishing campaigns by functioning as a real-time man-in-the-middle (MitM) framework.

The fraudulent infrastructure is reportedly capable of monitoring victims throughout the ticket-purchasing process, capturing payment card information, including card numbers,...

Copyright of this story solely belongs to expresscomputer.in. To see the full text click HERE

Read more

https://assets.bwbx.io/images/users/iqjWHBFdfxIU/imZqKnFL0nLU/v0/1200x800.jpg

Australia-based Firmus partners with Nvidia to build its first data center in Batam, Indonesia; the 360 MW Nvidia DSX AI factory campus is developed with DayOne

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.