The GHOST STADIUM phishing campaign has emerged as a major cyber threat targeting fans of the 2026 FIFA World Cup. Security researchers uncovered a large-scale fraud operation involving more than 300 phishing domains and over 3,500 fraudulent websites impersonating FIFA-related services. The campaign is designed to steal user credentials, financial information, and payments through fake ticketing portals, counterfeit merchandise stores, fraudulent betting sites, and fake streaming platforms. The attackers use a highly convincing phishing kit that closely replicates FIFA's official website and login process, making it difficult for users to distinguish between legitimate and malicious pages. The campaign has gained traction due to the massive demand for FIFA World Cup tickets and related services. With millions of fans competing for limited ticket availability, cybercriminals are exploiting the urgency and excitement surrounding the tournament. The threat actor known as GHOST STADIUM leverages targeted advertisements, fake promotions, and social engineering tactics to lure victims to fraudulent websites. In addition, credentials harvested through infostealer malware families such as Vidar and Lumma are being sold on underground markets, further expanding the attack surface and enabling account takeover activities. Researchers attribute the operation to a financially motivated Chinese-speaking threat actor based on technical indicators found within the phishing infrastructure. The campaign demonstrates a well-organized ecosystem that combines phishing, credential theft, malware distribution, and payment fraud. Organizations and individuals are advised to use official FIFA channels, enable multi-factor authentication, avoid suspicious advertisements, and continuously monitor for signs of phishing activity to reduce the risk of compromise.
Charter Communications has confirmed a cybersecurity incident impacting millions of customers following a breach allegedly conducted by the ShinyHunters extortion gang. According t...
A critical Remote Code Execution (RCE) vulnerability has been identified in Samba, the widely used open-source SMB/CIFS file-sharing software for Linux and Unix systems. The flaw c...
A sophisticated cyber-espionage campaign linked to the Iran-aligned threat group Seedworm has targeted at least nine organizations across multiple countries during early 2026. The ...