As millions of football fans around the world tune in to watch the FIFA Club World Cup, cybercriminals are cashing in on the excitement, using fake streaming sites, betting platforms and phishing emails to steal money and personal information.
Cybersecurity company Kaspersky says it has detected at least 336 unique domains impersonating official tournament resources since the competition kicked off on 11 June. The company warns that scammers are increasingly targeting supporters eager to watch matches live, place bets or access match predictions.
One of the most common scams involves fake streaming websites promising free access to matches. Users are encouraged to click a “Watch now” button and register for access. They are then asked to pay a cryptocurrency fee for what is advertised as lifetime tournament access.
Instead of gaining entry to a live match, victims risk losing both their money and personal information.
Football betting enthusiasts are also being targeted through fraudulent prediction and betting websites. In one case identified by Kaspersky, a platform asked users to provide extensive personal details, including their full names, email addresses and phone numbers, under the guise of creating an account.
Security experts warn that such information can be used for identity theft or to gain access to other online accounts, particularly when users recycle passwords across multiple platforms.
“Since the start of the tournament, scammers have increasingly focused on the ways fans engage with the event online, as watching matches today requires only an internet connection and a device,” said Olga Altukhova, senior web content analyst at Kaspersky.
“As a result, criminal activity continues to grow, as reflected in the fraudulent websites we observe offering streaming and betting services in multiple languages. We recommend that users stick to official broadcasts to help protect their data and finances.”
The scams do not end there.
Cybercriminals are also sending emails designed to exploit fans’ hopes of gaining an edge on match outcomes. In one example, recipients were offered access to football analytics and winner predictions for a fee of $200.
The emails often create a false sense of urgency, pressuring fans to act quickly before an opportunity supposedly disappears, a tactic commonly used in phishing campaigns.
With football fever running high, cybersecurity experts are urging supporters to think twice before clicking unfamiliar links, handing over personal information or paying for unofficial services.
For fans hoping to enjoy the tournament without becoming the next victim, the safest bet may be sticking to official broadcasters and trusted platforms.