Fake World Cup streaming sites are targeting virtual fans

how to prevent phishing attacks
(Image credit: Unsplash)

Zscaler has issued a warning to football fans looking to watch the World Cup online via streaming sites.

The company's latest Zscaler TheatLabz research found there has been a recent spike in cyber attacks targeting football fans using fake streaming sites and lottery scams, which is “leveraging the rush and excitement around these uncommon events to infect users with malware.”

The study found a recent increase in domain registrations relating to the World Cup, which is to be expected as more companies ramp up their football-related offerings online.

Numerous threats

Following analysis to “weed out hidden offenders”, Zscaler has presented a number of alarming case studies.

Most concerning is the usage of legitimate websites and portals - including Xiaomi, Reddit, OpenSea, and LinkedIn - that are hijacked to post fake streaming links.

This included one example where victims are enticed to visit a malicious site claiming to offer live streaming of the FIFA World Cup 2022 opening ceremony. 

However this redirects to a fake streaming site hosted on Blogspot, where users are prompted to create an account for free access to watch the live streaming event, giving away personal information or payment data to the scammers.

Attackers are also targeting users with malicious cracked version of games related to FIFA or football as a whole, including scam sites trying to collect fake ticket fees or steal payment card details.

ThreatLabz also detected a scam where users are offered prize money and airline tickets by Qatar Airways, and another campaign sending fake lottery emails and pretending to be a Qatar FIFA World Cup 2022 lottery committee.

As a whole, the firm suggests that users are wary of promises of match tickets, airline tickets, and themed lottery draws. 

Fortunately, the warning doesn’t come without solutions. As well as using authorized vendors and verified sites, Zscaler recommends avoiding downloading any software or games from untrusted sites and being aware of fraudulent emails, which can be checked in a number of ways including verifying the sender domain.

Further safety procedures, like utilizing HTTPS/secure connections, two-factor authentication (2FA), and even setting up a firewall are also advised.

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A man falling into a mobile phone screen.
Safer Internet Day: how to avoid online scams and stay safe online
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
A light pink gift box with blush pink bow, red hearts and confetti on a pastel pink background.
How to spot Valentine’s Day scams - stay safe on this most special day with our security tips
Robotic hand clicking on captcha 'I am not a robot'.
Fake CAPTCHAs are being used to spread malware - and we only have ourselves to blame
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
A Lego Pikachu tail next to a Pebble OS watch and a screenshot of Assassin's Creed Shadow
ICYMI: the week's 7 biggest tech stories from LG's excellent new OLED TV to our Assassin's Creed Shadow review
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models