Skip to main content

Netskope Details World Cup-Themed Cyber Threat Spike During the 2026 FIFA World Cup

Netskope reports a spike in attempts to access World Cup-themed malicious content during the 2026 FIFA World Cup, with near sixfold increases at peak and more than 28,000 threats blocked across over 1,000 organizations.

Research Overview

The vendor analyzed World Cup-related web activity during the tournament period and tracked users attempting to reach malicious destinations using World Cup themes.

Netskope states that malicious attempts rose around the tournament start and continued through the end of the event.

Key Findings

At its highest point, Netskope recorded nearly six times the pre-tournament average number of users attempting to access World Cup-themed malicious content.

Across the tournament, Netskope says it detected and stopped more than 28,000 World Cup-themed threats affecting more than 1,000 organizations worldwide.

Threat Analysis

Netskope highlights phishing and credential scams that used social engineering to obtain account details.

The vendor describes fraudulent job postings that prompted victims to log in to apply and included a fake videoconference join page for interviews, with the goal of credential harvesting.

Technical Breakdown

Another pattern Netskope reports involved fake streaming websites aimed at capturing traffic tied to match viewing demand.

Netskope says these portals used deceptive tactics, including payment prompts and subscription traps, and also used search engine optimization to appear favorably in search results.

Operational Impact

Netskope also reports file-based malware distributed under World Cup-themed lures, including content framed as helping users secure tickets or stream matches.

Netskope states the payloads were typically commodity infostealers designed to harvest credentials and other sensitive data from victims’ computers.

The report frames the World Cup as a recurring lure for multiple malicious activity types, including credential scams, fake streaming portals, and infostealers, with measured increases in malicious access attempts during the event. For enterprise IT and security leaders, the observed scale supports continued real-time web inspection and policy enforcement during high-interest global events. Blog Signals brief is a fact-based summary of the vendor blog.