SINGAPORE -
Media OutReach Newswire
- 21 July 2026 - Although the tournament itself took place in North
America, Asia's massive football fan base created the perfect conditions
for data leaks.
Fraudsters are capitalizing on football fans by creating fake streaming
platforms and malicious Android applications that steal saved passwords
and account credentials directly from browsers. Criminals are also
setting up fraudulent websites, as well as sending phishing emails to
company employees disguised as gifts, promotions, and office betting
pools.
"
During major global events, the corporate security perimeter is under huge stress," said Francis Yeoh, Country Director at SearchInform Malaysia. "
Employees
access streaming websites from corporate devices to watch matches live.
Traditional network-edge security is insufficient?the real danger comes
from the employee side of the fence.
Employees could watch a translation on a malware-infested website,
they could download streaming applications with hidden malware, or use
corporate credentials to register for fraudulent giveaways."
According to Group-IB and the FBI, from August 2025 to June 2026, more
than 4,300 fake websites were registered fully mimicking FIFA
interfaces, ticketing systems, streaming platforms, and World Cup
employment portals.
How Organizations Can Reduce Cyber Risks During Football Season
- - Monitor the use of corporate devices. Remind employees that
corporate workstations should not be used for personal purposes,
including streaming, downloading unofficial apps, or visiting suspicious
websites. This measure alone can help reduce exposure to many malware
threats.
- - Strengthen password security. Monitor risky password
practices, as some employees may reuse corporate credentials for
personal services. If one of these services is compromised, corporate
accounts and systems may be put at risk as well.
- - Enforce multi-factor authentication. Apply MFA for privileged
employees on a regular basis and temporarily strengthen authentication
requirements for remote employees during high-risk periods. This
provides an additional layer of protection against unauthorized access.
- - Monitor data access patterns. Track who accesses critical
information, from where, and monitor its transmission to prevent data
loss. Make sure protection also covers cloud services, as corporate data
is no longer limited to on-premises storage.