INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

2026 World Cup Attack Surface

| 2026-05-28 10:00 CRITICAL LOW
Executive Summary AI-generated
The 2026 World Cup is a high-profile event that poses significant cyber threats to various sectors, including hospitality supply chains and tournament infrastructure. Iran-nexus activity has been identified as a major risk factor for the tournament, with groups like Group-IB assessing them as potential fronts for Iranian intelligence services. The threat landscape also includes wiper attacks, hacktivist operations, and DDoS and defacement targeting of host-city, federation, and ticketing services. Furthermore, incidents such as the WADA leak and Pyeongchang Winter Olympics cyber attack demonstrate that state-sponsored actors are capable of launching sophisticated cyberattacks against major international sporting events.
Technical Mitigations AI-generated
• Implement robust network segmentation and isolation to limit the attack surface of critical infrastructure, such as internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs). • Conduct thorough vulnerability assessments and penetration testing on all systems hosting World Cup events, including stadiums, arenas, and transportation hubs. • Develop and implement a comprehensive incident response plan that includes procedures for responding to DDoS attacks, ransomware operations, and other types of cyber threats.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation EastwoodOperation Eastwood Scattered SpiderScattered SpiderAPT28APT28 ALPHVALPHVMilanMilanWiperWiperAvengerAvengerOlympic DestroyerOlympic DestroyerBlackCatBlackCat
Target & Sectors
NORTH_AMERICA NORTH_AMERICA GCC GCC financefinance mediamedia defensedefense transportationtransportation healthhealth hospitalityhospitality governmentgovernment technologytechnology energyenergy
Incident Timeline
‎Oct 2020
Iran-Nexus cyber operations targeted various World Cup host cities, including the U.S. and Qatar, with attacks on ticketing systems, hospitality businesses, and digital infrastructure.
tactic Wiper
source_region United Kingdom
tactic Ddos
organisation WADA
organisation Rio
organisation Fighting Ursa
organisation Pyeongchang Winter Olympics
malware Olympic Destroyer
organisation GRU Unit
organisation Sandworm
organisation Iran-Nexus
organisation Storm-0784
organisation IRGC Cyber-Electronic Command's
organisation the Electronic Operations Room
organisation Cyber Support Front
infrastructure Android
infrastructure Ios
organisation FIFA
organisation FanID
organisation Telegram
organisation Cybercriminal Vector Primary
organisation Hotel
organisation TestFlight
organisation RedLine
organisation Account Takeover
organisation Credential-stuffing
organisation Fiddling Scorpius
organisation French Rugby Federation
organisation PII
infrastructure 2024 Multiple cybercriminal groups
organisation Ransomware
organisation Every World Cup
organisation ANSSI
organisation Italian National Cybersecurity Agency
organisation the Tournament Supply Chain Financially
‎March 2022
NoName057(16) used Russian Federation's infrastructure to target Allied Hacktivists between July 2024 and July 2025.
source_region Russian Federation
organisation Allied Hacktivists NoName057(16
infrastructure 3,700 attributed targeted hosts
‎January 2024
Russian cyberattackers used the internet of things (IoT) devices to disrupt water treatment facilities in Texas.
source_region Russian Federation
‎July 2025
French authorities confirmed at least 140 cyber events during the Games, including 22 confirmed unauthorized intrusions and a ransomware attack against the Grand Palais venue.
organisation Operation Eastwood
organisation Documented Impact / Primary Source
threat_actor APT28
infrastructure 16,000 fraudulent domains
organisation PoS
‎December 2025
Threat actors used a compromised VPN service to target the UK National Cyber Security Centre (NCSC) and Eurojust in December 2025.
target_region United Kingdom
organisation Eurojust
organisation Europol
‎January 2026
Iran-nexus actors target host city utility infrastructure, specifically wastewater PLCs, to disrupt operations and create a public health advisory.
target_region United Kingdom
organisation Eurojust
organisation Europol
industry Government
organisation OT Disruption
organisation Host-City Utility During Match Scenario
organisation PLC
financial $10 reward
organisation Recorded Future
organisation Dragonbridge
organisation Cascading-Risk Scenarios
‎Feb. 28, 2026
Iran's involvement in the U.S.–Israel–Iran kinetic conflict has heightened concerns about potential cyber threats to major international events.
target_region Iran, Islamic Republic of
‎late February 2026
Threat actors exploited vulnerabilities in the 2026 World Cup's online ticketing system to gain unauthorized access.
‎February 2026
DieNet launched DDoS attacks against Bahrain and Saudi airports.
organisation DieNet
organisation DDoS
‎between July 2024 and July 2025
NoName057(16) used Russian Federation-associated hacking tools to target Allied Hacktivists between July 2024 and July 2025.
source_region Russian Federation
organisation Allied Hacktivists NoName057(16
infrastructure 3,700 attributed targeted hosts
‎June 11-July 19, 2026
Pre-tournament tabletop exercises with major hotel groups were conducted to inform IT help desk explicit verification protocols.
organisation Mitigation Pre-tournament
‎2026/05/28
Threat actors exploited vulnerabilities in the 2026 World Cup's online ticketing system to gain unauthorized access and steal sensitive information.
infrastructure 16 host cities
‎June 11, 2026
Threat actors exploited vulnerabilities in the tournament's online ticketing system to gain unauthorized access.
target_region Mexico
target_region Jersey
‎early 2026
The Handala Hack Team, a front for Iran's Ministry of Intelligence and Security (MOIS), executed significant wiper attacks in early 2026.
target_region Iran, Islamic Republic of
tactic Wiper
attribution The Handala Hack Team
attribution the U.S. Federal Bureau of Investigation (FBI
attribution Ministry of Intelligence and Security
‎July 19, 2026
The threat actors of concern for the 2026 FIFA World Cup are primarily focused on targeting Israeli-made Unitronics Vision Series PLCs, particularly in U.S. water, energy, and municipal targets.
target_region Mexico
target_region Jersey
organisation Threat Vector Severity Primary Actor
organisation Medium Cybercriminal Hospitality
organisation Medium Pro-Russian
organisation OT
organisation Medium Cybercriminal Table
organisation Ukraine Peace Summit
organisation the Handala Hack Team
organisation NATO
organisation WhatsApp
organisation Apply
organisation MFA
organisation WebAuthn
organisation Unitronics Vision Series
organisation HMI
organisation NFL
organisation MLS
organisation CFL
organisation Liga MX
organisation Rockwell Automation
organisation Islamic Revolutionary Guard Corps
organisation IRGC
organisation Mandate
organisation VMware
organisation SMS
threat_actor Scattered Spider
organisation Patch mobile
organisation Additional Resources
‎the July 19, 2026
The hospitality industry's reliance on remote access tools like TeamViewer and AnyDesk for incident response during the 2026 World Cup pre-tournament audit led to a muddled social-engineering campaign by threat actors.
industry Hospitality
tactic Ransomware
general_metric 48 team
attribution Mitigation Pre-
attribution TeamViewer
attribution OT Default-credential
attribution Final Week Scenario
Tactical Metrics
Metrics
infrastructure
16,000
Fraudulent Domains
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
3,700
Attributed Targeted Hosts
Metrics
infrastructure
2,024
Multiple Cybercriminal Groups
Metrics
infrastructure
16
Host Cities
Metrics
financial
10,000,000
Reward