Hero image for FBI: 19,000 Fake FIFA Sites Are Live Right Now
By Travel Tools Guide Team

FBI: 19,000 Fake FIFA Sites Are Live Right Now


The tournament opens Thursday. And the FBI wants you to know that before you click on anything labeled “FIFA tickets” in a search result, there’s a reasonable chance you’re about to hand your credit card to a criminal.

On May 27, the FBI’s Internet Crime Complaint Center published PSA260527, a formal warning that cyber actors are running large-scale spoofing operations against FIFA’s official websites. Not “might be.” Are. Active, live, already running when you read this.

The numbers make the scope clearer. Since January 2026, more than 19,000 domains containing “FIFA” have been registered — the vast majority by people who have nothing to do with the tournament. Insikt Group documented over 600 typosquat domains that directly mimic fifa.com itself. And according to BleepingComputer’s reporting on the PSA, that count was rising weekly as June 11 approached.

The two things fans are scrambling to do right now (buying last-minute tickets and booking accommodation) are exactly the two things these sites are built to intercept.

The Threat at a Glance

StatDetail
FBI warning issuedPSA260527, May 27, 2026
Fake FIFA domains since January19,000+
Direct typosquats of fifa.com600+ (Insikt Group)
Ticket scam increase36% year-over-year (Lloyds Bank)
Average victim loss£215 (~$270) — some lost thousands
Accommodation impersonation56% of all observed fraud activity (Check Point)
April domain surge alone9,741 new FIFA-themed domains in one month

The short version: Fraudsters built the infrastructure before the tournament started. You’re in the peak exposure window right now.

What the FBI Actually Said

PSA260527 is worth reading in full, but the core warning is specific. Fake sites are designed to do two things: steal personally identifiable information (name, address, phone, email, banking details), and sell tickets that won’t get anyone through the gate.

The method is typosquatting. A fraudulent site might live at fiffa.com, fifa-tickets-2026.org, or worldcup2026-official.com. Some use alternative top-level domains (.xyz, .live, .sale) to look plausible at a glance. Others clone the exact design of FIFA’s real site: the colors, the logos, the ticket purchase flow. Everything looks right until you look at the URL.

The FBI’s specific guidance: do not use search engines to navigate to FIFA’s ticketing site. Type fifa.com directly. Sponsored search results (the ones at the top of a Google search) can be paid placements by fraudulent sites. The FBI called this out explicitly. A site that bought the ad for “buy FIFA World Cup tickets” is not automatically legitimate. It’s possibly the opposite.

How Do You Spot a Fake FIFA Ticketing Site?

  1. Check the domain carefully. FIFA’s official presence is fifa.com and fifa.com/fifaplus. Any URL with extra words, hyphens between “FIFA” and other terms, or an ending other than .com warrants suspicion.
  2. Skip every sponsored search result for ticket purchases. Navigate directly to the URL. Don’t click ads for FIFA tickets or hospitality packages regardless of how official they look.
  3. Verify the SSL certificate hostname. Click the lock icon in your browser. The certificate should be issued to fifa.com — not a variation of it.
  4. Watch the payment method. FIFA’s platform uses credit card processing through official payment providers. Any site requesting Venmo, Zelle, wire transfer, crypto, or “bank transfer for international buyers” is a scam.
  5. Reject paper-only ticket offers. FIFA uses a digital transfer system tied to FIFA accounts. Any seller offering PDF tickets, photo attachments, or “printable” tickets cannot actually transfer a valid ticket.
  6. Ask about the transfer method. Legitimate FIFA ticket resale requires a transfer through the official FIFA ticket resale platform. If a seller can’t walk you through that process, the ticket doesn’t exist or won’t scan.

The Accommodation Scam Nobody Is Talking About

Fans fixate on ticket fraud, reasonably. But Check Point Research found that accommodation brands account for 56% of all observed World Cup-related impersonation activity — more than ticket sites.

The mechanics are nastier than a standard phishing email. In April 2026, Booking.com confirmed a data breach that exposed customer names, emails, phone numbers, travel dates, and property details. Criminals are using that data to run targeted scams: contacting travelers with messages that reference your correct reservation dates, the correct property name, and your real contact details, then requesting payment through an external link for an “outstanding balance” or “security hold.”

The scammer already knows details about your actual booking. That creates false trust that a generic phishing message doesn’t have.

The ask is always the same: pay through Zelle, Venmo, wire transfer, or an external link — for an issue with your reservation. Any payment request that comes outside the original booking platform should be reported to the platform immediately. Not clicked. Not replied to. Reported.

If you’re still securing accommodation — and the hotel situation for World Cup host cities is already difficult — book through verified platforms only and complete every payment inside those platforms. Not in a DM.

What Lloyds Bank Found

Lloyds Bank tracked fake ticket scams across English football from October 2025 through March 2026 and documented a 36% year-over-year increase in fraud. Average victim loss: £215 (roughly $270). Total losses across victims were up 42% — meaning more people hit, and those who were hit losing more.

Lloyds expects the World Cup to amplify every one of these patterns. The tournament generates international demand that bypasses the normal network checks people use to vet local ticket sellers. You don’t know if someone claiming to be selling Dallas tickets is who they say they are. The pressure to act fast — “other buyers are interested, wire by tonight” — is standard fraud and it works.

The scams targeting club football look identical to World Cup ticket fraud: fake social media listings, urgency pressure, bank transfer requests. The same playbook applied to a tournament that’s an order of magnitude larger.

The Fake App Problem

The FBI’s PSA covers websites, but the threat extends to apps. Before downloading any FIFA-related app, check the developer in the App Store or Google Play. The official FIFA app is published by FIFA — not “FIFA Tournament Media Ltd.” or “FIFA Official Fan Store.”

Fake apps request the same permissions as the real app, collect the same personal data, and deliver nothing. Any app with fewer than 1,000 reviews or published within the last six months by an unfamiliar developer: skip it. The official FIFA+ app has millions of installs and an established publisher profile.

This matters more if you’ve already had problems with the FIFA app at the stadium gate. Fans who’ve experienced the official app failing sometimes look for alternatives. There are no legitimate alternatives for FIFA ticket management — only scams that look like them.

What Legitimate Resale Actually Looks Like

If you need tickets now, the only legitimate secondary market is FIFA’s official ticket resale platform, accessible through your FIFA account at fifa.com. The transfer process requires both buyer and seller to have active FIFA accounts. The seller initiates a transfer through the platform. You receive a notification and confirm. The ticket migrates to your account with a new QR code.

What it doesn’t look like:

  • A seller emailing a PDF attachment
  • A screenshot of a QR code sent over WhatsApp
  • A ticket “transferred” via a third-party site claiming to be FIFA-authorized
  • Any seller who says they’ll do the transfer “after payment clears”

Group-IB identified six parallel fraud schemes active during this tournament cycle, run by at least four independent criminal groups. Some operations are sophisticated enough that the fake ticket arrives with a QR code that looks valid — until it hits the scanner at the stadium entrance. At that point, you’re standing outside trying to find someone at a fan support tent during match kick-off.

Don’t test this in person. The fraud detection happens at the gate, not before.

How This Connects to Everything Else Going Wrong

World Cup logistics already have enough legitimate failure points. Uber is banned at Mexico City’s airport, meaning fans heading to Estadio Azteca are navigating ground transport in an unfamiliar city without their default app. The tools most travelers rely on are working differently in tournament host cities.

When you’re already stressed about logistics, scammers count on that distraction. Urgency plus unfamiliarity is the combination that makes people click links they’d normally scrutinize.

The AI booking tools helping fans navigate the crunch — KAYAK Ask AI and Google Flights Canvas — are useful for finding legitimate options, but neither tool checks whether the URLs it surfaces are legitimate. That’s your job. If an AI planner gives you a link to buy tickets or book a hotel, verify the domain before completing any payment.

If You Get Hit: What to Do

Acting fast matters.

  1. File at IC3.gov immediately. The FBI’s Internet Crime Complaint Center is the formal reporting channel. Report the domain, the transaction, and every detail you have.
  2. Contact your bank or card issuer the same day. Fraud disputes are easier to win when filed within hours. Waiting until you’ve confirmed the scam cost you the dispute window.
  3. Screenshot everything. The fake site, the seller’s messages, the payment confirmation. You’ll need it for the dispute and for the IC3 complaint.
  4. Report the domain to the FBI via IC3.gov. The FBI is tracking which domains are active. Your report contributes to takedown efforts.

The Full Protection Checklist

Before booking anything:

  • Bookmark fifa.com right now. Use that bookmark every time you need the site.
  • Navigate directly — never from a search result, never from an email link.
  • When searching for World Cup tickets on Google, scroll past every sponsored result.

When buying tickets:

  • Only use FIFA’s official resale platform (accessible at fifa.com while logged in to your FIFA account).
  • Accept transfers only through FIFA’s system — not email, WhatsApp, or third-party sites.
  • If a seller pressures you to move fast or pay via Venmo, Zelle, wire, or crypto: they’re a scammer.

When booking hotels:

  • Complete all payments inside the original booking platform.
  • If you get an email or SMS about your reservation with an external payment link, don’t click it. Go directly to the platform and check your booking there.
  • Disregard any outreach — even from what appears to be your booked property — asking for payment through an external channel.

If something seems off:

  • Report it to IC3.gov.
  • Report the account to the social media platform or marketplace where you found it.
  • Do not send money while waiting to see if the situation resolves.

The Bottom Line

The FBI doesn’t issue formal Public Service Announcements as routine caution. PSA260527 exists because the infrastructure for defrauding World Cup fans was built months before the first match, and the peak exposure window is right now — the days immediately before kick-off when fans are doing last-minute searches, booking accommodation, and trying to transfer tickets.

19,000 domains is a lot of places to land by accident.

The rules are simple: bookmark fifa.com, don’t click ticket ads, buy only through FIFA’s official platform, and pay only inside your booking platform. If a seller or your hotel wants money through Venmo, Zelle, or wire transfer, it’s a scam.

The official FIFA ticketing site is fifa.com. Type it yourself.


FBI PSA260527 was issued May 27, 2026, by the Internet Crime Complaint Center (IC3). Domain statistics from Insikt Group, Check Point Research, and Group-IB reports published May–June 2026. Lloyds Bank fraud data covers October 2025–March 2026. File fraud reports and verify current advisories at IC3.gov.