Monday , August 3 2026
World Cup

World Cup Phishing Alert: 203 Malicious IPs Listed

The amount of phishing aimed at the 2026 FIFA World Cup has grown a lot. New studies show that the threats are bigger and more complicated than first thought.

What started as 79 bad domains has now turned into a widespread phishing network with 222 domains linked to 203 different IP addresses. This is almost three times the number of domains and has increased the hosting setup by over 14 times.

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

A follow-up study using passive DNS data, certificate transparency logs, and WHOIS checks shows that 206 out of 222 identified domains are still active.

52 new websites were signed up from April 1 to April 17, 2026. This shows that the campaign is speeding up as the tournament gets closer instead of slowing down.

Many different threat actors are using the same phishing kits that look like FIFA’s official platforms.

Flare says the system is spread out, using 203 different IP addresses. About 80.6% of these sites go through Cloudflare, letting attackers hide where the servers really are by using reverse proxy services. This makes it much harder to shut them down and find out who is behind it.

                                        IP address and domains (Source : flare).

A smaller subset of IPs hosts multiple phishing domains, including:

38.246.249.74 hosting 8 domains.
154.39.81.213 hosting 6 domains.
148.178.16.48 hosting 5 domains.

The expanded dataset includes 26 registrars, though a few dominate:

GNAME.COM accounts for 42.3% of domains.
GoDaddy follows with 18.9%.
Others include Spaceship, WebNIC, and Alibaba Cloud.

The focus shows that working together to take down important registrars could greatly stop the campaign.

Cloudflare has marked many websites as phishing sites, like fifa-com.store and fifa-com.site, showing warning pages instead of harmful content. But, this is just a tiny part of the whole system, showing the limits of checking each domain one by one.

This campaign shows how big events like the FIFA World Cup offer money-making chances for cybercriminals. With tools for phishing, shared networks, and tricks to hide identities, attackers can grow their actions quickly while avoiding regular defenses.

Check Also

EY

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group …