World Cup 2026 infrastructure faces rising cyberattack risks

An analysis of cyber threats surrounding the 2026 FIFA World Cup identifies disruptive intrusions, large-scale fraud, DDoS attacks and politically motivated hack-and-leak operations as the most likely risks during the tournament.

 


The expansion of the 2026 FIFA World Cup is not only increasing its scale, but also the cybersecurity risks facing the host countries.

The infrastructure supporting the 2026 FIFA World Cup could become one of the primary targets of cyberattacks during the tournament.


The 2026 FIFA World Cup is set to become the largest sporting event ever organized and, at the same time, one of the events most exposed to cybersecurity threats due to the complexity of its technological and operational infrastructure.

The tournament will be held over 39 days across 16 cities in the United States, Mexico and Canada, featuring 104 matches, 48 participating national teams and an estimated attendance of between five and six million spectators, in addition to a global audience approaching half of the world’s population.

The infrastructure supporting the 2026 FIFA World Cup significantly expands the attack surface for cyber threats targeting critical services and platforms associated with the tournament.

The tournament began on June 11, 2026, at Estadio Azteca and will conclude on July 19 at MetLife Stadium. It is the first edition to be jointly hosted by three countries.

Tournament operations will depend on a temporary network integrated with the existing infrastructure of the National Football League, Major League Soccer, Canadian Football League and Liga MX stadiums, as well as public services including transportation, traffic management, water treatment, electricity supply, airport operations and emergency services. This integration expands the potential points of exposure for malicious actors.

Threat landscape.

The findings are based on a report by Palo Alto Networks Unit 42 that reviews cyber operations recorded from 2016 through the Milano Cortina 2026 Winter Olympic Games.

The assessment considers disruptive intrusions, large-scale criminal fraud, distributed denial-of-service (DDoS) attacks and politically motivated hack-and-leak operations to be highly likely during the tournament.

Key risks identified.

1) Iran-linked activity.

The report states that the conflict involving the United States, Israel and Iran, which began on February 28, 2026, has changed the threat landscape for any event hosted by the United States.

It highlights the activities of Handala, identified by the FBI and several threat intelligence firms as a front for Iran’s Ministry of Intelligence and Security (MOIS), as well as a CISA alert regarding campaigns targeting Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), along with Vision Unitronics equipment used in critical water, energy and municipal infrastructure.

The report warns that these are the same categories of infrastructure on which World Cup host cities will depend during the tournament.

2) Russia-linked hacktivism.

The document identifies NoName057(16) as one of the principal threat actors. According to the assessment, the group has carried out more than 3,700 verified DDoS attacks against governments and critical infrastructure in NATO member countries since 2022 and has intensified its activity during high-profile political events.

Although Operation Eastwood disrupted part of its infrastructure in 2025, the United Kingdom’s National Cyber Security Centre (NCSC) confirmed that the group’s operations continued throughout 2026.

3) Financially motivated cybercrime.

The analysis recalls that during the 2022 FIFA World Cup Qatar, Group-IB identified more than 16,000 fraudulent domains and 90 compromised accounts associated with the Hayya fan portal.

It also references the campaign carried out by Muddled Libra, operators of the ALPHV (BlackCat) ransomware, against organizations in the entertainment sector, illustrating cybercriminal interest in booking platforms, digital keys, point-of-sale (PoS) terminals, loyalty programs and hospitality-related systems.

Among the primary targets anticipated for 2026 are ticket fraud, accommodation scams, transportation QR codes and the takeover of fan accounts.

Lessons from previous events.

As a recent precedent, the report cites the Paris 2024 Olympic Games, where French authorities confirmed at least 140 cybersecurity incidents, including 22 unauthorized access incidents and a ransomware attack against the Grand Palais venue.

According to the assessment, the continuity of the competitions was made possible by a preparation process that began several years in advance and was coordinated across public and private organizations.

In practice, the 2026 FIFA World Cup significantly increases the number of digital assets and critical infrastructure that will need to be protected in a coordinated manner across three countries during the tournament.

Scenarios the report recommends anticipating.

Cybercriminal campaigns targeting fans and the hospitality sector supply chain.

Iran-linked disruptive operations targeting U.S. supporting infrastructure during the tournament.

DDoS attacks by pro-Russian and pro-Iranian hacktivist groups against host cities, football federations and ticketing platforms.

Potential destructive wiper attacks against the tournament’s technology infrastructure during high-visibility ceremonies.

The analysis concludes that early preparation, coordination between public and private organizations, and the protection of critical infrastructure will be essential to reducing the impact of potential cybersecurity incidents during the 2026 FIFA World Cup.


Share:
Hosting Web
Most Read