Site icon Back End News

Kaspersky reveals how cybercriminals scam football fans

Soccer Tomislav Jakupec Pixabay

Image by Tomislav Jakupec from Pixabay

The FIFA World Cup Qatar 2022 is the most awaited sports event of 2022 for football and cybercriminals found an opportunity to exploit it.

Kaspersky experts have analyzed World Cup-related phishing websites from around the globe designed to steal users’ identifying and banking data. Kaspersky researchers have found fake pages offering everything from tickets or event merch, to match streaming services, plus numerous giveaways and NFT scams exploiting the World Cup.

Ticketing scams

As with all major global sports events, fake tickets are the spread bait most used to lure victims and this World Cup is no exception. Qatar 2022 is only offering digital tickets, increasing the risk of running into malicious resources. Kaspersky discovered numerous phishing pages offering to buy tickets for FIFA matches. Users will lose personal data, banking details, and money should they fall for this.

Kaspersky predicts shift in threat landscape to ICS in 2023
Banking credentials theft doubled in 2022 — Kaspersky

Gifts

No big public event is complete without fraudsters imitating extremely generous giveaways. Kaspersky experts also found phishing pages offering to win two tickets to the World Cup. This is quite popular where usually each user becomes a “lucky” winner; with the chosen ones only needing to pay a delivery fee.

Merchandise

Another way to steal users’ data is via fake FIFA-related merchandise stores. While the offer of a T-shirt of your favorite team, phone cases with popular players, or signed soccer balls sounds good, after entering your data and transferring money to make a purchase, fans lose their cash to fraudsters instead.

Crypto and NFT frauds

A distinctive feature of the threat landscape on the eve of the 2022 World Cup has been the active spread of various crypto scams, mostly exploiting the popularity of NFTs. Some offer to make a bet on a match and win cryptocurrency, others to win worldwide related NFT art. All the user needs to do is enter crypto wallet credentials, so the “prize” transfers directly. In such a scenario, scammers gain access to all savings and related wallet data.

Another scheme is crypto investment fraud is a bright example of a dubious investment. Fraudsters actively create real coins and convince a user to invest in them while promising the victim potential currency growth. In real life, such initiatives are almost never a success as users have spent money on something that will never develop.

Flights and accommodations

Pandemic-imposed limitations will also see the 2022 World Cup stage many offline events with live viewers, involving thousands of tourists in Qatar — something scammers have not missed. Kaspersky experts have observed numerous phishing pages imitating airline services offering tickets to Doha. The analyzed web page shows all the classic signs of a scam: nice appearance, wrong spelling, freshly registered domain, and limited functionality of the site. Although the site mimics a global airfare aggregator, the user can only choose Qatar in the list of destination countries. Once flight details are entered, the victim is offered the chance to enter personal data along with ID and credit information.

To avoid falling victim to a scam, Kaspersky advises users to:

Exit mobile version