CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Ghost Stadium PhaaS

campaign · campaign:ghost-stadium-phaas-300-fifa-domain-clones-eu-fan-credentials

Ghost Stadium PhaaS, 300+ FIFA domain clones targeting EU fans

Coverage
1
first 2026-05-30 → last 2026-05-30
Latest activity
2026-05-30
Ghost Stadium PhaaS, 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector · regions: europe, uk
Sources cited
2
2 hosts

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

part of

Story timeline

  1. 2026-05-30Ghost Stadium PhaaS, 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain fan credentials before June 11 kickoff
    active-threats

Entries about Ghost Stadium PhaaS (1)

2026-05-30 · view entry permalink →

HIGH

Ghost Stadium PhaaS, 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain fan credentials before June 11 kickoff

The FBI issued PSA260527 on 27 May 2026 warning that a Chinese-speaking financially-motivated threat actor tracked by Group-IB as Ghost Stadium has deployed more than 300 phishing sites impersonating fifa.com, all reproducing the official site pixel-for-pixel including a fake single-sign-on authentication flow in multiple languages (FBI IC3 PSA260527, 2026-05-27; BleepingComputer, 2026-05-28). Typosquatted domains span alternative TLDs (.org, .xyz, .live, .sale) and character substitutions; additional fake employment portals impersonate FIFA HR functions. Criminal objectives include credential and financial-data theft via the fake SSO, counterfeit ticket and hospitality sales, fake merchandise and streaming-rights fraud. UK, Germany, Portugal, and Spain are explicitly named as target demographics. Browser-based security controls (Safe Browsing, SmartScreen) do not protect against freshly-registered domains before abuse is reported. For defenders at organisations with large employee populations purchasing World Cup tickets: advise bookmarking https://www.fifa.com directly; treat any search-result-sponsored result for FIFA ticket purchases as unverified. The high-intensity fraud window is the lead-up to the July 19 final.

threat30 May 05:00Zmulti-sourceOpen finding →

Where this entity is cited

  • Threats1

Source distribution

  • bleepingcomputer.com1 (50%)
  • ic3.gov1 (50%)