With the 2026 World Cup under way, scammers are spoofing official ticket and hospitality sites — while summer travel scams and a fake-verification malware trick keep circulating.
Buy event tickets and book travel only through the official site you reach yourself — type the address or use a saved bookmark, and read it character by character. An ad, a search result, or a social post is not a source.
Why it's "Elevated" today
We don't predict the future. This level reflects what is verifiably happening right now.
The FBI warns that, ahead of and during the 2026 World Cup, cyber threat actors are spoofing the FIFA website to "collect personal information, sell fake World Cup tickets and hospitality products," using look-alike domains (for example, a doubled letter, or ".org" in place of ".com") that also harvest name, address, and banking details. Separately, the FTC's June 2026 alert on a fake "CAPTCHA" trick — which tells you to run keyboard commands to "verify" you are human and instead installs malware — is still circulating.
FBI IC3 PSA (2026): Threat Actors Spoofing FIFA Websites · FTC Consumer Alert (June 2026): How to spot a CAPTCHA scamSummer travel reliably draws travel, vacation-rental, and ticket scams every year — a recurring, sourced pattern, labeled here as a seasonal factor. The FTC warns that travel scams crop up in paid search ads that place a scammer's number alongside a well-known brand, or link to a site that only looks like a real hotel or airline.
FTC summer travel alert (June 2026) · AARP travel fraud reportingActive right now
The scams behind today's level.
Look-alike "official" sites sell tickets and hospitality packages that do not exist, and harvest your identity at checkout. Buy only through the event's official channel, reached by typing the address yourself, and pay by credit card.
Read the guideFake rental listings, look-alike booking sites, and paid-ad "support" numbers — increasingly on AI-cloned pages — demand upfront payment by wire, gift card, or crypto for a trip or place that does not exist.
Read the guideA pop-up or page poses as a CAPTCHA or "security check" and tells you to press keys like Windows + R, paste, and hit Enter — which quietly runs malware. Real verification never asks you to run commands.
Read the guideCallers and texts pose as the SSA, IRS, a court ("missed jury duty"), or even the FTC, using threats or urgency to pull payment or personal details. Real agencies do not demand gift cards, wire transfers, or crypto.
Read the guideEditorial, not algorithmic. Risk levels are a transparent editorial judgment based on a published rubric — with sources, never pseudo-precise scores.
Get the forecast in your inbox
The weekly Deception Forecast, plus urgent alerts when the level jumps to High or Severe.
Subscribe free