Ahead of the 2026 FIFA World Cup, scammers are increasingly using AI-generated materials to impersonate FIFA: cloned websites, deepfake videos, and professionally crafted phishing emails that mimic official communication and branding.
What the numbers show
Monitoring by security observers found a significant rise in FIFA-themed domain registrations in the first five months of the year: more than 13,000 such domains were registered between January and May. The cybersecurity firm Group-IB counted over 4,300 fake FIFA domains before any matches had kicked off. By early May, roughly one in 41 of those domains had already been flagged as suspicious.
How the scams have changed
Previously, many World Cup scams were exposed by obvious errors: broken English, misspellings, or amateurish web design. Artificial intelligence has removed many of those visible giveaways by cheaply and rapidly producing polished branding, clean copy, and cloned voices. The underlying scam concepts have not necessarily become more sophisticated; instead, AI strips away the friction and mistakes that once helped people detect fraud.
Why this matters for users and defenders
The informal defense taught to many internet users — "if it looks sloppy, don’t trust it" — is becoming less reliable. Higher-fidelity fake sites and messages can spread at scale, increasing the risk of successful phishing and fraud. That shifts part of the detection burden onto individual users and on security tools and teams, which must now distinguish between legitimate and convincingly fake content.
Conclusion
The pre-tournament surge in fake FIFA domains illustrates how AI can "fine-tune" existing scams rather than invent new ones. The registration of more than 13,000 FIFA-themed domains and Group-IB’s finding of over 4,300 counterfeit domains demonstrate how quickly and widely such threats can scale, underscoring the need for heightened vigilance and improved technical defenses.



