Mexico Leads in Cyberfraud Across FIFA World Cup Host Nations
Home > Cybersecurity > Article

Mexico Leads in Cyberfraud Across FIFA World Cup Host Nations

Photo by:   Government of Mexico
Share it!
Diego Valverde By Diego Valverde | Journalist & Industry Analyst - Tue, 06/30/2026 - 09:30
DIA assistant

Mexico is emerging as the most targeted country for cyberfraud activity linked to the FIFA World Cup 2026, as attackers scale phishing, smishing, and identity theft campaigns designed to exploit surging digital demand around ticketing, hospitality, and online commerce.

 

According to research from Check Point Software Technologies, companies operating in Mexico recorded an average of 3,548 weekly cyberattacks per organization in April 2026, a 4% increase compared to the same period a year earlier. The figure exceeds reported volumes in Canada and the United States, positioning Mexico as the primary regional target ahead of the tournament.

Omer Dembinsky, Group Manager of Data Research, Check Point Software Technologies, says attackers are rapidly adapting their tactics. He notes that cybercriminals are leveraging “highly convincing fake hospitality and ticketing platforms” to extract sensitive user data and payments during peak demand cycles.

The rise in attacks is occurring in a broader environment of accelerated digital activity. Sectors such as media, logistics, hospitality, retail, transportation, and entertainment are experiencing heightened exposure due to transaction spikes linked to World Cup-related demand.

A separate analysis from IQSEC documented 68 cybersecurity incidents against Mexican targets between April 15 and May 15, 2026, equivalent to 2.3 daily incidents tied specifically to World Cup-related activity.

Manuel Moreno, Cybersecurity Consultant, IQSEC, says that attackers rely heavily on behavioral manipulation. He explains that urgency, emotional engagement, and high demand conditions are systematically used to push users into “rapid decisions without verifying authenticity,” particularly in ticketing and promotional scams.

IQSEC also reports that 84% of detected incidents were linked to data breaches, while the remaining 16% involved ransomware activity designed to lock systems and demand payment for restoration.

Domain Proliferation and Identity Fraud Intensification

Check Point Software Technologies reports a significant acceleration in domain registration activity containing keywords such as “FIFA” and “World Cup,” with volumes increasing more than fourfold within two months, reaching 9,741 registrations in April 2026. This level exceeds observed peaks during the Qatar 2022 World Cup cycle.

Among the most notable findings is the identification of malicious domains designed to mimic official FIFA retail platforms and offer discounted merchandise of up to 80%, including jerseys and souvenirs. Dembinsky says that the combination of brand impersonation, social engineering, and AI is increasing the scalability and realism of fraud campaigns.

The risk is further amplified by widespread use of QR-based interactions, which attackers are increasingly exploiting to redirect users to malicious sites or trigger unauthorized downloads.

Regional Exposure and Macro Cybercrime Trends

Broader regional analysis confirms Mexico’s elevated exposure. Canada recorded an average of 1,649 weekly attacks per company, while the United States registered 1,497, according to Check Point Software Technologies. While Canada experienced a sharper annual increase of 18%, Mexico continues to lead in absolute volume.

Parallel findings from Fortinet and Kaspersky indicate that Mexico is facing more than 58 billion cyberattack attempts so far in 2026, positioning it among the most targeted markets in Latin America.

Víctor Merchand, Coordinator of the Cybercrime Program, United Nations Office on Drugs and Crime (UNODC) in Mexico, notes that global-scale events significantly expand the attack surface due to simultaneous exposure across digital platforms, streaming services, and payment systems. He says that criminal groups exploit “increased exposure through social media, financial transactions, and identity-sharing environments.”

Mexico has 88.6 million internet users, representing 75.6% of the population aged six and above, according to INEGI. Despite this high connectivity rate, only around half of users believe their devices are adequately protected against cyber threats.

Structural Vulnerabilities and Behavioral Risk Factors

The convergence of digital tourism, cashless payments, and temporary access systems during global events increases vulnerability across both domestic and foreign users. Merchand highlights that attackers exploit unsecured WiFi networks, unverified platforms, and identity impersonation schemes. He also notes that Mexico remains highly exposed due to limited cybersecurity legislation development, with at least 11 cybersecurity-related legislative proposals failing to advance in recent years.

In parallel, Kaspersky researchers emphasize that fraud campaigns increasingly leverage emerging digital trends, including AI-generated content such as “fan cam” selfie transformations, which can expose biometric data and increase identity cloning risks.

María Isabel Manjarrez, Latin America Security Researcher, Kaspersky, says that major sporting events concentrate “emotion, urgency, and high demand,” which reduces user vigilance and increases susceptibility to fraud.

Cybersecurity analysts anticipate that attack volumes will increase further as the tournament approaches, driven by higher transaction frequency across ticketing platforms, travel services, and hospitality networks.

Merchand warns that exposure will extend beyond the tournament period itself, as compromised credentials and malicious access points can be reused after the event concludes. He emphasizes that preventive behavior, including verification of domains, secure authentication practices, and cautious interaction with unsolicited links, remains critical.

Photo by:   Government of Mexico

You May Like

Most popular

Newsletter