Most fans attending the 2026 FIFA World Cup won't spend a single moment thinking about cybersecurity. They’ll think about travel plans, where to eat, and whether their team has a realistic shot. The ticketing app will work. The stadium network will hold. The hotel booking will be real.
Such seamless experiences won't be accidental. They’ll be the result of years of planning and coordination spanning government agencies, law enforcement at every level, private sector partners, and international organizations, all working to ensure that athletes can compete, fans can celebrate, and no one has to think about what’s happening behind the scenes to protect them.
As a former state CIO and a former state CISO, we have deep respect for that work. We have lived versions of it at smaller scale: the statewide tabletop exercises, the cross-agency briefings, the vendor reviews, the off-hour calls. As the World Cup unfolds across North America in June, we hope for continued acknowledgement and celebration of the intense work of cybersecurity professionals across federal, state, and local governments; the facilities, vendors and other businesses; and FIFA itself.
The event is also, inevitably, a dry run for the next global sporting event to be held in North America, the 2028 Summer Olympics in Los Angeles. Those games are already in planning, and every lesson from this summer is critical intelligence for what comes next.
Here’s what we think about when we think about securing an event like this and the critical infrastructure that enables it.

The fan is the most visible target
More than 4,300 fraudulent domains impersonating official FIFA ticketing, merchandise, and streaming platforms have already been identified, some registered more than a year in advance. Domain aging makes them progressively harder to detect and take down. At the same time, a Proofpoint study found that 36% of official World Cup partners lack full DMARC enforcement, meaning fraudsters can send emails that convincingly appear to come from trusted sponsor brands. Especially when you consider that many fans traveling to the event from overseas may be less able to spot cultural or linguistic irregularities that can betray a scam communication when it arrives in a language they’re less familiar with.
The low-tech version of this threat is just as potent. Consider the attacker's logic: print QR codes promising last-minute tickets or a VIP experience, post them near a venue entrance, and wait. Even a 10% success rate nets a meaningful haul across a crowd of tens of thousands, and it costs almost nothing to set up. The attack surface extends well beyond the stadium, and the tremendous work to secure the event ecosystem must also come with public messaging to fans: Be aware of scams and protect your personal devices by keeping them updated and practicing good cyber hygiene. Buy only through official FIFA channels and treat any unsolicited World Cup offer as suspicious by default.
AI has undermined trust
The scale and quality of deception make 2026 materially different from Qatar 2022. The barrier to entry for sophisticated attacks has dropped substantially as threat actors incorporate AI, a tool that has also accelerated the speed at which those attacks can be constructed and deployed. That means that defenders have to think and act just as quickly, with response playbooks built and tested before something happens rather than improvised in a crisis.
There is also the disinformation dimension. Official-looking communications can no longer be taken at face value. The shift required—defaulting to a healthy skepticism rather than trust—is difficult for individuals and organizations alike. The World Cup, also a magnet for hacktivists, is simply a high-profile version of a challenge that already pervades daily life.
Infrastructure will be stress tested
The 2026 Milan Winter Olympics saw a 180% spike in DDoS attacks against Italian critical infrastructure, which is a direct preview of what this summer could bring. DDoS has evolved from a nuisance into a tool of geopolitical aggression, and the World Cup's multi-country, multi-ISP footprint creates a surface of enormous scale.
Temporary infrastructure is the most exposed element. Stadium networks, portable cellular towers, broadcast systems stood up quickly for the tournament—all are inherently less hardened than permanent systems, and AI-assisted probing can often find weaknesses faster than defenders can assess the risk. Consider also what happens when that infrastructure strains under purely legitimate demand: Every fan in a 70,000-person venue will reach for their phone at the same moment. Whether the network holds is not only a fan experience question. In an emergency, it is a life-and-safety question. Planning for backup telecommunications and failover systems is among the most consequential things organizers can do.
The ecosystem is much larger than the stadium
Hotels, restaurants, transit systems, and local vendors in World Cup cities are prime targets. The 2023 MGM/Caesars attacks—sophisticated social engineering leading to operational paralysis—are the model that attackers are likely studying. More than 7,500 fraudulent hospitality websites are reportedly active in World Cup markets.
<blockquote>The supply chain dimension compounds the challenge. The World Cup relies on thousands of vendors, volunteers, and third-party technology providers, each a potential entry point.</blockquote>
The supply chain dimension compounds the challenge. The World Cup relies on thousands of vendors, volunteers, and third-party technology providers, each a potential entry point. The foundational question every security leader should be able to answer before an event of this scale: Do you know every system that has access to your environment? Every vendor credential that is active? You cannot protect what you cannot see, and at this scale, visibility is not a given.
There’s always a geopolitical angle
Security experts see more potential for hacktivist disruption at this tournament than at any previous World Cup. Geopolitical tensions, such as the Russia-Ukraine conflict, Middle East instability, and the United States' symbolic weight as a host nation, create fertile ground for state-sponsored disruption and politically motivated hacktivism alike.
The motivations vary: Some actors want financial gain; others want the visibility that a high-profile attack provides. Hacktivist groups have a well-documented history of exploiting large, media-saturated gatherings to amplify their message. For defenders, this makes threat intelligence sharing and active coordination with CISA and international counterparts a foundational requirement.
Preparation is necessary, and resilience is essential
Preparation for one of the most complex security operations ever for a security event is critically important. But events do not always go according to plan. The question that experienced security leaders really wrestle with is not "Are we ready?" It is: "How fast can we respond to something we didn’t anticipate?"
Being prepared means having contingencies you can execute under pressure: failover systems for emergency call centers, backup communications if primary networks are overwhelmed, playbooks that have been stress-tested before they are needed. In a crisis, not everything can be addressed simultaneously. Life and safety come first, always. Critical infrastructure is next. Everything else after that.
<blockquote>In cybersecurity today, 'faster than the human eye' is not an aspiration, it’s the basic requirement.</blockquote>
We have to be faster than the human eye. In cybersecurity today, that’s not an aspiration, it’s the basic requirement. That means empowering teams with real-time visibility and the autonomous capability to act, not merely to alert. Teams that can see everything in their environment and respond within seconds, not hours, are the ones that contain damage before it spreads.
Los Angeles is waiting in the wings
This summer's tournament represents one of the most extensive cybersecurity mobilizations in sporting history. The coordination across governments, law enforcement, private sector partners, and international bodies is a genuine achievement, and we’re eager to see these games succeed. From an IT and security perspective, every test of infrastructure resilience, logged incident, and repelled attack becomes institutional knowledge for the 2028 Olympics in Los Angeles. That planning is already underway, and it should be informed in detail by what this year produces.
With every global sporting event, the attack surface grows, the vectors change, and both attackers and defenders upgrade their tools and techniques. For defenders, the game remains the same. As Andy has put it in his own work protecting state-level clients: You cannot guarantee that nothing will happen. What you can commit to is limiting the scope and impact of any successful attack, and working to ensure that it doesn’t spread as far or last as long as the adversary expects.
Real-time visibility, rapid response, genuine resilience. That is the standard that gives you the ability, and confidence, to act at scale to protect your data and your environment. That’s true for this World Cup, for L.A. 2028, and for every organization operating in today's threat landscape.