Organisations are being urged to strengthen their cybersecurity measures during major football tournaments as cybercriminals increasingly exploit the heightened online activity of fans through phishing campaigns, fake streaming platforms and malicious mobile applications.
SearchInform Malaysia warned that while the latest global football tournament was held in North America, Asia’s large football fan base has created favourable conditions for cyberattacks targeting both individuals and businesses.
According to the company, fraudsters are luring football fans with fake streaming websites and malicious Android applications designed to steal saved passwords and browser credentials. Cybercriminals are also distributing phishing emails disguised as promotional offers, giveaways and office betting pools to trick employees into revealing sensitive information.
“During major global events, the corporate security perimeter is under huge stress,” said Francis Yeoh, Country Director of SearchInform Malaysia.
He said employees often use corporate devices to watch live matches or access football-related content, creating potential entry points for attackers.
“Traditional network-edge security is insufficient. The real danger comes from the employee side. Staff may access malware-infected streaming websites, download compromised applications or use corporate credentials to register for fraudulent promotions,” he said.
The warning comes as cybercrime activity linked to football events continues to rise. Citing findings from cybersecurity firm Group-IB and the US Federal Bureau of Investigation (FBI), SearchInform said more than 4,300 fraudulent websites imitating FIFA interfaces, ticketing platforms, streaming services and World Cup employment portals were registered between August 2025 and June 2026.
To reduce cyber risks during major sporting events, SearchInform recommends that organisations reinforce cybersecurity awareness among employees and tighten access controls.
The company advised employers to discourage the use of corporate devices for personal activities such as streaming matches, downloading unofficial applications or visiting unverified websites, as these actions significantly increase the risk of malware infections.
It also urged organisations to strengthen password management practices, noting that employees frequently reuse corporate passwords across personal online services. A breach involving those personal accounts could potentially expose corporate systems.
In addition, SearchInform recommended wider deployment of multi-factor authentication (MFA), particularly for privileged accounts and remote employees, to reduce the risk of unauthorised access during periods of heightened cyber threats.
The company also called on businesses to monitor user access to sensitive data, including activity across cloud environments, to detect unusual behaviour and prevent potential data leaks.





