The FBI doesn’t usually issue a public warning about a sporting event. For the 2026 World Cup, it did — and the scale of what researchers found backs it up: tens of thousands of fake FIFA-referencing domains registered in the run-up to the tournament, some hiding malware behind a “free stream” promise.
What’s actually happening
Security researchers tracking domain registrations found roughly 19,000 domains referencing “FIFA” registered since January 2026 — far more than the tournament itself would ever need. A meaningful share of them are set up specifically to catch fans searching for a way to watch matches for free.
Two patterns show up repeatedly:
- Ad-chain fake streams. Some sites promise a live match, then route you through a long chain of ad pages that never actually show football — the entire point is generating ad revenue off the click, not entertaining you.
- Malware disguised as a streaming app. This is the more serious version. Fake streaming apps — especially Android APKs offered outside the Google Play Store — have been found to conceal banking trojans that capture credentials and keystrokes while displaying a convincing streaming-app interface on top.
How to tell a fake site from a real one
The offer is the tell. FOX (English) and Telemundo/Peacock (Spanish) hold the actual US broadcast rights, and they’re not giving away the World Cup Final for free with no account required. If a site’s whole pitch is “free, no signup, no subscription” — that’s exactly the model fake sites use, because it’s what gets the most clicks.
Go direct, don’t search. The FBI’s specific advice: type the broadcaster’s real domain straight into your browser’s address bar rather than clicking a search result, an ad, or a link shared on social media. Fake domains are built to look almost right — small misspellings, extra characters, or a different ending (.sale instead of .com, for example) are common tricks.
Never install a streaming “app” from outside the official app store. This is the single highest-risk behavior in this whole scam wave. A real streaming service doesn’t need you to download an APK file from a random website — if a “stream” asks you to do that, stop.
If you think you already hit one
- Entered personal info or a password? Change that password now, and change it everywhere else you reused it — a password manager makes this much less painful going forward, since you’re not reusing passwords in the first place.
- Entered payment details? Watch your bank and card statements closely for a few weeks, and consider a card freeze or replacement if anything looks off.
- Installed an app from outside your phone’s store? This is the case to take most seriously — uninstall it immediately, and on Android in particular, a factory reset is the safest way to be sure a hidden trojan is actually gone if you can’t otherwise confirm it.
- Report it either way. File with the FBI at ic3.gov and the FTC at reportfraud.ftc.gov — this is what lets investigators track and shut these operations down faster, and it costs you five minutes.
The safe way to actually watch
Subscribe directly through FOX One / the FOX Sports app (English) or Peacock (Spanish, US) — no VPN or workaround needed if you’re watching from inside the US. If you’re traveling during the tournament and need to access your home subscription from abroad, see our guide on how to watch the World Cup Final with a VPN — the legitimate version of “getting around a blackout,” using a subscription you actually paid for.
Ticket and merchandise scams follow the same FBI advisory and the same playbook — the ticket and merchandise sections below apply if you’re buying anything related to the tournament. For general account hygiene heading into a high-scam-traffic event like this, our guide to ending password reuse and the Privacy Kit hub cover the basics worth having in place year-round, not just this tournament.