Securing FIFA World Cup 2026 With a Collective Defense Approach
The United States was co-host to the world’s largest sporting event as millions of fans gathered for the FIFA World Cup 2026 (FWC26), which for the first time included a 48-team competition.
Securing an event spanning three countries, dozens of host cities, and billions of digital touchpoints isn't a problem any single organization can solve, it's a collective challenge that demands a collective response to security.
The Challenge: Securing a Global Event in a Complex Threat Landscape
By the time quarterfinals began, more than 6 million spectators attended matches and over 7 million fans gathered at FIFA Fan Festivals across the U.S., Mexico, and Canada. Attendance spanned broadcast and digital ecosystems, including a record-breaking 20 billion video views across FIFA’s platforms.
The massive undertaking also came with significant risk. More than one billion cyber attacks were blocked during the tournament, with over 11,000 malicious domains identified and neutralized, according to FIFA.
At the same time, stadiums, host cities, athletes, and attendees faced online threats of violence, ticketing scams, suspected swatting incidents, extremist messaging, barrier breaches, and foreign adversarial information operations exploiting the intense, emotional engagement surrounding the games.
“This is the most volatile threat environment. We are dealing with physical acts of violence, we’re dealing with cyber attacks by state and non-state actors, we’re dealing with the increasing use of advanced technology like artificial intelligence and drones to engage in disruptive activities.”
John Cohen
Executive Director, Office of Strategic Programs & Initiatives
As the eyes of the world watched the matches, the Center for Internet Security® (CIS®) was working behind the scenes as a critical partner for event security. Leading up to and during the 39-day tournament, CIS provided strategic analysis, real-time threat monitoring, and weekly analytic review of threats and trends to event organizers, broadcasters, host city organizers, public safety partners, and Multi-State Information Sharing and Analysis Center® (MS-ISAC) members.
Video | One Mission. One Team. How CIS Supported FIFA World Cup Security
The Solution: A Community-Driven Approach to Security and Intelligence Sharing
Shared intelligence and open communication were key to ensuring host cities remained safe throughout the tournament. CIS analysts were operationally embedded within FIFA's security and intelligence center and a host city's intelligence command center to provide real-time threat information that allowed for coordinated decision-making for the tournament’s security.
By collaborating with partner organizations like Blackbird.AI, CyberWA, the Institute for Strategic Dialogue (ISD), and SocialScout, they were able to uncover, analyze, and distribute information on a range of multidimensional threats throughout the tournament.
“The rise and fall of any organization or major event is communication. And without that we will fail.”
Sasha Larkin
Director of Intelligence and C4 Operations for FIFA World Cup 2026
Uncovering Multidimensional Threats
The following are examples of the cyber, physical, and information operation threats that have been uncovered during the 2026 FIFA World Cup.
A Call for Lone Wolf Attacks
The Islamic State called the FWC26 a “golden opportunity” to revive “lone wolf attacks” in the U.S. In a June 18 newsletter, the group outlined using knives, vehicles, and arson as means to conduct attacks in “the heart” of the U.S., “because it is hosting games in 11 cities." The publication circulated widely in Islamic State-affiliated channels, indicating its message was resonating with the organization’s online supporters.
Synthetic Media
Deepfakes and synthetic media was disseminated by a potentially Russian-aligned account on social media denigrating the U.S. and using FWC26 and related branding. The social media account, previously assessed to be a conduit for Russian information operations, posted a video from the perspective of a live broadcast at a FWC26 match and included references to the so-called “War Cup” and called U.S. hosting a “betrayal.” The use of FWC26-related branding likely aimed to give implicit legitimacy to the synthetic content, strengthening its emotional resonance, and increasing the risk of reputation harm.
Typosquatting
On June 30, analysts observed a likely malicious typo-squatted domain and assessed the webpage was impersonating a FWC26 sponsor. With FWC26's global visibility, official sponsors likely increased cyber threat actor interest in leveraging event-related branding to make phishing, impersonation, and malware-delivery activity appear more credible.
The Impact: Increased Awareness, Shared Intel, and Mitigated Threats
To keep event organizers, public safety officials, and host cities aware and proactive in their defense, CIS provided real-time operational support and leveraged analyst expertise around-the-clock, issuing a series of Incident and Situational Awareness Alerts. This led to a deeper understanding of the multidimensional threat environment surrounding large-scale events and prompted relevant action from public safety and event organizers.
Alerts addressed pro-Jihadist rhetoric tied to a host city social media account (escalated to stadium security and federal law enforcement); direct threats of violence against players, referees, and FIFA personnel, including a spike targeting FIFA's president after a player suspension reversal; death threats against fans that prompted law enforcement to enhance venue security; planned in-stadium activity that could be disruptive to fans, which that relevant entities to adjust their security posture; and possible neo-Nazi activity in a host city, which prompted law enforcement to evaluate the threat.
Emerging Threats: Resources & Lessons Learned
Large-scale events operate within a distinct threat landscape driven by the specific set of risks and circumstances that coalesce during major events and gatherings, including large, dense crowds; a compressed timeframe; and heightened emotional response.
To further inform our stakeholders on the specific risks and mitigation measures suited to large events, CIS created and distributed publicly available resources to help public safety officials, event security professionals, and communities strengthen planning and preparedness.
AI and Emerging Technology Threats
CIS examined how AI-generated content and drone technology are reshaping the threat landscape for large-scale events, including hands-on testing of GenAI platforms to assess how threat actors could exploit them.
- Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings
- An Examination of AI-Enabled Threats to Event and Stadium Security
- Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings
- UAS Cyber Risks Companion Guide
- The Cybersecurity and Infrastructure Security Agency (CISA) hosted a Cross-Sector Community Webinar on CIS's UAS and deepfake white paper findings
Physical Security and Violent Extremism
CIS observed and escalated a range of credible threats targeting players, officials, fans, and venues — including extremist rhetoric and death threats — while also publishing research on mass casualty tactics at major sporting events.
- Lone Actor and Small-Group Mass Casualty Tactics in the Context of Major Sporting Events
- Incident Alerts: pro-Jihadist rhetoric, direct threats to players/referees/FIFA personnel, death threats against fans, possible neo-Nazi activity
Infrastructure and Access Control
CIS assessed vulnerabilities in the systems fans and cities depend on most, from ticketing platforms and stadium access controls to transportation networks that serve as critical event infrastructure.
- Transportation Infrastructure Sabotage as a World Cup 2026 Risk Multiplier
- Growing Risks to Digital Ticketing Platforms for Large-Scale Events
Financial Crime and Integrity
CIS, in collaboration with Wein Strategy Lab, analyzed how fraud actors and illicit betting networks exploit the surge in activity around major sporting events to manipulate outcomes and layer illegal funds.
Practitioner Guidance
CIS translated threat research into accessible, action-oriented resources to help cities, venues, and security professionals prepare for and respond to large-scale event risks.
- 5 Major Emerging Risks to Large-Scale Events (blog)
- 5 Steps to Help Secure Your City before a Large-Scale Event (blog)
- Cybersecurity Where You Are, Episode 196: Securing FIFA World Cup 2026 Collaboratively (podcast)
Looking Ahead
The World Cup was a proving ground, and the lessons it produced don't expire when the tournament ends.
In the coming months and years, the U.S. will host a series of events that demand the same level of coordination, intelligence sharing, and cross-sector collaboration that defined the FWC26 security effort. The 2026 midterm elections and the 2028 Summer Olympics in Los Angeles are among the highest-profile targets on the horizon, but major gatherings of any kind, includingconcerts, summits, championship games, arry a threat landscape that requires specialized planning and dedicated resources to deliver a safe experience for everyone involved.
The FWC26 experience reinforced a fundamental truth: no single agency, organization, or technology can secure a large-scale event alone. Defending against cyber attacks, physical threats, and information operations requires multiple stakeholders working in concert. Sharing intelligence in real time, establishing clear crisis communications protocols, and maintaining a unified security posture before, during, and after the event is a requirement.
For public safety agencies and event organizers beginning that planning process, CIS recommends:
- Stay informed. Understand emerging threat trends specific to large-scale events and ensure your team has access to timely, actionable intelligence.
- Engage early. Proactive information sharing with public safety officials, venue operators, federal partners, and ISACs creates the relationships that matter most when threats arise or incidents occur.
- Establish protocols before you need them. Crisis communications plans, escalation paths, and inter-agency coordination structures should be in place well before event day.
- Implement baseline security standards. The CIS Critical Security Controls® (CIS Controls®) provide a proven framework for identifying critical event systems, assigning ownership, and enforcing safeguards including multi-factor authentication (MFA), patching, and network segmentation. Apply CIS Benchmarks® to all applicable systems on your network.
The threat environment is not slowing down. But with the right partnerships, resources, and preparation, every future event can benefit from what was learned here.
Partner Organizations
Learn more about the organizations CIS partnered with to foster a safer, more robust security environment during FWC26.
Blackbird.AI is the leading narrative intelligence detection and response company that contributed reporting and analysis to enhance the safety and security of the World Cup. Through investigations by their RAV3N team and narrative intelligence platform, they discovered narrative attacks that focused on tournament access, sponsor backlash, geopolitical influence, cybersecurity, physical security and brand reputation threats.
CyberWA is the elite concierge cybersecurity service for high-net-worth and high-valued individuals. CyberWA delivered its tailored Cyber Bodyguard® service providing executive cyber protection, digital risk intelligence, and executive risk management to safeguard individuals associated with major global organizations. Decades of cyber threat experience allowed CyberWA’s intelligence experts to understand, analyze, and integrate personal cybersecurity protection into security operations.
The Institute for Strategic Dialogue (ISD) is at the forefront of analyzing and innovating solutions to the threats of violent groups, hostile influence operations and extremism of all ideological forms. Prior to and throughout the tournament, ISD provided intelligence gathering and analysis on physical threats, online extremist content, and subject matter expertise in support of CIS's special events initiative.
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.