[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Insights](https://unit42.paloaltonetworks.com/category/insights/ "Insights")
* [General](https://unit42.paloaltonetworks.com/category/general/ "General")  
  [General](https://unit42.paloaltonetworks.com/category/general/)

# 2026 World Cup: Discussing The World's Biggest Game's Attack Surface

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read  
Related Products  
[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Justin Moore](https://unit42.paloaltonetworks.com/author/justin-moore/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 28, 2026

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [General](https://unit42.paloaltonetworks.com/category/general/)
  * [Hacktivism](https://unit42.paloaltonetworks.com/category/hacktivism/)
  * [Insights](https://unit42.paloaltonetworks.com/category/insights/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/)
  * [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/)
  * [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [QR Codes](https://unit42.paloaltonetworks.com/tag/qr-codes/)
  * [Razing Ursa](https://unit42.paloaltonetworks.com/tag/razing-ursa/)
  * [Typosquatting](https://unit42.paloaltonetworks.com/tag/typosquatting/)
  * [Wiper](https://unit42.paloaltonetworks.com/tag/wiper/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/?pdf=download&lg=en&_wpnonce=fafa58d2d0 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/?pdf=print&lg=en&_wpnonce=fafa58d2d0 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=2026%20World%20Cup:%20Discussing%20The%20World’s%20Biggest%20Game’s%20Attack%20Surface&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ffifa-world-cup-attack-surface%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffifa-world-cup-attack-surface%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffifa-world-cup-attack-surface%2F&title=2026%20World%20Cup:%20Discussing%20The%20World’s%20Biggest%20Game’s%20Attack%20Surface "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffifa-world-cup-attack-surface%2F&text=2026%20World%20Cup:%20Discussing%20The%20World’s%20Biggest%20Game’s%20Attack%20Surface "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffifa-world-cup-attack-surface%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=2026%20World%20Cup:%20Discussing%20The%20World’s%20Biggest%20Game’s%20Attack%20Surface%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ffifa-world-cup-attack-surface%2F "Share in Mastodon")
  The 2026 FIFA World Cup will be the largest sporting event ever staged. Across 39 days, 16 host cities in three nations will host 104 matches, an expanded 48-team tournament and an estimated five-to-six million in-venue spectators alongside a global broadcast audience approaching half the planet.

The tournament opens at Estadio Azteca in Mexico City on June 11, 2026, and concludes at MetLife Stadium in East Rutherford, New Jersey, on July 19, 2026.

This is the first World Cup to be jointly hosted by three nations. Each match runs on a temporary, multi-ring tournament network grafted onto pre-existing NFL, MLS, CFL and Liga MX stadium environments. It depends on a network of municipal services, including public transit, signalized traffic, water and wastewater treatment, regional power, airport operations and emergency services. Each of those touchpoints is in scope for an adversary.

Based on a review of cyber operations against prior mega-events from 2016 through the [Milano-Cortina 2026 Winter Games](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/), this assessment finds that disruptive intrusions, criminal fraud at scale and politically motivated distributed denial-of-service (DDoS) and hack-and-leak operations are highly likely. The only meaningful questions are who, against which targets and at what severity.

There are three drivers in the 2026 World Cup risk picture:

* **Iran-nexus activity.** The U.S.--Israel--Iran kinetic conflict that began on Feb. 28, 2026 has reordered the threat surface for any U.S.-hosted event. The Handala Hack Team, [assessed by the U.S. Federal Bureau of Investigation (FBI)](https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations) and multiple commercial threat intelligence firms to be a front for Iran's Ministry of Intelligence and Security (MOIS), executed significant [wiper attacks](https://www.google.com/url?q=https://unit42.paloaltonetworks.com/evolution-of-iran-cyber-threats/&sa=D&source=docs&ust=1779200661208089&usg=AOvVaw0CiPqxVSSoCynKFCddGrfk) in early 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a joint advisory [AA26-097A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a) confirming an active, ongoing Iranian-affiliated campaign. The campaign targets internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs) in U.S. critical infrastructure, as well as [Islamic Revolutionary Guard Corps (IRGC) targeting](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a) of Israeli-made Unitronics Vision Series PLCs at [U.S. water, energy and municipal](https://media.defense.gov/2023/Dec/04/2003350920/-1/-1/0/CSA-IRGC-AFFILIATED-CYBER-ACTORS-EXPLOIT-PLCS-IN-MULTIPLE-SECTORS.PDF) targets. These are the same categories of infrastructure that World Cup host cities will be operating under tournament load.
* **Russia-nexus hacktivism.** Since 2022, NoName057(16) has conducted over 3,700 verified DDoS attacks against governments and critical sectors in NATO member states. Documented surges keyed to politically symbolic events including the [NATO Summit](https://www.eurojust.europa.eu/news/hacktivist-group-responsible-cyberattacks-critical-infrastructure-europe-taken-down), the [Ukraine Peace Summit](https://therecord.media/international-police-takedown-noname-hacker) and claims of intent at the [Paris 2022 Olympics](https://www.intel471.com/blog/winter-olympics-2026-hacktivism-surges-ahead-of-protests-and-suspected-sabotage) and the [Milano Cortina 2026 Winter Olympics](https://securityaffairs.com/187654/hacktivism/pro-russian-group-noname05716-launched-ddos-attacks-on-milano-cortina-2026-winter-olympics.html). [Operation Eastwood](https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network) (July 2025) disrupted but did not eliminate the group. The [UK NCSC](https://www.ncsc.gov.uk/news/pro-russia-hacktivist-activity-continues-to-target-uk-organisations) confirmed continued operations into 2026. The U.S., Canada and Mexico are NATO partners or allies and the World Cup is a politically symbolic event of the highest order.
* **Financially motivated cybercrime.** Group-IB identified more than [16,000 fraudulent domains](https://www.group-ib.com/media-center/press-releases/scammers-on-the-pitch/) and 90 compromised Hayya fan-portal accounts during World Cup 2022 in Qatar. The 2023 Muddled Libra (operators of ALPHV aka BlackCat ransomware) campaign against entertainment organizations demonstrated that the hospitality stack is a target for [ransomware operators](https://www.cyberark.com/resources/blog/the-mgm-resorts-attack-initial-analysis). The stack includes reservations, digital keys, point-of-sale (PoS) machines and loyalty data. Ticket fraud, accommodation fraud, transportation QR-code fraud and FanID-equivalent account takeover are prime targets at scale across all three host nations.

The [Paris 2024 Olympics](https://www.paloaltonetworks.com/unit42/threats-to-paris) is a strong example of a recent precedent. French authorities (ANSSI) confirmed at least 140 cyber events during the Games, including 22 confirmed unauthorized intrusions and a ransomware attack against the Grand Palais venue.

None succeeded in disrupting competition, but only because of preparation that began years earlier. Preparation included exercises against 500 Games-linked facilities, and support by sustained government-industry coordination. The 2026 tournament must clear the same bar across multiple jurisdictions, regulatory bodies and languages.

### The Bottom Line

Defenders should plan against the possibility of all of the following:

* Cybercriminals targeting fans and the hospitality supply chain
* Iran-nexus disruptive operations against ancillary U.S. infrastructure during the tournament window
* Pro-Russian and pro-Iran hacktivist DDoS and defacement targeting of host-city, federation and ticketing services
* A wiper deployed against tournament IT during a high-visibility ceremony

### Previous Attacks Against Major International Sporting Events

|           **Event**           | **Year** |                                                                                                                                                               **Operation / Actor**                                                                                                                                                                |                                                                                                                                                                                                              **Documented Impact / Primary Source**                                                                                                                                                                                                              |
|-------------------------------|----------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Rio Summer Olympics           | 2016     | [OpOlympicHacking](https://igarape.org.br/en/with-anonymous-latest-attacks-in-rio-the-digital-games-have-begun/); Fighting Ursa (aka Fancy Bear, APT28) [WADA leak](https://www.wada-ama.org/en/news/wada-confirms-another-batch-athlete-data-leaked-russian-cyber-hackers-fancy-bear)                                                             | Prolonged DDoS against the official Rio website; Fighting Ursa publication of [stolen WADA athlete medical records](https://www.wada-ama.org/en/news/cyber-hack-update-data-leak-concerning-41-athletes-13-countries-and-17-sports)                                                                                                                                                                                                                              |
| Pyeongchang Winter Olympics   | 2018     | [Olympic Destroyer wiper](https://www.gov.uk/government/news/uk-exposes-series-of-russian-cyber-attacks-against-olympic-and-paralympic-games); attributed to Razing Ursa (aka GRU Unit 74455, Sandworm) by [UK FCDO](https://www.gov.uk/government/news/uk-exposes-series-of-russian-cyber-attacks-against-olympic-and-paralympic-games), Oct 2020 | Wi-Fi at [opening ceremony](https://time.com/5155234/hackers-targeted-pyeongchang-opening-ceremony/), Olympics website, ticketing, broadcast drones disabled. 300+ systems compromised. 12 hours to restore. [Credentials](https://blog.talosintelligence.com/olympic-destroyer/) in binary referenced 44 [Pyeongchang accounts](https://www.recordedfuture.com/research/olympic-destroyer-malware).                                                             |
| Tokyo Summer Olympics         | 2020/21  | Razing Ursa [reconnaissance and disruption](https://www.cfr.org/cyber-operations/targeting-of-tokyo-olympics-organizers-logistics-services-and-sponsors)                                                                                                                                                                                           | Over 450 million blocked attempts reported. No disruption to competition. [Phishing/social engineering](https://www.theguardian.com/world/2020/oct/19/russia-planned-cyber-attack-on-tokyo-olympics-says-uk) against athletes and ticket-holders persisted.                                                                                                                                                                                                      |
| FIFA World Cup, Qatar         | 2022     | Cybercriminal [ecosystem](https://cyberscoop.com/fifa-world-cup-cyber-scam-phishing-malware/); multiple groups                                                                                                                                                                                                                                     | [Group-IB](https://www.group-ib.com/media-center/press-releases/scammers-on-the-pitch/): 16,000+ scam domains, 40+ fake mobile apps, 50+ fake social-media accounts, and 90 compromised Hayya FanID accounts (RedLine and Erbium info-stealer credentials).                                                                                                                                                                                                      |
| Rugby World Cup, France       | 2023     | Fiddling Scorpius, distributors of [Play ransomware](https://www.numerama.com/cyberguerre/1424330-la-federation-francaise-de-rugby-piratee-les-hackers-auraient-derobe-des-donnees-confidentielles.html)                                                                                                                                           | French Rugby Federation systems encrypted three months before kickoff; Personally identifiable information (PII) exfiltrated. No on-field disruption. Reputational and financial damage.                                                                                                                                                                                                                                                                         |
| Paris Summer Olympics         | 2024     | Multiple [cybercriminal and hacktivist groups](https://www.ibm.com/think/insights/paris-olympic-authorities-battled-cyberattacks-won-gold); one ransomware actor. ANSSI confirmed [140+ events](https://www.france24.com/en/live-news/20240814-france-reports-over-140-cyberattacks-linked-to-olympics)                                            | [ANSSI](https://www.cert.ssi.gouv.fr/cti/CERTFR-2025-CTI-004/): [140+ events](https://www.cyberthreatalliance.org/looking-beyond-the-medal-a-cybersecurity-after-action-report-on-the-paris-olympics/), 119 low-impact, 22 successful intrusions. Ransomware on Grand Palais venue and approximately 40 other museums. [DDoS peaks at 190,000 req/sec](https://radar.cloudflare.com/reports/paris-2024-olympics) on official site. No competition was disrupted. |
| Milan-Cortina Winter Olympics | 2026     | Italian Foreign Minister Antonio Tajani said [in a press conference](https://www.reuters.com/world/italy-foiled-russia-linked-cyberattacks-embassies-olympic-sites-minister-says-2026-02-04/) that Italy thwarted attacks                                                                                                                          | No public confirmation of disruption to competition. Italian National Cybersecurity Agency operated a dedicated command centre throughout the Games.                                                                                                                                                                                                                                                                                                             |

Table 1. Previous attacks against major sporting events.

## Cybercriminal Threats to Fans and the Tournament Supply Chain

Financially motivated cybercrime is the highest-volume, highest-likelihood threat category for the 2026 FIFA World Cup Games.

#### Ticket Fraud and FanID-equivalent Account Takeover

Based on the Qatar 2022 Games, there are [five categories](https://www.group-ib.com/media-center/press-releases/scammers-on-the-pitch/) of [ticket-themed fraud](https://www.lloydsbankinggroup.com/media/press-releases/2026/lloyds/world-cup-ticket-scams.html):

* Lookalike resale sites
* Fake social-media reseller accounts
* Lottery/giveaway phishing
* Fake mobile applications on official app stores
* Credential-stuffing attacks against the official fan portal

#### Hospitality and Accommodation Fraud

Attacks against hospitality businesses and platforms, digital key infrastructure, point of sale (PoS) and identity providers and [fake short-term rental properties](https://www.globalrescue.com/common/blog/detail/2026-fifa-world-cup-scams/) are another potential area of risk.

#### QR-Code, Transportation and PoS Fraud

Tournament-specific [QR-code fraud](https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/) is the single fastest-growing variant. There have already been observed [pre-tournament listing scams](https://www.khou.com/article/sports/soccer/world-cup/houston-property-owner-rental-fraud-scheme-world-cup/285-1d6fada9-4374-4934-aaa2-444e985da416), and a high potential for fake shuttle passes, parking permits and official fan transport QR codes that fail when scanned. The geographic spread of the 2026 games in various cities multiplies opportunities for transit-themed fraud relative to single-host-city games.

#### Phishing, Malware and Lure Themes

Confirmed [lure themes](https://www.group-ib.com/media-center/press-releases/scammers-on-the-pitch/) from prior tournaments include:

* Lottery winnings
* Ticket cancellations
* FIFA dispute-resolution decisions
* Accreditation problems
* FanID issues
* Free streaming
* Counterfeit merchandise

Expect to see typosquatted FIFA domains, malicious mobile applications, infostealers sold on Telegram, and Telegram-based reseller channels moving money via peer-to-peer payment apps as seen in Table 2.

|                 **Cybercriminal Vector**                 |                                                                            **Primary Targets**                                                                            |
|----------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Phishing/lookalike domains/typosquatting                 | All fans, especially first-time international travelers                                                                                                                   |
| Fake/resold tickets; FanID account takeover              | Fans buying outside the FIFA platform                                                                                                                                     |
| Hospitality ransomware (High-profile operators)          | Hotel chains, property management, casino-resort venues                                                                                                                   |
| DDoS against host-city, federation or ticketing services | Pro-Russian and pro-Iran hacktivist targets                                                                                                                               |
| Hack-and-leak/doxxing of officials, sponsors, athletes   | Officials, sponsors, athletes                                                                                                                                             |
| QR-code/transportation/parking fraud                     | Fans moving between host cities                                                                                                                                           |
| Mobile malware via fake apps in official stores          | Android primarily; [iOS via TestFlight](https://www.hkcert.org/security-bulletin/malware-alert-public-should-beware-of-golddigger-malware-targeting-ios-devices_20240220) |

Table 2. Cybercriminal techniques that are possible during the World Cup.

## Geopolitical Threats: Iran-Nexus and Disruptive Hacktivism

The geopolitical context for the 2026 tournament is materially different from any prior World Cup. The U.S.-Israel-Iran conflict has produced a surge in Iran-nexus cyber operations against U.S. organizations. The Russia-Ukraine war and the resulting NATO alignment of all three host nations make pro-Russian hacktivism an additional, parallel risk.

### Iran-Nexus: The Handala Hack Team

The [Handala Hack Team](https://www.fdd.org/analysis/2026/04/01/6-things-to-know-about-handala-tehrans-hackers-making-front-page-news) (aka [Banished Kitten](https://www.crowdstrike.com/en-us/adversaries/banished-kitten/), [Storm-0842](https://www.cfr.org/cyber-operations/storm-842), [Void Manticore](https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/) and [Cobalt Mystique](https://www.sophos.com/en-us/threat-profiles/cobalt-mystique)) and [Ababil of Minab](https://cdn.prod.website-files.com/69944dd945f20ca4a27a7c47/6a155deeaffba9a1bf3c5b63_Ababil_of_Minab_Tech_Report.pdf), are [just two of several](https://ict.org.il/bibi-gate-handala-hack-team-a-mask-for-iranian-psychological-warfare/) front [personas](https://www.govinfosecurity.com/inside-tehran-linked-faketivist-hacking-group-handala-a-31001) operated by Iran's MOIS directly responsible for wiper attacks, [targeting high-level government officials](https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/), and [doxxing employees](https://cybernews.com/security/lockheed-martin-israel-breach-handala/) of [public companies](https://www.iranwatch.org/library/governments/united-states/executive-branch/department-justice/justice-department-disrupts-iranian-cyber-enabled-psychological-operations).

### Iran-Nexus: CyberAv3ngers and OT Targeting

[CyberAv3ngers](https://www.tenable.com/blog/what-to-know-about-cyberav3ngers-the-irgc-linked-group-targeting-critical-infrastructure) (aka [Shahid Kaveh Group](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a), [Bauxite](https://www.dragos.com/threat/bauxite), [Hydro Kitten](https://www.crowdstrike.com/en-us/adversaries/hydro-kitten/), [Storm-0784](https://www.microsoft.com/en-us/security/blog/2024/05/30/exposed-and-vulnerable-recent-attacks-highlight-critical-need-to-protect-internet-exposed-ot-devices/) and [UNC5691](https://cloud.google.com/blog/topics/threat-intelligence/securing-protection-relays-modern-substations)) is the [IRGC Cyber-Electronic Command's](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a) industrial-control-system arm. Its [documented escalation curve](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a) is the single most important data point for defenders concerned with municipal infrastructure during the FIFA World Cup 2026.

Every World Cup host city in the United States operates municipal water, wastewater and energy infrastructure inside this advisory's threat envelope. A 2024 [CISA assessment](https://www.epa.gov/newsreleases/epa-outlines-enforcement-measures-help-prevent-cybersecurity-attacks-and-protect) found over 70% non-compliance with existing safety requirements at U.S. water utilities.

### Iran-Nexus: Other Personas and the Electronic Operations Room

Beyond Handala and CyberAv3ngers, multiple Iran-aligned personas --- DieNet, APTIran, Cyber Toufan, Cyber Support Front, Iranian Avenger, Cyb3r Drag0nz --- have been [observed](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/) operating through a team named the [Electronic Operations Room of Islamic Resistance Axis](https://www.sophos.com/en-us/blog/hacktivist-campaigns-increase-as-united-states-iran-and-israel-conflict-intensifies). This team formed in late February 2026. DieNet has specifically claimed DDoS attacks against Bahrain and Saudi airports and Jordanian banks --- transportation and finance targets directly relevant to fan-facing infrastructure.

### Russia-Nexus: NoName057(16) and Allied Hacktivists

NoName057(16) has been the most operationally consistent pro-Russian hacktivist group since March 2022, with an [attributed 3,700-plus targeted hosts](https://www.recordedfuture.com/research/anatomy-of-ddosia) to the group between July 2024 and July 2025. The [UK NCSC, Eurojust and Europol](https://www.ncsc.gov.uk/news/pro-russia-hacktivist-activity-continues-to-target-uk-organisations) issued co-sealed advisories in December 2025 and January 2026 regarding the hacktivist group. Operation Eastwood [produced two arrests](https://www.google.com/url?q=https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network&sa=D&source=docs&ust=1778859185926429&usg=AOvVaw3GKL_K65QESvXL1Cj4X38d) and seven arrest warrants but did not stop the group, which resumed activity within days.

Three operational characteristics are directly relevant to 2026:

* **Event-keying:** [DDoSia operations](https://www.recordedfuture.com/research/anatomy-of-ddosia) have [repeatedly surged](https://www.intel471.com/blog/cyber-threat-landscape-2024-paris-olympic-games) in the 24-72 hours surrounding politically symbolic events.
* **Volunteer-driven scale:** DDoSia [rewards volunteer participants](https://www.recordedfuture.com/research/anatomy-of-ddosia) with cryptocurrency and runs on Windows, Linux, Android and Docker.
* **OT expansion:** A [co-sealed advisory](https://www.google.com/url?q=https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a&sa=D&source=docs&ust=1779122815533629&usg=AOvVaw1j01ZKR0uRcN171nlXhWoO) and subsequent UK NCSC alert [specifically warns](https://www.ncsc.gov.uk/news/pro-russia-hacktivist-activity-continues-to-target-uk-organisations) that pro-Russian hacktivists have moved beyond DDoS into operational technology (OT) targeting via exposed VNC and remote-access services.

Information Operations  
Major global sporting events have proven fertile ground for state-sponsored information operations aimed at sowing distrust in institutions, embarrassing athletes or nations, and amplifying narratives conducive to strategic interests. [Russian influence operations](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/) are well established with past reported activities surrounding [leaked athlete data](https://ru.usembassy.gov/the-united-states-condemns-malicious-cyber-activity-targeting-germany-czechia-and-other-eu-member-states/), [AI-enabled deception and defaming](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/MTAC_Report_Russian_Influence_and_Paris_2024.pdf), [delegitimization of Ukraine and Ukrainian athletes, narratives of the West against Russia, and pro-Kremlin narratives](https://www.disinformationindex.org/blog/2026-03-10-milano-cortina-2026-three-information-manipulation-playbooks-on-one-global-stage/).

The current conflict in Iran opens the door for potential [Iran-based narrative](https://www.csis.org/analysis/tapping-americas-distaste-forever-wars-spread-iranian-narratives-bluesky) [amplification](https://rsis.edu.sg/rsis-publication/rsis/inside-irans-information-war-on-the-us-ai-propaganda-and-perception-management/), consistent with its observed [hybrid offensive approach](https://ndupress.ndu.edu/Portals/68/Documents/prism/prism_9-2/prism_9-2_77-97_Eisenstadt.pdf?ver=GfdJ0-b5_6KkllvHhvOYZA%3d%3d), specifically aimed at compounding the division of support for kinetic activity and targeting countries or athletes from Gulf states perceived as adversarial.

People's Republic of China-aligned [Dragonbridge](https://cloud.google.com/blog/topics/threat-intelligence/prc-dragonbridge-influence-elections) has increasingly experimented with and [deployed generative AI tools](https://blog.google/threat-analysis-group/google-disrupted-dragonbridge-activity-q1-2024/) --- such as synthetic audio, AI-generated news hosts, avatars, and images --- to [scale its political influence operations](https://blog.google/threat-analysis-group/over-50000-instances-of-dragonbridge-activity-disrupted-in-2022/) across social media, though these efforts have ultimately failed to garner significant organic engagement from authentic viewers.

## Temporary Multi-City Tournament Infrastructure

FIFA's published [tournament structure](https://en.wikipedia.org/wiki/2026_FIFA_World_Cup) presents a unique and historically large attack surface. Sixteen host cities span three host nations, four time zones and multiple regulatory regimes. Each match operates a layered, ring-based tournament network grafted onto a permanent stadium environment, depends on a temporary commercial supplier ecosystem and pulls on host-city public services that FIFA does not own. Table 3 lists these rings and the primary cyber risk to each.

#### Network Rings and What Each Ring Is For

|                        **Ring**                         |                                           **Function**                                            |                                                                                                      **Primary Cyber Risk**                                                                                                       |
|---------------------------------------------------------|---------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Field-of-play/Video Assistant Referee (VAR)/officiating | Goal-line technology, semi-automated offside, Video Assisted Review, in-stadium broadcast cabling | Integrity-of-competition attack; broadcast disruption during a key moment                                                                                                                                                         |
| Venue operational network                               | Access control, ticket scanning, screens, public-address, Wi-Fi, accreditation                    | Replay of the [Pyeongchang scenario](https://blog.talosintelligence.com/olympic-destroyer/): Wi-Fi, app, ticketing, gates rendered [unusable](https://www.recordedfuture.com/research/olympic-destroyer-malware)                  |
| Tournament management                                   | Schedule, results, statistics, athlete management, broadcaster feeds                              | [Wiper or ransomware](https://www.gov.uk/government/news/uk-exposes-series-of-russian-cyber-attacks-against-olympic-and-paralympic-games) timed to opening match or final; data integrity                                         |
| Hospitality and commercial                              | VIP access, payments, loyalty, hospitality suites, sponsor activations                            | Hospitality-stack [ransomware](https://www.cyberark.com/resources/blog/the-mgm-resorts-attack-initial-analysis); PII and payment information exfiltration                                                                         |
| Fan-facing digital                                      | FIFA app, official ticket resale, FanID, streaming, social                                        | [Account takeover, FanID compromise, content defacement, mobile malware](https://www.group-ib.com/media-center/press-releases/scammers-on-the-pitch/)                                                                             |
| Host-city public services                               | Transit, traffic signals, water, wastewater, power, airports, emergency services                  | Iran-nexus [OT targeting](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a) per [CISA AA26-097A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a); cascade impact on tournament operations |

Table 3. Network rings and use cases.

### The Supplier Ecosystem

The 2026 supplier ecosystem will be vast. Each host city contracts independently for stadium operations, security, transit, hospitality, food service, signage, fan-zone production and last-mile network connectivity. The [Pyeongchang 2018 Olympic Destroyer destructive case](https://blog.talosintelligence.com/olympic-destroyer/) is a clear historical warning: Recorded Future identified that Olympic Destroyer samples targeting the IT service provider were timestamped five minutes ahead of samples targeting the host.

## Impact on Municipal, State and Federal Infrastructure

#### Municipal Layer

CISA AA26-097A [identifies](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a) "Government Services and Facilities (to include local municipalities)" as one of three named target sectors of the active Iran-nexus PLC campaign. Analysis of [CyberAv3ngers' targeting](https://www.tenable.com/blog/what-to-know-about-cyberav3ngers-the-irgc-linked-group-targeting-critical-infrastructure) found that small municipal authorities are deliberately selected because they manage OT with consumer remote-access tools or expose PLC interfaces directly to the internet. A [January 2024 Russian cyberattack](https://cyberscoop.com/sandworm-apt44-texas-water-facility/) on a municipality in Texas resulted in successfully [overflowing a water tank](https://www.govtech.com/security/overflowing-water-tank-linked-to-russian-cyber-attack) after unsuccessful attempts in neighboring water systems. Ransomware attacks on water systems have also occurred.

#### State and Provincial Layer

Pro-Russian hacktivist DDoS has already demonstrated the ability to [take state and local government websites](https://statescoop.com/russia-ukraine-killnet-ddos-state-governments/) offline for hours. UK [NCSC's January 2026 alert](https://www.ncsc.gov.uk/news/pro-russia-hacktivist-activity-continues-to-target-uk-organisations) specifically called out persistent NoName057(16) targeting of UK local-government services. The U.S., Canadian and Mexican equivalents are inside the same threat envelope.

#### Federal Layer

Federal agencies have signaled awareness: CISA AA26-097A, the DOJ domain-seizure activity against Iranian cyber fronts and the U.S. State Department's $10 million [reward offers](https://rewardsforjustice.net/rewards/islamic-revolutionary-guard-corps-irgc-key-leaders/) indicate active coordination. Defenders should expect and request pre-tournament threat-sharing engagements with CISA, FBI, the Canadian Centre for Cyber Security and Mexico's CERT-MX, mirroring the model that ANSSI ran in advance of Paris 2024.

#### Cascading-Risk Scenarios

Two specific scenarios merit pre-tournament tabletop exercise.

##### **OT Disruption at Host-City Utility During Match**

*Scenario*: An Iran-nexus actor manipulates a wastewater PLC in a host city overnight before a knockout match, producing a service alert and a forced public-health advisory.

##### Mitigation

* Pre-tournament audit of all internet-exposed PLCs per CISA AA26-097A
* Mandated migration off TeamViewer/AnyDesk for OT
* Default-credential audits
* 24/7 OT incident-response retainer

##### **Hospitality Ransomware in Final Week**

*Scenario:* A [Muddled Libra-style social-engineering campaign](https://unit42.paloaltonetworks.com/muddled-libra/) against a major host-city hotel operator collapses room access, mobile check-in and PoS for 48-72 hours during the run-up to the July 19, 2026, final at MetLife Stadium.

##### Mitigation

* Pre-tournament tabletop exercises with major hotel groups
* Explicit verification protocols on IT help desks
* Segregation of IdP trust from ESXi management
* Offline runbooks for the property-management system

### Prioritized Threat Matrix

The following matrix in Table 4 consolidates the assessed likelihood and severity of each evidence-backed threat vector for the tournament window of June 11-July 19, 2026. Severity is conditioned on the potential impact to fans, host cities and the integrity of the competition.

|                    **Threat Vector**                     |            **Severity**             |                         **Primary Actor Class**                          |
|----------------------------------------------------------|-------------------------------------|--------------------------------------------------------------------------|
| Phishing, fake tickets, lookalike domains targeting fans | Low-medium per fan; cumulative high | Cybercriminal                                                            |
| FanID/FIFA-portal account takeover                       | Medium                              | Cybercriminal                                                            |
| Hospitality ransomware against major hotel operator(s)   | High                                | Cybercriminal (Muddled Libra (aka Scattered Spider)/high-profile actors) |
| DDoS against host-city, federation or ticketing services | Medium                              | Pro-Russian and pro-Iran hacktivist                                      |
| Hack-and-leak/doxxing of officials, sponsors, athletes   | Medium-high                         | Iran-nexus (Handala) and adjacent personas                               |
| Wiper/destructive operation against a vendor or venue    | High-critical                       | Iran-nexus state-backed; Russia-nexus state-backed                       |
| OT disruption at a host-city utility                     | High                                | Iran-nexus (CyberAv3ngers-class)                                         |
| Disinformation/AI-generated content around matches       | Medium                              | Multiple state and non-state actors                                      |
| Insider compromise at a tournament supplier              | High                                | Cybercriminal-for-hire; state-backed                                     |
| Mobile malware via fake apps in official stores          | Medium                              | Cybercriminal                                                            |

Table 4. Prioritized threat matrix of likely cyberattacks.

## Recommendations

These recommendations are derived from the threat picture above and from public after-action reporting on Paris 2024 and Milan-Cortina 2026. They are prioritized by impact rather than by category.

**For the tournament organization and host-city committees**

* Stand up a single, multi-jurisdictional cyber operations center with U.S. CISA, the Canadian Centre for Cyber Security, Mexico's CERT-MX, the FBI, the RCMP and Mexican federal cyber liaison co-located or fully integrated, replicating the ANSSI/Paris 2024 model.
* Inventory the full vendor and supplier graph for each host city and conduct credential-rotation, default-password and remote-access audits across that graph. Prioritize IT service providers and venue operations, which Recorded Future identified as Pyeongchang's primary breach vector.
* Mandate that no tournament network, at any ring, permits consumer remote-access tools on production infrastructure for the duration of the tournament window.
* Pre-position DDoS scrubbing capacity, content-delivery-network failover and rate-limiting on all fan-facing domains. NoName057(16) DDoS volumes during Paris 2024 peaked at 190,000 requests/second; defenders should plan for an order of magnitude above that.
* Run a destructive-malware tabletop. Validate that backups are isolated, immutable and recoverable inside a four-hour window.

**For host-city utilities and municipal operators**

* Audit every internet-exposed PLC, HMI and SCADA component in water, wastewater, energy and transit operations. Apply CISA AA26-097A and AA23-335A guidance specifically: Change all default credentials, place PLCs behind segmented firewalls and eliminate direct internet exposure on ports 44818, 2222, 102, 22 and 502.
* Engage the FBI, CISA and EPA for sector-specific assessments before kickoff. Where budget is constrained, a single round of vulnerability scans focused on the AA26-097A indicator set is high value.
* Establish 24/7 OT incident response coverage through the entire tournament window.

**For hospitality and venue operators in host metros**

* Treat the IT help desk as the first line of defense and the most likely point of compromise. Implement out-of-band caller-verification protocols; ban credential resets initiated by phone alone; assume that publicly identifiable employees are reconnaissance targets.
* Segregate identity-provider trust from VMware ESXi management. Previous compromises pivoted from Okta to ESXi to ransomware; that pivot path must be broken architecturally before the tournament, not during it.
* Maintain offline runbooks for property-management, PoS, digital-key and reservation systems. Confirm pen-and-paper fallback works under load.

**For sponsors, federations and broadcast partners**

* Assume executive personal accounts are in scope for state-aligned hack-and-leak operations.
* Apply phishing-resistant MFA (FIDO2/WebAuthn) to all corporate, executive and high-visibility employee accounts before kickoff. SMS and TOTP MFA are insufficient against the demonstrated tradecraft of Scattered Spider and Handala.
* Pre-build communications response templates for hack-and-leak scenarios; do not draft them under live attack.

**For fans and the traveling public**

* Buy tickets only on the official FIFA platform or a FIFA-authorised resale partner. Do not buy through Telegram, WhatsApp, social media DMs or peer-to-peer payment apps. Use a credit card with chargeback protection.
* Verify accommodation listings with major platforms; treat off-platform wire transfers and cryptocurrency requests as fraud. Cross-reference street view and listing photos.
* Treat any QR code presented in transit, parking or fan-zone contexts with skepticism. Cross-check with the host city's official transportation app or website before scanning.
* On public Wi-Fi, use a reputable VPN for any account-level activity; better still, use cellular data. Disable Wi-Fi auto-join; remove networks after use.
* Patch mobile devices. Avoid sideloading apps. Verify every FIFA app against the FIFA-published list of official applications.

## Final Thoughts

The window for shifting from preparation to live response is closing fast. The 2026 FIFA World Cup conditions are different than at any previous tournament: three host nations, sixteen host cities, a 48-team field, an active U.S.-Israel-Iran kinetic conflict, an ongoing Russia-NATO confrontation and a cybercriminal ecosystem that has industrialized against the hospitality sector since 2023.

The threat actors of greatest concern for 2026 --- the Handala Hack Team, CyberAv3ngers, NoName057(16), Muddled Libra, ALPHV affiliates and the broader Iran- and Russia-aligned hacktivist ecosystem --- have all demonstrated their capabilities within the last 24 months. This has been proven in public record by what these actors have already accomplished.

Plan for incidents across the full supplier and host-city graph, exercise the response against realistic scenarios and coordinate across jurisdictions before kickoff rather than during the tournament. Where that posture has been adopted, the historical record shows that competition has not been disrupted. Where it has been weaker, adversaries have succeeded. The single most important defender posture for 2026 is to assume the attacks will come.

**Additional Resources**

* [Analysis of domains taking advantage of FIFA World Cup](https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-05-19-Analysis-of-domains-taking-advantage-of-FIFA-World-Cup-2026.txt?utm_campaign=tti_worldcupfrauddomains) -- Timely Threat Intelligence, Unit 42 on GitHub
* [Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/) -- Unit 42, Palo Alto Networks
* [2026 Unit 42 Global Incident Response Report](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report) -- Unit 42, Palo Alto Networks
  Back to top

### Tags

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")
* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")
* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [QR Codes](https://unit42.paloaltonetworks.com/tag/qr-codes/ "QR Codes")
* [Razing Ursa](https://unit42.paloaltonetworks.com/tag/razing-ursa/ "Razing Ursa")
* [Typosquatting](https://unit42.paloaltonetworks.com/tag/typosquatting/ "typosquatting")
* [Wiper](https://unit42.paloaltonetworks.com/tag/wiper/ "wiper")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")

### Table of Contents

* 

### Related Articles

* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")
* [When "Hi, This Is IT" Comes Through Microsoft Teams](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/ "article - table of contents")

## Related Resources

![Pictorial representation of a woman in glasses viewing a reflection of a monitor screen. The reflection features multicolored numbers, arrows, and graphs.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/07_Opinion_Overview_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 2, 2026 [#### An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation](https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/ "An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation")  
  ![New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_General_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 28, 2026 [#### Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety](https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Jailbreak](https://unit42.paloaltonetworks.com/tag/jailbreak/ "Jailbreak")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/ "Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety")  
  ![Pictorial representation of a male individual viewing multiple monitor screens. The blurred background indicates a female indiviual in the back, also viewing multiple monitor screens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/09_Myth-Busting_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 21, 2026 [#### Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain](https://unit42.paloaltonetworks.com/sdlc-supply-chain/)

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Npm packages](https://unit42.paloaltonetworks.com/tag/npm-packages/ "npm packages")

* [Software supply-chain attack](https://unit42.paloaltonetworks.com/tag/software-supply-chain-attack/ "software supply-chain attack")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/sdlc-supply-chain/ "Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain")  
  ![Pictorial representation of large-scale credential attacks. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 18, 2026 [#### Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)](https://unit42.paloaltonetworks.com/large-scale-credential-attacks/)

* [Credential theft](https://unit42.paloaltonetworks.com/tag/credential-theft/ "credential theft")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/large-scale-credential-attacks/ "Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)")  
  ![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of WebAuthn. A person wearing glasses with computer code reflected in the lenses. The focus is on the eye, and the code is clear and detailed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Myth-Busting_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) July 2, 2026 [#### How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/)

* [IDA Pro](https://unit42.paloaltonetworks.com/tag/ida-pro/ "IDA Pro")

* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")

* [RDP](https://unit42.paloaltonetworks.com/tag/rdp/ "RDP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "How We Added WebAuthn to a Browser-Based RDP Client")  
  ![Pictorial representation of an individual typing on a laptop featuring pop-up screens of lists and tasks.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) June 12, 2026 [#### Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/)

* [Digital forensics](https://unit42.paloaltonetworks.com/tag/digital-forensics/ "digital forensics")

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/ "Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered")  
  ![Pictorial representation of an aerial view of an individual working on a cumputer in an office setting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/02_Opinion_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) June 8, 2026 [#### When "Hi, This Is IT" Comes Through Microsoft Teams](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Identity](https://unit42.paloaltonetworks.com/tag/identity/ "identity")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/ "When “Hi, This Is IT” Comes Through Microsoft Teams")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
