As the World Cup approaches, payment security agencies warn of fraud and chargebacks
As the 2026 FIFA World Cup kicks off in North America, payment security agencies such as ACI Worldwide and Bluefin Payment Systems have issued warnings that fraudsters are exploiting the surge in online ticketing and spending brought by the event to launch attacks. Based on an analysis of 24.5 million transactions from 61 past events, ACI found that fraud attempts spike just before the event. Both agencies advise merchants to strengthen defenses, be wary of tactics such as fake ticketing websites and phishing attacks, and note the amplifying effect of AI technology on fraudulent activities.

When major events like the World Cup generate a surge in online ticket sales and related merchandise consumption, fraudsters also seize the opportunity to profit from this active period. Payment security service providers ACI Worldwide and Bluefin Payment Systems recently issued warnings that the FIFA World Cup currently underway in North America could trigger a wave of fraud and chargebacks.
Both organizations provide fraud protection for event organizers and merchants. Their concerns are closely linked to the current backdrop of artificial intelligence technology exacerbating global online fraud. According to a report released in March by Verafin, a Nasdaq company, the total amount stolen by cybercriminals worldwide in 2025 increased by 9.2% compared to 2024, partly due to the proliferation of AI technology. Verafin also provides financial crime fighting software.
ACI analyzed merchant data from past events, specifically covering 24.5 million global transactions from 61 live events, including the 2022 World Cup, in order to gain a deeper understanding of fraud patterns. According to a press release issued this month by the Nebraska-based company headquartered in Elkhorn, its analysis revealed clear patterns.
Ahead of the 2026 FIFA World Cup kicking off this month, ACI has already identified similar patterns, indicating that fraud related to the event is on the rise. Jackie Barwell, the company's director of fraud product management, said the company is trying to alert customers and provide them with protective measures to identify and block fraud through tools such as consumer data insights, device intelligence, and geolocation inputs.
"We have been advising them to increase vigilance," Barwell said in an interview this month from her office in Bromley, England. She noted that merchants need to be prepared to scale operations to handle increased demand. Barwell explained that criminals exploit the unique nature of the event to create opportunities for payment volume spikes when merchants may be short-staffed or even using temporary employees unfamiliar with processes.
Barwell said fraud typically targets merchants selling event-related tickets and accommodations, appearing about 8 to 12 weeks before the event begins and intensifying as the event approaches. Fraud attempts generally range from $200 to $400 and rise as the event nears. Fraudsters create fake websites, steal consumer credentials and related information in card-not-present transactions—whether conducted via mobile devices, apps, or phone—and then use that information to make purchases immediately or shortly thereafter on legitimate websites during busy transaction periods.
"Cybercriminals are targeting the entire fan journey, from searching for tickets and booking travel to watching live matches and purchasing merchandise," said Brent Johnson, chief information security officer at Bluefin, in an email. "We have seen the highest concentration of attacks focused on fraudulent ticketing sites, counterfeit FIFA domains, fraudulent hospitality services, phishing campaigns, and counterfeit merchandise websites." Johnson noted that criminals exploit fans' urgency and emotional state during purchases. Fraudsters thrive in environments where consumers make high-value transactions on unfamiliar websites.
Atlanta-based Bluefin believes AI amplifies this threat. "Artificial intelligence enables criminals to generate professional-looking websites, phishing emails, fake QR codes, and customer communications, making it harder for consumers to distinguish them from legitimate ones," Johnson said.
ACI data shows that locally issued cards—for example, those issued in a specific country—are more susceptible to criminal activity than international cards. Barwell explained this could mean fraudsters are locals familiar with the local payment environment. Even consumers who are not directly victimized may be affected by heightened merchant vigilance. "This pattern increases the risk of genuine fans being mistakenly rejected when purchasing high-value tickets," ACI's press release stated.
Barwell predicts that the full impact of fraud related to this year's World Cup has not yet materialized, and when it arrives, some merchants may be shocked. It is not until the event approaches the July 19 final that consumers begin reporting fraudulent transactions, thereby generating a wave of chargebacks for merchants. Whether merchants overall are better prepared for fraud this World Cup remains an open question. "Time will tell," Barwell said, though she believes ACI's merchant clients will be well protected.
Johnson emphasized that protecting data security is key. "Organizations should not only focus on preventing fraudulent transactions but also minimize exposure of sensitive payment data through technologies such as tokenization and point-to-point encryption," he explained. "Even if attackers successfully breach the transaction path, reducing the value of the underlying payment data can significantly limit the impact of the attack."