Global events have become one of the most coveted targets for the global cybercrime landscape. The celebration of the FIFA World Cup 2026 will mobilize millions of fans around the world, but it will also significantly raise companies’ exposure to cyberattacks. In this context, Hiscox emphasizes the importance of organizations taking immediate, practical steps to protect their operations, revenue, and corporate reputation, as reflected in the Hiscox Cyber Readiness Report 2025, which shows that 94% of Spanish organizations plan to increase their cybersecurity investment this year.
The World Cup in the cybercriminals’ crosshairs
The high visibility of major sporting events and the extreme complexity of their supply chains create a highly attractive attack surface for both organized criminal groups seeking financial gain through ransomware and for state-linked actors amid geopolitical tensions.
To illustrate the scale of the threat, Hiscox highlights some of the most notable incidents recorded in the international sports ecosystem in recent years:
- The digital blackout at the Winter Olympics in PyeongChang, a clear example of an attack motivated by sabotage and the pursuit of reputational impact. A malware (known as Olympic Destroyer) infiltrated the IT systems of the event’s vendor IT companies. The result severely affected television and internet networks, disabled stadium Wi‑Fi, and prevented many spectators from loading their digital tickets, leaving empty seats during the opening ceremony.
- Broadcast interruptions at the European Championship: recently, online streams of several matches of the Poland national team were disrupted by Distributed Denial of Service (DDoS) attacks. The attackers bombarded the servers with massive traffic until they saturated, demonstrating the vulnerability of digital platforms to these hacking techniques.
- Ticketing-related fraud and attacks: in major recent competitions, cybercriminals have exploited high demand to launch phishing and fraud campaigns related to ticket sales, as well as to attempt to compromise platforms managed by third parties, putting both organizations and fans at risk.
However, the risk is not limited to the event organizers. Businesses linked directly or indirectly to the World Cup—such as local businesses, hotels, or transportation companies—can also become targets of cybercriminals. A cyberattack can translate into direct financial losses—for example, reservation cancellations if a hotel’s systems go down—or even operational disruptions that affect the movement of teams and fans.
Tips for preparing for the heightened cyber risk
Against this backdrop, Hiscox recommends prioritizing five key measures:
- Ensure operational resilience and test backups: it’s crucial to assume disruption is a real possibility. Companies should verify that their backups can be restored in time and have alternative contingency providers or standby servers if the primary chain fails.
- Protect critical systems: review defenses against ransomware and DDoS attacks, especially on ticketing or reservation platforms.
- Review supplier security: cyber risk rises during major events due to complex supply chains, so it’s essential to audit the resilience of key suppliers as well as your own.
- Train employees: help desks and staff remain primary targets for social engineering and cybercriminals. Regular security awareness training is essential.
- Prepare incident response: it’s important to agree in advance on roles, communications, and steps to escalate so teams can act quickly if an attack occurs.
“The high visibility and complexity of the tournament make it an attractive target for both state-sponsored cyberattacks and organized criminal groups seeking financial gain. It’s a threat environment that should place the development of operational and business resilience in the face of cyber threats at the top of the agenda for all companies involved in the World Cup,” notes Hiscox Spain.