Major sporting events, major risks—here’s how cyberattackers exploit global events
When the world’s attention is focused on a major sporting event, it’s not just the fans who are brimming with excitement. For cyberattackers, these periods present an excellent opportunity to launch phishing campaigns by exploiting people’s interest, curiosity, and trust.
Ticket purchases, sweepstakes, betting opportunities, and exclusive offers are all topics that users tend to be less suspicious of. That is precisely why scams capitalizing on these themes regularly surge during major international events.
Real-World Attack Scenarios
Security researchers have identified several active campaigns that specifically capitalize on the popularity of major sporting events.
Fake Betting Sites and Crypto Wallet Scams
One of the most dangerous methods involves using professionally designed sports betting or casino sites that appear completely legitimate at first glance.
Users are encouraged to connect their cryptocurrency wallets in order to receive a bonus or access exclusive betting opportunities. However, in the background, a so-called “wallet drainer” is at work, which, once it gains the necessary access, can drain the entire balance of the wallet.
Fake Ticket Sales Sites
The second common method is to copy well-known ticket sales providers.
Attackers register domains that differ from the original by just a single character. A minor typo or moment of inattention is enough for a user to end up on the fake site, where they enter their credit card details, login credentials, or personal information.
These so-called typosquatting attacks are becoming more sophisticated every year.
Fake Sweepstakes
Another common tactic is sending emails along the lines of “Congratulations, you’ve won!”
These messages claim that the recipient has won an official lottery, but in order to claim the prize, they are asked to pay a registration fee, shipping costs, or provide personal information.
Although these scams have been around for decades, artificial intelligence now makes it possible to create emails that are extremely convincing both linguistically and visually.
Why does email remain the number one target for attackers?
Most of these campaigns ultimately reach the victim via email.
Attackers know full well that email is the most important communication channel within a company. A well-crafted message that mentions a well-known brand, a current event, or an urgent action is much more likely to entice the user to click.
Moreover, modern attacks no longer necessarily contain a virus or an infected attachment. In many cases, they rely solely on psychological manipulation, personalization, and trust-building.
Traditional spam filtering is no longer sufficient
Keyword- or signature-based filtering alone is no longer enough to detect today’s phishing campaigns.
Cisco Secure Email Threat Defense employs multi-layered protection that uses artificial intelligence, behavioral analysis, relationship modeling, and Cisco Talos’s global threat intelligence to determine whether an email is part of a legitimate communication or a sophisticated phishing attack. The analysis examines not only attachments and links, but also sender behavior, communication patterns, and business relationships. This enables the detection of Business Email Compromise (BEC), impersonation, and brand spoofing attacks that would easily slip past traditional filters.
Prevention requires multi-layered protection
Successful protection does not depend on a single technology. The best results are achieved when an organization implements the following simultaneously:
- a state-of-the-art email security solution;
- DMARC, SPF, and DKIM authentication;
- multi-factor authentication (MFA);
- regular security awareness training;
- rapid incident detection and response processes.
The themes of the attacks change, but the method remains the same
Today it’s a world championship, tomorrow a concert series, a Black Friday sale, or tax season—all provide attackers with the perfect pretext. The goal, however, is always the same: to trick the user into clicking a link or entering data that opens the door to further attacks.
Modern email security is therefore no longer just about filtering out spam. We need intelligent protection solutions capable of detecting deception before the email even reaches the user’s inbox. Cisco Secure Email Threat Defense supports this with AI-based threat detection, real-time analysis, and automated incident management, significantly reducing the likelihood that a sophisticated phishing campaign will succeed.


