Advertisement

‘Integrated’ cyber and physical attacks concerned FIFA planners

“The threat environment has changed" and the lines between physical and digital attacks have blurred, said one security expert involved in FIFA World Cup Planning.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
FIFA fans
Supporters react as the United States men's national soccer team defeats Australia 2-0 at FIFA Fan Fest at Centennial Olympic Park on June 19, 2026 in Atlanta, Georgia. (Julia Beverly / Getty Images)

Among the events that did not occur during any of this year’s FIFA World Cup matches was a terrorist hijacking a jumbotron. Not during any one of the 78 games hosted in the United States this year was an AI-generated video shown to tens of thousands of startled soccer fans, falsely warning them of an imminent explosion somewhere in the stadium. And although that scenario did not occur this year, it was one of many possible scenarios that event planners prepared for leading up to the global sporting event that concluded on Sunday with fireworks, not bombs, and a 1-0 Spanish victory over Argentina.

John Cohen, executive director of the office of strategic programs and initiatives at the Center for Internet Security, an Upstate New York nonprofit that assists state and local governments with their cybersecurity, said it’s a sign of the times that such considerations of digital intrusion were this year put on equal footing with more traditional, physical threats associated with large-scale events.

“The threat environment has changed,” Cohen said in an interview. “Typically the way state, locals and event organizers would prepare for an event like the World Cup would be to ensure they were adequately prepared to deal with physical issues, whether it’s a mass casualty attack or some type of disruption. In today’s environment, as with other day-to-day threat mitigation efforts, they have to take into account events that occur in both the digital and physical worlds, because they’ve converged.”

A report published by the center on Monday counts more than one billion cyberattacks that were blocked over the course of the games, by a multidisciplinary group of planners. Planning for the World Cup, an event spanning 39 days, started last year, Cohen said, as state and local governments and private companies associated with the events — everything from banks to bus operators — outlined every contingency they could imagine, some of which eventually arose and were thwarted.

Advertisement

Most sports arouse passion in their fans, but soccer’s reputation had preceded the summer’s international matches. Threats the FIFA planners imagined, and then sometimes encountered, included threats of violence against players, fans and referees, Jihadist calls for knifings and arson, ticketing scams, AI-fueled social media disinformation campaigns run by nation-states and malicious web domains preying on clumsy typists. “Whether it was being prepared for an active shooter, demonstrations intended to disrupt access, attacks to the critical infrastructure, transportation, banking, hospitality, whether it was dealing with the various types of criminal activity typically associated with these types of events, whether it’s human trafficking or false credentialing or ticket fraud, everyone had to be on the same page, and that requires planning,” Cohen said.

Cohen praised FIFA, the soccer organization’s self-governing body, for its success in convening a widened scope of planning participants. The center played its role in the planning, too, conducting risk assessments and, working with FIFA and the National Fusion Center Association and state and local law enforcement agencies, providing an information-sharing platform that would eventually be used by 4,000 people monitoring the games. “It wasn’t just sharing information so people were informed,” Cohen said. “It was sharing information so operational activities could be informed. This is the way, unfortunately, in the current threat environment.”

Threats came from every vector, Cohen said — and information on cyberattacks, swatting hoaxes and malicious domains were shared so law enforcement agencies, organizers and state and local governments could act. The center researched malicious domains and in some cases managed to connect them to other malicious domains known to be seeking to disrupt the games’ infrastructure. Cohen said the center in some cases provided “tactical guidance, on a number of occasions” to “state and local host regions” that were experiencing cybersecurity incidents. “During high visibility events such as this, the eyes of the world are on you, and if you’re a hotel, a hospital, a restaurant, a mass transit system that’s responsible for moving hundreds of thousands of people within a compressed timeframe, if you’re the banking industry and you have ATMs that need to be operating, a ransomware attack could have a direct impact on your being a viable part of these games,” Cohen said of the incentives guiding the event’s would-be disrupters.

Sporting events propel malicious campaigns by nation-states — in this case, Russia is suspected to have been behind social media accounts using the games as a means of furthering anti-U.S. propaganda — and attract terrorist organizations that want attention for their causes. The center’s recent report recalls a newsletter last month in which the Islamic State called the World Cup, which would include games in 11 U.S. cities, “a golden opportunity” for so-called “lone-wolf attacks,” in which enterprising terrorists could use knives, vehicles and fire to injure others and attract attention.

But there was one potential threat category for which organizers held “real concern,” Cohen said. This was “integrated” attacks, those that combine avenues of attack, launched simultaneously to catch organizers off-guard and possibly render them unable to communicate. Cohen imagined a scenario in which threat actors called for acts of violence, while simultaneously calling in bomb threats and swatting hoaxes, disabling law enforcement social media accounts used to communicate with the public and disabling 911 call centers through distributed denial-of-service attacks, all while disseminating their own ideological or political messaging.

Advertisement

“Every time those players were on the field or every time there was a watch party, every time there was any type of FIFA event, that was viewed as potentially an opportunity for a criminal organization, terrorist group or foreign intelligence service to exploit it and to either undermine confidence in the U.S., undermine confidence in FIFA, disrupt the games and bring attention to their cause,” Cohen said. “Because the international media was watching everything that occurred there. So it had to be all hands on deck, every minute of every day.”

Latest Podcasts