top of page

How Cybercrims Cashed in on World Cup Match Streams

20 July 2026

Cyber criminals have reportedly made nearly US$220M from the record number of viewers who streamed matches during the 2026 World Cup.


The Satori Threat Intelligence team at HUMAN Security found more than 12M compromised user accounts on the dark web linked to 10 of the streaming services broadcasting World Cup matches. 


While many World Cup matches – including today’s final - aired free on broadcast television in the US, others required a cable or streaming subscription. That created significant demand for low-cost and illicit ways to watch the tournament.


At the end of the tournament’s Group Stage, cyber criminals released a record 802,000 compromised accounts, generating an estimated $14.8 million in potential single-day black market revenue. 


Lindsay Kaye, VP of threat intelligence at HUMAN Security, told Fortune that fans not wanting to the pay the $30 to $50 for a legitimate streaming account could pay as little as $5 to watch World Cup matches.


Prime Targets 

Broadcasters and streaming platforms are prime targets for cybercriminals seeking to steal user credentials, largely because these businesses move enormous volumes of sensitive data across complex internal and partner ecosystems.  They have been under growing pressure from event organisers and rights managers to protect customer accounts and quickly shut down unauthorised live streams.


One invaluable protection is a Managed File Transfer (MFT) solution.


MFT shuts down common attack paths by replacing ad‑hoc data movement with a single, governed, policy‑driven transfer layer. By enforcing encryption, endpoint verification, MFA, and strict workflow controls, MFT ensures that even if attackers compromise an employee account, they cannot quietly extract subscriber information or authentication data.


Credential theft often succeeds because internal teams rely on risky operational shortcuts - exporting user lists, sharing logs, or transferring authentication data through unsecured scripts and legacy SFTP servers. MFT eliminates these weak points by automating transfers, removing human error, and blocking any data movement that isn’t explicitly approved. This prevents attackers from intercepting or exfiltrating user credentials, and it also protects the systems that store them, such as CRMs, billing platforms, and identity providers, by ensuring all inter‑system data flows are encrypted, authenticated, and auditable.


Quick Reflexes

During times of peak risk - such as major sporting events – when cybercriminals attempt credential scraping or account‑takeover activity, MFT provides the forensic visibility broadcasters and streamers need to respond quickly. Immutable audit logs, real‑time alerts, and detailed transfer metadata allow security teams to detect suspicious behaviour early and contain incidents before they escalate. 


MFT doesn’t just secure files, it provides organisations a hardened, controlled backbone for all sensitive data movement, dramatically reducing the impact of credential theft and strengthening the overall resilience of their digital platforms.


Local MFT Experts

At Generic Systems Australia, we have decades of experience helping Australian and New Zealand organisations take advantage of the security and efficiency that MFT provides.


Let us know if we can help you do the same.

bottom of page