
- 01Recent major-event telemetry is unambiguous. Tokyo 2020 reported on the order of 450 million blocked events per day; Pyeongchang 2018 was hit by the Olympic Destroyer wiper at the opening ceremony; Qatar 2022 saw industrial-scale ticketing, hospitality, and accommodation phishing in the months before kickoff. A World Cup compresses similar pressure into a thirty-day window.
- 02The host nation's attack surface is layered — match operations, stadium OT, critical national infrastructure, government services, payments and hospitality, broadcast and media, sponsors, and the fan-facing apps. Most boards focus on the ticketing site. Threat actors focus on the layers underneath it.
- 03The most damaging incidents in recent major events were OT-adjacent (lighting, scoreboards, broadcast, transit ticketing, stadium access control), not data-breach in the conventional sense. The blast radius is reputational and operational, not regulatory.
- 04Threat actors fall into four buckets: nation-state (geopolitical signaling), hacktivists (visibility), organized crime (ransomware on hospitality + ticketing), and event-specific opportunists (fake-ticket fraud, phishing). The defensive posture has to address all four — they target different layers.
- 05The single highest-leverage investment for a host nation is a unified Major Event Security Operations Center (ME-SOC) that fuses telemetry from FIFA / federation systems, host-city CERT, transport operators, broadcast partners, telecom, and payments — for the duration of the event window. Standing it up two years out is the minimum.
Hosting the FIFA World Cup is the largest planned cybersecurity event a country can sign up for. Match operations, stadium OT, transport, government services, payments, broadcast, hospitality, and millions of incoming travellers all converge into a single, time-boxed attack window. Threat actors know the schedule, know the stadiums, know the broadcast partners, and have months of preparation lead time.
This piece is the systems-level map. It is written for the host-nation CISO, the National CERT lead, the FIFA security liaison, and the head of stadium operations who has to translate it into runbooks. The framing is deliberate: which systems get attacked, by whom, with what intent, and where defenders historically over- or under-invest.
Why major events are different from ordinary enterprise risk.
Three properties make a major event a unique risk container. The window is fixed and short — defenders cannot defer. The visibility is global — a single visible failure is amplified for weeks. And the systems are heterogeneous — IT, OT, broadcast, payments, and government services are forced into the same operational tempo. A host nation does not get to handle these in isolation. The attacker's leverage comes from the seams between them.
The historical baseline — what the last decade of major events teaches us
Pattern recognition matters. The last four major sporting events publicly reported attack volumes and incident types that reveal where the pressure actually lands. Below is the practitioner's summary, normalized for what it means for a host nation today.
Read the table for the seams, not the headlines.
The headline incidents (Olympic Destroyer at Pyeongchang) get the press. The pattern that matters is the steady volume of fraud, phishing, hospitality compromise, and DDoS that runs for months before kickoff and continues for weeks after. A host nation that prepares only for the spectacular incident under-invests in the slow-burn losses.
/MAJOR_EVENTS · CYBER_BASELINE
| Event | Reported pressure | Most consequential incident type |
|---|---|---|
| Pyeongchang 2018 | Olympic Destroyer wiper detonated at opening ceremony | Wiper / OT-adjacent — broadcast, Wi-Fi, ticket-printing offline |
| Tokyo 2020 (held 2021) | ~450M blocked events / day reported by organizers | Phishing, credential stuffing, DDoS — sustained, multi-vector |
| Qatar 2022 World Cup | Industrial-scale ticketing + accommodation phishing pre-event | Fan-facing fraud, hospitality compromise, fake-app ecosystem |
| Paris 2024 | Government + transport pre-event probing, IT incident at venues during event | Transport, ticketing, government services — pre-event reconnaissance |
| UEFA Euro 2024 | Surge in ticketing fraud + payment scams; DDoS on federation sites | Fraud, DDoS, sponsor-impersonation phishing |
The eight-layer attack surface — what the host nation actually has to defend
Below is the inventory we run with national-event programs. Each layer has a distinct owner, a distinct telemetry source, and a distinct adversary mix. The mistake is treating any one of them as 'the' problem; the value comes from defending them as a system.
/WORLD_CUP_HOST · ATTACK_SURFACE_LAYERS
| Layer | Representative systems | Likely adversary | Worst-case impact |
|---|---|---|---|
| 1. Match operations | VAR, goal-line tech, match-data feeds, federation back-office | Nation-state, hacktivist | On-field decision integrity, broadcast credibility |
| 2. Stadium OT / venue | Access control, turnstiles, lighting, scoreboards, HVAC, emergency PA | Nation-state, hacktivist | Public safety incident, evacuation, broadcast disruption |
| 3. Ticketing + access | Ticket platform, mobile credential, fan ID, gate scanners | Organized crime, opportunists | Fraud at scale, denial-of-entry, gate chaos |
| 4. Broadcast + media | Production, satellite uplink, OB trucks, CDN, host broadcaster IT | Nation-state, hacktivist | On-air disruption, content manipulation, reputational |
| 5. National critical infrastructure | Power, water, telecom, rail, air traffic, road tolling | Nation-state | Cascading public-safety + economic damage |
| 6. Government + border | E-visa, border control, police, health-system surge capacity | Nation-state, hacktivist | Border throughput collapse, sovereignty signaling |
| 7. Payments + hospitality | POS at venues, hotel PMS, FX, ATM networks, sponsor commerce | Organized crime | Ransomware on hospitality, payment outage, card fraud |
| 8. Fan experience | Official app, public Wi-Fi, fan zone displays, social media accounts | Opportunists, organized crime, hacktivists | Fan-app account takeover, fake-ticket fraud, disinformation |
Layer 1–2 — Match operations and stadium OT, where the worst-case lives
Match operations and the stadium operational technology stack are the layers most likely to produce an irrecoverable incident — by which we mean an incident the public sees in real time, that cannot be retrofitted with a press statement, and that follows the host nation for years. Pyeongchang 2018 set the template: a wiper deployed against the IT/OT seam at the opening ceremony took down ticket-printing, broadcast Wi-Fi, and fan apps in front of a global audience.
These systems are typically vendor-supplied, vendor-maintained, and deployed late. They are also the layer where conventional enterprise EDR, SIEM, and identity controls have the lowest coverage, because the assets are not joined to the corporate domain and are often air-gapped — until they aren't.
- 01VAR + goal-line technology — match-decision integrity. Compromise here is on-field, on-camera, and irreversible during the match.
- 02Stadium access control + turnstiles — denial-of-entry is the most common 'soft' attack. A 30-minute outage at gates 30 minutes before kickoff produces a global incident.
- 03Lighting, PA, scoreboards — broadcast-visible. These are the highest-leverage hacktivist target: low effort to disrupt, maximum visibility.
- 04HVAC + life-safety systems — public-safety implications. Threat actors who reach this layer are at the upper end of the threat spectrum, and the response posture must reflect that.
- 05Match-data feeds + federation back-office — feeds underwriting broadcast graphics, betting, and sponsor activations. A poisoned feed has commercial and legal consequences across the ecosystem.
The OT–IT seam is the highest-priority pre-event audit.
The single highest-yield audit a host program runs in the 18 months before the event is the inventory of every IT-to-OT crossing in every venue: jump hosts, vendor remote-access tools, shared file servers used by stadium operations, building-management VPN endpoints. Most venues have more crossings than the venue operator believes. Each one is an attack path. Catalog them, gate them with strict access control, monitor them as a tier-0 asset class.
Layer 3 — Ticketing, fan ID, and access credentials
Ticketing is the layer the public assumes is the main target. It is not the most damaging, but it is the noisiest and the most consistently attacked. Three failure modes recur across recent events: (1) credential stuffing and account takeover against fan accounts, (2) bot-driven scalping that bleeds into the secondary market and feeds the fake-ticket fraud ecosystem, and (3) gate-day denial-of-entry from compromised credential infrastructure.
The control set is well-understood — strong identity proofing, device-bound credentials for transferable tickets, bot management at the application edge, and a rehearsed gate-day fallback for credential lookup. The execution discipline is the variable.
Layer 4 — Broadcast and media
Broadcast is uniquely exposed because it concentrates the highest-visibility output of the event into a small number of vendors and a fixed geography. The attack surface includes the host broadcaster's production environment, the international broadcast center, satellite uplinks, the encoding chain, the streaming CDN, and the partner-broadcaster onward delivery. A successful attack at any link in this chain is broadcast-visible within seconds.
The pattern that recurs in our incident response work: broadcast IT is patched and reasonably segmented; the production OT (cameras, replay, graphics, audio) is treated as appliance estate and is the soft target. Broadcast operators that have invested in production-network segmentation, vendor-access governance, and pre-event red-team exercises have markedly fewer incidents.
Layer 5 — National critical infrastructure, the nation-state target
Power, telecom, rail, air traffic, and road tolling form the layer most likely to be probed by sophisticated adversaries during the event window. The intent is rarely to take the country offline mid-tournament — that would be war-adjacent. The intent is signaling: a brief, deniable, broadcast-visible disruption that demonstrates capability without escalating.
Defending this layer is not the host program's job alone; it is the National CERT, the sector regulators, and the operators themselves. The host program's job is to ensure that fusion happens — that telemetry flows from these operators into a unified situational-awareness picture for the duration of the event window. Without that fusion, attribution is slow and response is fragmented at the worst possible moment.
What 'event-period telemetry fusion' looks like in practice.
A Major Event SOC runs side-by-side liaison desks for: National CERT, host-city CERT, FIFA / federation security, host broadcaster, telecom (one desk per major operator), payments switch operator, transport operators (rail + air), and the lead venue-operations contractor. Each desk has read access to a shared situational picture. Each desk is staffed 24/7 for the event window plus two weeks before and after. Decisions cross desks in minutes, not days.
Layer 6 — Government services and border systems
E-visa platforms, biometric border control, police computer-aided dispatch, and the surge-capacity health system all see unprecedented load during a World Cup. Two threat patterns dominate: pre-event DDoS and credential-stuffing on visa portals (organized fraud + hacktivist signaling), and event-period denial of service on border control (cascading travel disruption with high public visibility).
The control investment that pays back: aggressive load testing of every public-facing service at three to five times projected peak, application-layer DDoS protection at the network edge, and an explicit fallback procedure for biometric border control degradation that does not collapse the airport throughput.
Layer 7 — Payments and hospitality, the organized-crime target
Hotels, payment terminals, and the official-sponsor commerce stack are the layer organized crime cares about. Ransomware against major hotel groups in a host city peaks in the 90 days before the event, when negotiation leverage is maximal — operators cannot afford to lose property-management systems with overbooked properties on the calendar. Card-not-present fraud against ticketing and merchandise rises with traveller volume. POS skimmer campaigns against tourist-corridor retail follow the schedule.
Hospitality and payments operators that have not run a tabletop with their cyber-insurance carrier and their forensics retainer in the 12 months before the event are operating at materially elevated risk. The countermeasure is procedural, not technical, and it is cheap.
Layer 8 — The fan experience, where opportunists harvest scale
The fan-facing layer is where the noise lives — and where the slow-burn losses accumulate. Fake-ticket marketplaces, look-alike accommodation booking sites, fraudulent fan-app clones, social-media account takeovers of player and federation handles, public-Wi-Fi credential harvesting in fan zones. None of these are sophisticated; all of them are at scale.
The defensive posture is brand protection (takedown velocity for look-alike domains and fake apps), proactive consumer comms (explicit, simple guidance on official channels for tickets / accommodation / apps), and partnership with the major platforms for accelerated takedown during the event window.
Threat actor mix — who attacks which layer, and why
Different actors target different layers because they want different outcomes. Defenders that map their controls to a single threat model under-invest somewhere. Below is the mapping we use in host-nation tabletops.
/ACTOR_X_LAYER · THREAT_MAPPING
| Actor | Primary motive | Layers targeted | Tradecraft signature |
|---|---|---|---|
| Nation-state | Geopolitical signaling, sovereign capability demonstration | Match ops, stadium OT, broadcast, CNI, government | Long lead-time access, low-noise, broadcast-timed activation |
| Hacktivist | Visibility, ideological message | Stadium OT (lighting, scoreboards), federation web, social media | Opportunistic, broadcast-timed, defacement and DDoS |
| Organized crime | Yield per attacker-hour | Hospitality (ransomware), ticketing fraud, payments, sponsor commerce | Industrial scale, pre-event peak, retail-style negotiation |
| Event-period opportunists | Fast cash from fans + travellers | Fan apps, fake tickets, look-alike domains, public Wi-Fi | Volume-driven, low sophistication, brand impersonation |
The Major Event Security Operations Center (ME-SOC) — the keystone control
If a host nation makes one structural investment, it is a unified, time-boxed Major Event SOC. The function is not to replace existing SOCs at the National CERT, the federation, the broadcaster, or the operators — it is to fuse them into a single situational picture for the duration of the event window. Standing it up two years out is the minimum; eighteen months out is the realistic timeline for a first-time host.
- 01Months -24 to -18 — Charter and governance signed across federation, host government, telecoms, payments, transport, and broadcast. Authority to declare 'event posture' and trigger pre-agreed escalations is established in writing.
- 02Months -18 to -12 — Telemetry inventory and integration. Identify every source feeding the ME-SOC; agree on data-sharing classification; build the fusion platform; recruit core staff.
- 03Months -12 to -6 — Tabletop programme. Run quarterly exercises that walk through the eight-layer attack surface, escalating in scope each quarter. Close gaps revealed by each tabletop.
- 04Months -6 to -1 — Live-fire purple team across venues, broadcast, ticketing, payments. Validate the cross-desk decision flow under realistic timing pressure. Lock in playbooks.
- 05Event window — 24/7 staffing, fixed cadence briefings, formal posture changes between 'preparation', 'match-day', and 'recovery'. After-action review begins on the closing whistle and runs through month +3.
The ME-SOC test that proves it is real (run it eighteen months out).
Pick a Tuesday. At 14:00, simulate a coordinated incident: a credential-stuffing surge on the official ticketing platform, a DDoS spike on a federation domain, a suspicious access-control reboot at one venue, and an anomalous outbound transfer from a sponsor partner. Time how long it takes from the first detection to the moment a single unified picture is on the screens of all eight liaison desks, and the moment a coordinated response is in flight across federation, broadcaster, ticketing, telecom, and the venue operator. If that elapsed time is more than 30 minutes, the ME-SOC is not yet operational — and you have eighteen months to fix it.
- ▸Trigger the simulation with no advance warning to liaison desks
- ▸Measure: detection-to-fusion time and fusion-to-coordinated-response time
- ▸Capture every cross-desk handoff that exceeded five minutes
- ▸Treat each excess as a runbook or integration gap to close before the next drill
- ▸Re-run the same simulation each quarter; expect the time to halve over four cycles
The 24-month host-nation programme — sequencing what matters
The biggest implementation mistake in host-nation cyber programmes is treating the timeline as flexible. It is not — the kickoff date is fixed. Below is the sequencing we use with national programmes; specifics shift, the order of operations does not.
- 01M-24 — Establish governance, charter the ME-SOC, formally identify the eight layers and assign accountable owners per layer.
- 02M-18 — Complete the OT-IT seam audit at every venue. Begin the broadcast production-network segmentation programme. Stand up the National CERT — host-program liaison.
- 03M-12 — Telemetry fusion live in test. First end-to-end tabletop across all eight layers. Brand-protection programme for fan-facing assets begins (domain monitoring, app store monitoring, social-media liaison).
- 04M-9 — Hospitality and payments tabletop programme begins, with insurance and forensics-retainer involvement. Border systems load tested at 5x projected peak.
- 05M-6 — Live-fire purple team in venues. Stadium OT runbooks tested under realistic match-day timing. Cross-desk decision flow drilled monthly.
- 06M-3 — Pre-event posture lockdown: change-freeze on all event-critical systems, vendor-access reauthorization, final fallback runbook walk-through.
- 07M-0 — Event window. ME-SOC at full staffing. Daily briefings. Formal posture transitions match by match.
- 08M+1 to M+3 — After-action review across every layer. Findings folded back into the National CERT operating model so the investment outlives the event.
What a host nation should not do — three common failure modes
- 01Treat the official ticketing site as the headline risk. It is the noisiest layer, not the most damaging. Stadium OT, broadcast, and CNI carry the irrecoverable downside.
- 02Stand up a Major Event SOC six months out. The integration debt cannot be paid down on that timeline. Eighteen months is the minimum; twenty-four is realistic.
- 03Defer the OT-IT seam audit because venues are not yet built. Conduct it on a per-venue basis as each venue handover happens, not as one programme at the end. Late discovery is the single most common cause of programme overrun.
Closing — the host nation's single defensible position
A World Cup is the most concentrated cyber risk a country plans for. The defensible position is not 'we will not be attacked' — every host is, continuously, across all eight layers. The defensible position is 'we will see it, we will coordinate across the layers in minutes, we will absorb it without a broadcast-visible failure, and we will leave the country with a stronger National CERT than we started with.' The programme that gets you there starts twenty-four months out, sequences the eight layers in the right order, and treats the Major Event SOC as the keystone control. Everything else is a feature.


