What World Cup Transactions Can Teach Banks about the State of Payments Fraud
By Mike Cook, head of fraud insights at Socure
Simple Subscribe
Subscribe Now!
Every four years, the World Cup becomes one of the biggest customer acquisition moments in sports. In 2026, it also became a live example of how fraud rings exploit digital growth. For sports betting platforms, prediction markets, payments providers and banks, the lesson is clear: When promotions become more valuable, stolen identities become more valuable too.
The tournament acted as a stress test for the gaming and financial services space. With the next events on the horizon (the NFL Kickoff Game, the World Series, Super Bowl LXI, etc.), there are some things the World Cup taught us to curb fraud activity next time.
Key insight: World Cup fraud was not just bonus abuse, which is where criminals exploit new-account bonuses over and over again using synthetic identities, stolen credentials and other measures. It was identity theft at scale. The consumer consequences are now beginning to surface, weeks after the final whistle.
Need to Know:
- More than 90% of attacks in Socure’s World Cup analysis involved real consumer identities, not purely fabricated synthetic personas.
- Socure alone detected and helped stop 451,884 fraud attempts tied to World Cup activity throughout the tournament.
- Fraudsters suppressed traditional linkages by generating unique-looking emails, phone numbers, and identity elements.
- Victims are unlikely to discover this fraud through credit monitoring, because betting and prediction market accounts do not typically appear on credit reports.
- The fraud control question is no longer whether an identity exists. It is whether the person presenting it is the legitimate owner.
Promotions Change the Economics of Stolen Identity
The World Cup is a special event for many reasons. Like the Olympics, the long period between tournaments turns each World Cup into a milestone, showing how quickly technology, consumer behavior and fraud tactics can change. With global attention on the matches, sports betting companies and prediction markets competed for new consumers with deposit bonuses, signup credits, referral rewards, promotional contests and more.
That growth opportunity has a shadow market. Fraudsters follow incentives. When acquisition offers become more valuable, the value of stolen identities rises too. This year’s tournament proved that, with the single operator running the largest promotion absorbing 194,115 fraud attempts — 43% of all the fraud Socure tracked across the entire World Cup.
Why it matters: Promotions are designed to attract legitimate consumers, but they also create a return-on-investment calculation for fraud rings that specialize in account creation, bonus abuse and identity theft.
Before the next major sporting event:
- Map fraud rate changes against specific promotions, not just game dates.
- Track whether fraud continues after legitimate onboarding cools.
- Treat promotional surges as high-risk windows that require dynamic controls–and plan them before the next season, not during it.
Read more: Why Traditional Financial Controls Are Struggling Against Modern Fraud
Identity Theft Changed the Risk Profile
The most important fraud finding from the World Cup was not the attack volume. It was the type of attack.
More than 90% of attacks involved identity theft. These were not simply fraudulent accounts, bonus abuse attempts, or operator losses. In most cases, there was a real person whose identity was being used without their knowledge.
A synthetic identity may create losses for an operator. Identity theft creates losses for both operators and victims. It can lead to account disputes, tax reporting issues, regulatory scrutiny and long-term consequences for consumers.
Key insight: The fraud rings weren’t just trying to prove that an identity exists. In many cases, the identity was real. They were trying to fake ownership.
Before the next major sporting event:
- Separate identity theft risk from synthetic identity risk in reporting.
- Measure consumer-impact exposure, not only fraud loss.
- Prepare support teams now for disputes that may emerge well after account opening.
Read more: Tiny Transactions May Be the Vanguard for Massive Payments Fraud
Gaming-Related Identity Theft can Hide Longer than Credit Fraud
Most consumers understand traditional identity theft. If someone opens a credit card in their name, they may see a credit inquiry, a new account on a credit report, or a notification from a financial institution. But betting and prediction platforms work differently.
Customer accounts typically do not appear as traditional trade lines on a credit report, so victims may not receive the same early warning signals that accompany other forms of financial identity theft. Some discover the fraud only through unusual banking activity, unexpected account notifications, tax documents, or an inquiry months later.
One of the least discussed consequences is tax reporting. If a fraudster opens an account using a victim’s identity and generates reportable winnings, tax documents may be associated with that person’s Social Security number. The victim may then have to prove they did not open the account, did not participate in the activity, and did not receive the proceeds.
Why it matters: This type of identity theft will long outlive the tournament that drives it. Many consumers may not realize the harm that was done until tax season or long after the original promotional campaign has ended.
Before the next major sporting event:
- Review tax-reporting workflows for signs of fraud-created accounts.
- Create clearer dispute pathways for consumers who deny account ownership.
- Coordinate fraud, compliance, customer support and tax operations before the next season.
Read more: Anti-Fraud Practices Your Bank Should Teach Every Small Business Customer
Fraud Rings are Manufacturing Uniqueness
One of the more important developments in World Cup fraud was how attackers adapted to modern identity analytics.
Historically, fraud rings were often exposed because they reused phone numbers, email addresses, physical addresses, devices, or other identity attributes. Today, sophisticated attackers know those patterns are being watched and act accordingly.
Socure observed attackers generating large numbers of seemingly unique identity elements to reduce visibility into coordinated activity. That includes unique email addresses, purchased phone numbers, disposable domains, proxy infrastructure, and identity data that looks clean when reviewed one application at a time.
Three fraud ring archetypes illustrate the shift:
One used real consumer identities with artificially generated contact data. Repeated applications tied to the same victim often showed entirely different phone numbers, exposing automation errors in the fraud ring’s workflow.
Another avoided obvious reuse. Shared phone numbers, emails, and other attributes were rare, making conventional linkage analysis harder.
The last didn’t adapt at all. It leaned on internationally routed infrastructure and repeated the same application sequences. Its approach was less about fraud innovation, and more about volume and repetition.
Key insight: Fraudsters are not just scaling attacks. They are learning how identity systems think, but taking distinct approaches to exploiting vulnerabilities.
Before the next major sporting event:
- Look beyond repeated attributes and monitor suspicious uniqueness at scale.
- Watch for sequential phone ranges, recently created domains, and domain clusters.
- Combine identity, email, phone, device, network, and behavioral signals before making trust decisions.
Read more: A Credit Union’s Five-Point Anti-Fraud Strategy Pays Off
Continuous Identity is the Operating Model Now
The industry response has evolved. Leading operators increasingly recognize that traditional identity verification alone is not enough.
The old question was: Does this identity exist? That is no longer sufficient. Many of the identities in these attacks are real. The harder question is whether the applicant presenting the identity is the rightful owner. That requires a layered view of identity, risk, behavior, device, network and environmental signals.
The tournament exposed helpful insights into how fraud rings operate. Identities are cheap and disposable, which is why fraudsters burn through them constantly. However, the infrastructure behind them has a more lasting footprint.
Domain strategies, phone patterns, routing choices and sequences all linger long enough to leave a trail. Following these breadcrumbs is how you can catch an adversary adapting. No company can see them within its own data, though; it takes a network to uncover isolated red flags as part of a coordinated campaign.
This is where continuous identity matters. Identity is not a moment. It is a lifecycle. Today fraud is industrialized, AI-powered and continuous, so identity can’t remain a point-in-time checkpoint.
Why it matters: Fraud rings exploit the gaps between systems, companies, and lifecycle moments. Static verification creates static blind spots.
Before the next major sporting event:
- Move from point-in-time verification to lifecycle risk monitoring.
- Use layered, networked identity intelligence to evaluate ownership, not just existence.
- Treat identity infrastructure as a growth requirement, not only a fraud control.
Read more: How to Stop Three AI Threats Changing the Face of Identity Fraud — Literally
Fraud Risk Continues to Accelerate
The hidden cost of World Cup fraud isn’t only what operators lost to bonus abuse or fraudulent account creation. It is what happens when real people’s identities become assets for enterprise-scale fraud rings — with consumers left to pay the price.
That is the deeper lesson from 2026.
Fraud follows the money. It adapts to promotions, suppresses linkages, uses global infrastructure, and turns real consumer identities into reusable tools. The next major event is already on the calendar. The businesses that respond best will not be the ones that add more friction everywhere. They will be the ones that build stronger identity intelligence into the moments where trust is created, tested, and renewed.
The goal is not only to protect businesses from fraud. It is to make fraud uneconomical for fraudsters so consumers do not pay the hidden cost.
That is the fight now: protecting growth, protecting trust, and moving trustworthy people through the digital world with assurance.
Read next: Four Ways Banks Can Turn Fraud Into a Loyalty Play
