{"id":8919,"date":"2026-02-02T12:00:00","date_gmt":"2026-02-02T10:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=8919"},"modified":"2026-06-14T19:58:09","modified_gmt":"2026-06-14T16:58:09","slug":"a-slippery-slope-beware-of-winter-olympics-scams-and-other-cyberthreats","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2026\/02\/02\/a-slippery-slope-beware-of-winter-olympics-scams-and-other-cyberthreats\/","title":{"rendered":"A slippery slope: Beware of Winter Olympics scams and other cyberthreats"},"content":{"rendered":"<p>Cybercriminals have always been drawn to major sporting events. A combination of global brand awareness and an extensive digital footprint make them a popular option for opportunistic scammers. And events don\u2019t get much bigger or better known than the Olympics.<\/p>\n<p>Cybercriminals have been looking to capitalize on the Olympics for years \u2013 for example, fake ticketing sites <a href=\"https:\/\/www.networkworld.com\/article\/904360\/security-the-olympic-games-were-hacked.html\">proliferated<\/a> way back during the Beijing 2008 Summer Olympics. Since then, even some state-aligned threat actors have got involved, <a href=\"https:\/\/www.welivesecurity.com\/2022\/03\/21\/sandworm-tale-disruption-told-anew\/#:~:text=Olympic%20Destroyer%20impersonating%20Lazarus%20(2018)\">disrupting the Pyeongchang 2018 games<\/a> by using wiper malware that shut down Wi-Fi hotspots and TV feeds, and crippled the back-end servers of the games\u2019 official app. Some <a href=\"https:\/\/www.welivesecurity.com\/en\/business-security\/hacktivism-evolving-bad-news-organizations-everywhere\/\">hacktivists<\/a> are never far away either, spying a perfect opportunity to draw attention to their cause.<\/p>\n<p>But as the world prepares for Milano-Cortina 2026, what are the most common threats that you should look out for? And how can you stay safe?<\/p>\n<h2>What to watch out for<\/h2>\n<p>There are various threats that sports fans should look out for in the days leading up to the event, and the 16 days of the games. They include:<\/p>\n<h3>Phishing attempts<\/h3>\n<p>These are unsolicited emails, texts or social media messages impersonating the official organizers of the games, sponsors or other third parties. Typically, they will <a href=\"https:\/\/www.welivesecurity.com\/en\/scams\/dear-all-what-are-some-common-subject-lines-in-phishing-emails\/\">try to trick you<\/a> into entering your personal and financial information, or clicking on malicious links\/opening attachments which result in silent <a href=\"https:\/\/www.welivesecurity.com\/2020\/12\/23\/7-ways-malware-can-get-your-device\/\">malware installation<\/a>. Examples include:<\/p>\n<ul>\n<li>Free <a href=\"https:\/\/www.welivesecurity.com\/2021\/07\/15\/sports-streaming-events-cybersecurity\/\">streaming links<\/a> that lead to malware delivery or credential theft<\/li>\n<li>Special <a href=\"https:\/\/www.welivesecurity.com\/2018\/06\/06\/fake-fifa-world-cup-themed-lotteries-giveaways\/\">prize draws<\/a> and \u2018last chance offers\u2019 such as tickets to the games<\/li>\n<li>Alerts about cancelled tickets or payment issues<\/li>\n<\/ul>\n<h3>Fake Olympics sites<\/h3>\n<p>Some e-commerce sites purporting to sell official tickets, travel and accommodation may look like the real deal. But they just want your money and\/or card details. Your purchase does not exist. In some cases, scammers might also put fake listings on genuine sites and marketplaces, like <a href=\"https:\/\/www.welivesecurity.com\/2021\/07\/28\/booking-holiday-airbnb-scams\/\">Airbnb<\/a>, eBay and <a href=\"https:\/\/www.welivesecurity.com\/2022\/07\/06\/8-common-facebook-marketplace-scams-how-avoid\/\">Facebook Marketplace<\/a>.<\/p>\n<h3>Free and illegal streaming sites<\/h3>\n<p>Some sites offer sports fans free access to video content from the games. But these sites could also be a hotbed of malware hidden in links, plugins and files. They\u2019re also full of video overlay ads that aren\u2019t often just a minor inconvenience. Instead, many tend to be malicious and when you click on them, you\u2019ll be redirected to a malicious website or unwittingly download malware on your device.<\/p>\n<h3>Fake apps<\/h3>\n<p>Mobile apps masquerading as official Winter Olympics apps may actually contain <a href=\"https:\/\/www.welivesecurity.com\/en\/malware\/theyre-coming-data-infostealers-how-stay-safe\/\">infostealing malware<\/a> or other threats. Such malicious apps are mainly found on various third-party app stores.<\/p>\n<h3>SEO poisoning<\/h3>\n<p>Scammers pay for sponsored ads or use SEO techniques to put their malicious websites at the top of search results. They may trigger drive-by-downloads or try to obtain your personal information.<\/p>\n<h3>Support scams<\/h3>\n<p>If you complain on social media about an issue with your flight\/hotel\/tickets, fraudsters may jump in posing as \u2018official support.\u2019 They don\u2019t really want to help, they just want your personal, financial and booking information. <\/p>\n<h3>Fake employment scams<\/h3>\n<p>Look out for <a href=\"https:\/\/www.welivesecurity.com\/en\/scams\/the-job-hunters-guide-separating-genuine-offers-from-scams\/\">bogus opportunities<\/a> to join the Olympics as a volunteer or paid worker. These are usually designed to either harvest your personal information or trick you into paying an upfront \u2018fee\u2019 to process your details. <\/p>\n<h3>AI-powered scams<\/h3>\n<p>Fraudsters are increasingly using AI-powered tools and services to increase their chances of success. They can generate phishing websites and messages at scale in flawless local languages. And they can also create realistic audio and video designed to influence your decision making. Watch out for deepfake videos of famous athletes seeking to solicit donations for fake charities or \u2018training funds.\u2019<\/p>\n<h3>QR code phishing<\/h3>\n<p>If you\u2019re at the event, look out for <a href=\"https:\/\/www.welivesecurity.com\/2022\/02\/04\/think-before-scan-how-fraudsters-exploit-qr-codes\/\">quishing attempts<\/a>. QR codes posted at events may actually lead to phishing sites and malware downloads. It\u2019s a favored tactic that blends physical and digital threats to <a href=\"https:\/\/www.welivesecurity.com\/2022\/06\/27\/5-ways-cybercriminals-steal-credit-card-details\/\">steal your payment details<\/a> or personal information. It\u2019s particularly effective tactic because it often doesn\u2019t arouse the same level of suspicion among people as, say, phishing URLs. Mobile devices are also often less well protected than laptops and desktops, so there\u2019s more chance of success.<\/p>\n<h3>Public Wi-Fi<\/h3>\n<p>If you\u2019re out and about at the event, beware of fake and lookalike hotspots designed to capture your personal and financial information.<\/p>\n<h2>Staying safe from Winter Olympics scams<\/h2>\n<p>To stay safe online, stick to the official Winter Olympics sites and don\u2019t engage with unsolicited messages and too-goo-to-be-true deals. More specifically:<\/p>\n<ul>\n<li>Only buy tickets from <a href=\"https:\/\/tickets.milanocortina2026.org\/\">https:\/\/tickets.milanocortina2026.org\/<\/a> or <a href=\"https:\/\/hospitality.milanocortina2026.org\/\">https:\/\/hospitality.milanocortina2026.org\/<\/a>. The event organizers have not authorized resale on any third-party ticketing sites.<\/li>\n<li>Stick to the official site, <a href=\"https:\/\/shop.olympics.com\/\">shop.olympics.com<\/a> for merchandise.<\/li>\n<li>Avoid pirated streaming services and only visit sites hosted by the official broadcasters, including NBCUniversal (US), BBC (UK), Warner Bros Discovery (Europe).<\/li>\n<li>Never trust too-good-to-be-true deals in unsolicited messages.<\/li>\n<li>Avoid clicking on links or opening attachments in unsolicited messages, even if they appear to be from legitimate Winter Olympics organizers\/sponsors.<\/li>\n<li>Scrutinize listings for red flags, even if they\u2019re on legitimate sites. Check out reviews, always use the official in-app messaging service and prioritize sellers with \u201cverified\u201d badges or similar.<\/li>\n<li>If you\u2019re going to the event, download the official Olympics app for schedules, maps, and digital tickets.<\/li>\n<li>Avoid public Wi-Fi where possible, or use a VPN if you can. If you have to use a hotspot, don\u2019t log in to high-value accounts, such as your email or online banking.<\/li>\n<li>Avoid scanning QR codes at the event, or ones that turn up in emails.<\/li>\n<li>Install anti-malware on your device from a reputable vendor to mitigate the risk of quishing, smishing and email-based phishing.<\/li>\n<li>Remember that the Olympic games organizers never ask for money to volunteer or work there. Official volunteering sites can be found at <a href=\"https:\/\/team26.milanocortina2026.org\/\">https:\/\/team26.milanocortina2026.org\/<\/a> and paid roles can be found at <a href=\"https:\/\/milanocortina2026.intervieweb.it\/en\/career\">https:\/\/milanocortina2026.intervieweb.it\/en\/career<\/a>.<\/li>\n<\/ul>\n<p>The XXV Winter Olympic Games in Milano-Cortina is set to be a treat for sports fans around the world. But digital scammers will also be paying close attention. Enjoy the fun, and stay safe. <\/p>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/slippery-slope-winter-olympics-scams-cyberthreats\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s snow joke \u2013 sporting events are a big draw for cybercriminals. Make sure you\u2019re not on the losing side by following these best practices.<\/p>\n","protected":false},"author":5,"featured_media":8920,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-8919","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8919"}],"version-history":[{"count":1,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8919\/revisions"}],"predecessor-version":[{"id":9647,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8919\/revisions\/9647"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8920"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8919"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8919"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}