AI makes phishing undetectable. 344 fake FIFA sites already active. Let’s stop blaming users, the responsibility belongs to the platforms and hosts.
For twenty years, digital security has been based on a comfortable lie: the well-informed user can defend himself. Artificial intelligence has just denied it. More than 344 fake sites perfectly cloning the official World Cup website have already been identified, and no one, not even an expert, knows how to distinguish them from the real one. Continuing to demand vigilance from individuals is no longer prudence: it is an unworthy transfer of responsibility, which places on the victim a failure which falls to the platforms, hosts and brands.
There is one piece of advice we repeat to everyone who connects to the Internet: be vigilant. Check the site address, track down spelling mistakes, be wary of overly urgent emails. This pedagogy has structured our entire culture of digital security. It is now out of date, and millions of supporters will learn it the hard way. The bet on which we bet everything, that of a last human rampart, has just collapsed.
For years, online fraud was betrayed by its imperfections. The fake site was almost perfect, but a pixelated logo, an awkward twist, a crooked URL allowed the trained eye to spot the trap. Our entire collective strategy was based on this premise: the end user, properly educated, would be the last barrier. We have transferred onto his shoulders a responsibility that should never have fallen on him.
This postulate no longer holds, because the imperfection has disappeared. Generative artificial intelligence tools produce clones of official sites indistinguishable from the original, flawless emails, instantly available in all languages, and payment pages with perfect realism. And the issue is not abstract: on these fake sites, you think you are buying a ticket and you are actually putting your card number, your identifiers, sometimes a copy of your identity document, directly into the hands of crooks. The payment disappears, the ticket does not exist, and the data thus collected is then used to empty an account, steal an identity or be resold to other fraudsters. The loophole we were counting on, the trace left by the fraudster, no longer exists. And humans are no longer capable of sorting: a third of Internet users say they are sure they know how to spot an AI-generated scam, but 78% of them open the trapped emails anyway, and the detection rate for falsified content drops to 24.5%. In other words, those who think they are best armed have already fallen. Asking a supporter to distinguish a real ticketing site from a fake is no longer an effort of prudence, it is a test rigged in advance.
Because the fraud is no longer artisanal: it is industrial, and it was premeditated. Behind the 344 clones already active, more than 3,000 other domains linked to the same campaign are waiting, registered and dormant, ready to be activated as the tournament progresses. We are not talking about opportunists who improvise, but about organizations which have prepared their ammunition months in advance. Because behind these campaigns, there is a real economy. Online fraud has structured itself like a clandestine industry, with its ready-to-use phishing kits rented or resold, its shared infrastructures and its marketplaces where stolen data, bank cards, identifiers and identity documents, are sold in bulk. During the previous World Cup, information stolen via fake event applications ended up for sale on dark web markets. And football is just a testing ground. What is happening today will be replayed at each peak of high-stakes transactions: sales, donation campaigns, administrative procedures, waves of recruitment. The question is not if it will happen again, but when.
In this context, hammering home the message of individual vigilance is not only ineffective: it is a headlong rush, and, quite frankly, hypocrisy. This amounts to blaming the victim for a failure that is not theirs. When a person is trapped by a fake site that no expert would have unmasked, opposing them with your lack of caution means protecting those who could have acted and did not do so. The user’s guilt is the symptom of a system which has given up trying to defend itself upstream.
The responsibility has shifted, and it is time to assume it. If the individual can no longer see the difference, the defense must go back to where it is still possible: among those who have the technical means. Impersonated brands must track down their own counterfeiting instead of waiting for complaints from their customers. Hosts and registrars, who allow these clones to flourish on their servers, must stop serving as a shield: in the campaign analyzed, 146 fraudulent domains were sheltered behind the services of the same large infrastructure provider, neutralizing the blockage and slowing down withdrawals accordingly. As for the platforms that collect advertising revenue from these lures, they can no longer hide behind the status of neutral host: they spread the fraud, they profit from it, they must answer for it. As long as these actors are not held accountable, the fight will be fought one victim at a time, which means it will be lost in advance.
We must therefore change our doctrine. For twenty years, we invested heavily in public awareness, betting that well-informed humans would make up for the flaws in the system. This bet is dead. The challenge is no longer to teach people to spot the undetectable, but to build an environment where the undetectable never reaches them. As long as we ask Internet users to maintain a border that they no longer see, we will defend lines that the adversary has already crossed.
Artificial intelligence has not only made fraud more effective: it has made obsolete the defense strategy on which we built everything. Recognizing this is not an admission of weakness. This is the only condition to stop fighting the bad fight, and finally start the good one.