They amplify fear, confusion, and opportunistic fraud at the same time, which can depress attendance and increase successful scams. When hostile actors combine disinformation with phishing, fake sites, and identity theft, the attack surface expands beyond IT into commerce, travel, and public trust. That makes the economic and operational impact much larger than a standalone technical incident.
Why large public events become force multipliers for attackers
Large events create an unusually dense mix of emotion, urgency, and time pressure. That combination lets influence operations shape what people believe while cybercrime exploits what they do next, such as booking travel, buying tickets, checking venue updates, or reacting to a breaking story. The result is not one isolated incident, but a coordinated pressure campaign across trust, attention, and transactions.
At event scale, small manipulations can have outsized effect because many victims share the same triggers at the same time. A rumor can suppress attendance, a fake alert can redirect traffic, and a phishing page can convert confusion into credential theft or payment fraud. The attacker is not only trying to break systems, but to distort behavior in the physical world.
That is why the risk extends beyond the security team. When public confidence becomes part of the attack surface, operational disruption, reputational damage, and financial loss reinforce one another. A well-timed scam or false narrative can lower turnout, overload support channels, and make legitimate communications harder to trust.
How disinformation and fraud reinforce each other
Influence operations work best when they create uncertainty faster than organizers can correct it. If people are unsure which account is official, which ticketing link is real, or whether a venue advisory is legitimate, they are more likely to click first and verify later. That behavior is exactly what cybercriminals exploit with fake registration pages, fraudulent refund offers, and account takeover attempts.
The strongest campaigns usually blend social engineering with technical compromise. Disinformation provides the context, phishing provides the collection point, and stolen credentials or payment details provide the monetization path. In practical terms, this is the same pattern seen in broader SANS Security Resources coverage of incident handling and detection: the adversary benefits when the victim cannot easily distinguish warning from noise.
Public events also attract copycat fraud because the theme itself is marketable. Attackers can clone branding, venue names, speaker names, transport alerts, and sponsor offers with very little effort. If the event is high-profile enough, a counterfeit site or message campaign can look plausible long before defenders have enough visibility to take it down.
Why the blast radius reaches travel, commerce, and public trust
Large events sit at the intersection of multiple industries, so the impact rarely stays inside one network. Ticketing, hotels, airlines, rideshare, payment processors, and local public services all become adjacent targets. When one of those touchpoints is manipulated, the damage can spread through cancellations, chargebacks, support overload, and physical crowd management problems.
This makes the event environment especially attractive for opportunistic crime. A fake venue notice can drive victims to a fraudulent payment portal, while a stolen inbox or social account can be used to send convincing follow-on messages. The same cross-channel pressure is why defenders often track active exploitation patterns through sources such as the CISA cyber threat advisories and the CISA Known Exploited Vulnerabilities Catalog when planning exposure windows around major public moments.
Travel and commerce add another multiplier: once a victim has entered card data, identity details, or login credentials, the harm can extend beyond the event itself. The attacker gains not just one transaction, but a path into broader account abuse, refund fraud, or identity theft. That is why these incidents are best understood as ecosystem attacks rather than single-vector scams.
Risk and Threat Considerations
Large public events create a high-density target environment where trust is already strained, so attackers can win by creating hesitation, not just by stealing data. The main risk is correlated failure: the same false message, fraudulent site, or compromised account can affect thousands of people at once and turn a local security issue into a public disruption.
Failure mechanism: Influence content seeds uncertainty, then phishing, fake services, and identity abuse convert that uncertainty into credential theft, payment fraud, and operational confusion before organizers can correct the narrative.
Impact: Attendance can fall, support and fraud volumes can spike, and reputational harm can outlast the event itself because victims and bystanders remember the confusion as much as the incident.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Phishing is a core delivery path for event-related fraud and credential theft. |
| T1585 — Establish Accounts | Attackers often create fake event accounts and personas to amplify disinformation. | |
| Recommendation — Hunt for phishing lures that exploit event urgency and brand impersonation. Track fake personas and lookalike accounts used to distribute event misinformation. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | Event scams commonly arrive through email, web links, and lookalike sites. |
| CIS-17 — Incident Response Management | Large events need rapid coordination when misinformation and fraud spread together. | |
| Recommendation — Harden email and browser defenses against impersonation and fraudulent destinations. Prepare event-specific response playbooks for fake alerts, phishing, and takedown requests. | ||
| NIST CSF 2.0 | PR.AT-01 — Identity Management, Authentication, and Access Control Awareness | Users must recognize official channels before they can resist spoofed event communications. |
| Recommendation — Train staff and partners to verify event communications before acting on them. | ||
Practitioner Guidance
What to verify: Treat official communication channels as a control surface, not just a marketing function. Before the event opens, verify which domains, social handles, SMS senders, and support numbers are authoritative, and make those references easy to find in one trusted place.
What to prioritize: Prioritize the highest-consequence fraud paths first, usually ticketing, refunds, venue alerts, travel changes, and account recovery. Those are the channels where confusion most quickly becomes financial loss or identity compromise.
Decision rule: If a message asks for credentials, payment, or urgent travel action, assume it will be abused unless the channel and destination were pre-published and independently verified. If the request depends on urgency and secrecy, it deserves extra scrutiny.
Practitioner takeaway: The key judgment is to manage the event as a trust ecosystem, not only as a website or SOC problem. The faster you make legitimate communications recognizable, the less room attackers have to turn fear into fraud.
Related resources from NHI Mgmt Group
- Why do coordinated attacks on transportation and public services create outsized risk for large international events?
- Why do non-human identities create more risk than many human accounts?
- Why do non-human identities create more remediation risk than many human accounts?
- Why can a single SaaS app create such a large blast radius?