Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do influence operations and cybercrime create outsized…
Threats, Abuse & Incident Response

Why do influence operations and cybercrime create outsized risk for large public events?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

They amplify fear, confusion, and opportunistic fraud at the same time, which can depress attendance and increase successful scams. When hostile actors combine disinformation with phishing, fake sites, and identity theft, the attack surface expands beyond IT into commerce, travel, and public trust. That makes the economic and operational impact much larger than a standalone technical incident.

Why large public events become force multipliers for attackers

Large events create an unusually dense mix of emotion, urgency, and time pressure. That combination lets influence operations shape what people believe while cybercrime exploits what they do next, such as booking travel, buying tickets, checking venue updates, or reacting to a breaking story. The result is not one isolated incident, but a coordinated pressure campaign across trust, attention, and transactions.

At event scale, small manipulations can have outsized effect because many victims share the same triggers at the same time. A rumor can suppress attendance, a fake alert can redirect traffic, and a phishing page can convert confusion into credential theft or payment fraud. The attacker is not only trying to break systems, but to distort behavior in the physical world.

That is why the risk extends beyond the security team. When public confidence becomes part of the attack surface, operational disruption, reputational damage, and financial loss reinforce one another. A well-timed scam or false narrative can lower turnout, overload support channels, and make legitimate communications harder to trust.

How disinformation and fraud reinforce each other

Influence operations work best when they create uncertainty faster than organizers can correct it. If people are unsure which account is official, which ticketing link is real, or whether a venue advisory is legitimate, they are more likely to click first and verify later. That behavior is exactly what cybercriminals exploit with fake registration pages, fraudulent refund offers, and account takeover attempts.

The strongest campaigns usually blend social engineering with technical compromise. Disinformation provides the context, phishing provides the collection point, and stolen credentials or payment details provide the monetization path. In practical terms, this is the same pattern seen in broader SANS Security Resources coverage of incident handling and detection: the adversary benefits when the victim cannot easily distinguish warning from noise.

Public events also attract copycat fraud because the theme itself is marketable. Attackers can clone branding, venue names, speaker names, transport alerts, and sponsor offers with very little effort. If the event is high-profile enough, a counterfeit site or message campaign can look plausible long before defenders have enough visibility to take it down.

Why the blast radius reaches travel, commerce, and public trust

Large events sit at the intersection of multiple industries, so the impact rarely stays inside one network. Ticketing, hotels, airlines, rideshare, payment processors, and local public services all become adjacent targets. When one of those touchpoints is manipulated, the damage can spread through cancellations, chargebacks, support overload, and physical crowd management problems.

This makes the event environment especially attractive for opportunistic crime. A fake venue notice can drive victims to a fraudulent payment portal, while a stolen inbox or social account can be used to send convincing follow-on messages. The same cross-channel pressure is why defenders often track active exploitation patterns through sources such as the CISA cyber threat advisories and the CISA Known Exploited Vulnerabilities Catalog when planning exposure windows around major public moments.

Travel and commerce add another multiplier: once a victim has entered card data, identity details, or login credentials, the harm can extend beyond the event itself. The attacker gains not just one transaction, but a path into broader account abuse, refund fraud, or identity theft. That is why these incidents are best understood as ecosystem attacks rather than single-vector scams.

Risk and Threat Considerations

Large public events create a high-density target environment where trust is already strained, so attackers can win by creating hesitation, not just by stealing data. The main risk is correlated failure: the same false message, fraudulent site, or compromised account can affect thousands of people at once and turn a local security issue into a public disruption.

Failure mechanism: Influence content seeds uncertainty, then phishing, fake services, and identity abuse convert that uncertainty into credential theft, payment fraud, and operational confusion before organizers can correct the narrative.

Impact: Attendance can fall, support and fraud volumes can spike, and reputational harm can outlast the event itself because victims and bystanders remember the confusion as much as the incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingPhishing is a core delivery path for event-related fraud and credential theft.
T1585 — Establish AccountsAttackers often create fake event accounts and personas to amplify disinformation.
Recommendation — Hunt for phishing lures that exploit event urgency and brand impersonation. Track fake personas and lookalike accounts used to distribute event misinformation.
CIS Controls v8CIS-9 — Email and Web Browser ProtectionsEvent scams commonly arrive through email, web links, and lookalike sites.
CIS-17 — Incident Response ManagementLarge events need rapid coordination when misinformation and fraud spread together.
Recommendation — Harden email and browser defenses against impersonation and fraudulent destinations. Prepare event-specific response playbooks for fake alerts, phishing, and takedown requests.
NIST CSF 2.0PR.AT-01 — Identity Management, Authentication, and Access Control AwarenessUsers must recognize official channels before they can resist spoofed event communications.
Recommendation — Train staff and partners to verify event communications before acting on them.

Practitioner Guidance

What to verify: Treat official communication channels as a control surface, not just a marketing function. Before the event opens, verify which domains, social handles, SMS senders, and support numbers are authoritative, and make those references easy to find in one trusted place.

What to prioritize: Prioritize the highest-consequence fraud paths first, usually ticketing, refunds, venue alerts, travel changes, and account recovery. Those are the channels where confusion most quickly becomes financial loss or identity compromise.

Decision rule: If a message asks for credentials, payment, or urgent travel action, assume it will be abused unless the channel and destination were pre-published and independently verified. If the request depends on urgency and secrecy, it deserves extra scrutiny.

Practitioner takeaway: The key judgment is to manage the event as a trust ecosystem, not only as a website or SOC problem. The faster you make legitimate communications recognizable, the less room attackers have to turn fear into fraud.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org