Large events concentrate attention, data, money, and political symbolism in one place, which creates multiple motives for attackers. State-linked actors may seek influence or disruption, while opportunistic criminals chase profit through phishing, fake sites, and scams. The result is a blended threat landscape where cybersecurity teams must defend against both targeted campaigns and mass opportunistic abuse.
Why the same event can trigger espionage, disruption, and fraud at once
Large sporting events compress high-value targets into a short window: visitors, broadcasters, sponsors, payments, credentials, logistics, and public attention. That concentration creates multiple attack incentives at the same time, so state-linked actors may pursue influence or disruption while criminals focus on fraud, impersonation, and account abuse. The overlap is not unusual, it is a feature of the event model.
Because the event is temporary but the supporting systems are not, attackers can choose the lane that best fits their objective. Some aim at information collection and access, some at operational disruption, and some at monetising the surge in traffic and trust. The threat mix broadens further when the event becomes a media focal point, because false urgency increases the success rate of scams and phishing.
What makes the target set so attractive to different attackers?
Different attacker types value different assets, and major events expose all of them at once. Espionage actors look for communications, schedules, delegations, or policy insights. Disruptive actors may want to interrupt services, degrade confidence, or create symbolic embarrassment. Fraud actors prefer payment flows, ticketing systems, fake merchandise stores, social-media impersonation, and credential harvesting.
The scale matters because the same brand and same moment can support many parallel campaigns. A fake ticketing page can be profitable even if the broader operation is unsophisticated, while a targeted intrusion into a sponsor, vendor, or media partner can be valuable for espionage or disruption. This is why the same event can host both low-end mass fraud and high-end strategic activity.
Operationally, the event ecosystem is usually larger than the host organisation. Contractors, transport providers, hospitality platforms, broadcasters, volunteers, and local authorities all create additional trust boundaries. That expands the attack surface, especially where identity and access are shared across organisations or where third-party systems are connected quickly for the duration of the event.
Why fraud, phishing, and disruption blend together during the event window
Fraud campaigns often ride the same public attention that makes disruption politically or operationally attractive. Attackers exploit urgency, legitimacy cues, and audience scale to imitate organisers, ticket vendors, sponsors, or support desks. The same fraudulent infrastructure can also be used to collect credentials, seed malware, or redirect victims into broader compromise paths.
Disruption does not need to be technically sophisticated to be effective. A flood of bogus support requests, fake alerts, account lockouts, or service outages can consume incident response capacity and distract defenders from a quieter espionage campaign. In practice, a noisy fraud wave can serve as cover for more targeted intrusion attempts.
That blending is why event security teams have to treat user trust, public messaging, and technical control as one problem. Clear official channels, verified domains, and disciplined authentication reduce the chance that a scam becomes an access path. For baseline control expectations, teams often map event operations to NIST Cybersecurity Framework 2.0 and use identity-focused controls from NIST SP 800-63 Digital Identity Guidelines for phishing-resistant authentication.
Risk and Threat Considerations
These campaigns become more dangerous when defenders assume the threat is only one thing, such as fraud or denial of service. In reality, large events create a layered risk model where one weak link can support several attack objectives, from credential theft to operational embarrassment to financial loss.
Failure mechanism: Attackers exploit the event’s trust surge, broad third-party ecosystem, and compressed timelines to move from public deception into access, disruption, or collection. A fake message, compromised vendor, or overloaded support process can become the first step in a larger intrusion or fraud chain.
Impact: The result can include stolen credentials, fraudulent payments, service degradation, reputational damage, and intelligence collection against high-value participants. The same compromise pattern can affect many victims quickly because the event amplifies reach and urgency.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC-01 — Supply Chain Risk Management | Event ecosystems depend on many vendors and partners, making third-party trust central to the threat mix. |
| Recommendation — Map event suppliers and partners, then enforce controls for external dependency and trust-path risk. | ||
| NIST SP 800-63 | V10 — OAuth and OIDC | Large-event phishing and account takeover often hinge on weak or spoofable login and federation flows. |
| Recommendation — Require phishing-resistant authentication for public-facing and partner-access portals. | ||
| MITRE ATT&CK | T1566 — Phishing | Fraud and credential theft campaigns commonly use event-themed lures and impersonation. |
| Recommendation — Hunt for event-themed phishing lures and block lookalike domains early. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Temporary event access across vendors and volunteers raises privilege spillover risk. |
| Recommendation — Scope every event account to the minimum permissions and expire access promptly. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Ticketing, support, and partner APIs are attractive for fraud when authentication is weak or reused. |
| Recommendation — Protect event-facing APIs with strong authentication and session protections. | ||
Practitioner Guidance
What to prioritise: Treat verified public communications, ticketing, payment, and volunteer or contractor access as the highest-risk pathways because those channels are the most likely to be abused by both criminals and more targeted actors. The most useful early question is not “is this attack sophisticated?” but “can this path create real access, money movement, or public trust loss?”
What to verify: Confirm that event domains, help channels, and third-party support workflows have strong authentication, clear ownership, and rapid takedown capability for impersonation. Where many partners are involved, insist on short-lived access, tight scope, and explicit revocation dates so the event does not leave behind durable exposure.
Practitioner takeaway: Major events are not one threat problem, they are a concentration problem, so the best defence is to reduce how easily public trust can be converted into access, payments, or operational disruption.
Related resources from NHI Mgmt Group
- Why do large digital banking ecosystems create both growth and fraud risk at the same time?
- How should security teams prepare for phishing and fraud campaigns around major sporting events with heavy ticketing and travel activity?
- Why can a single SaaS app create such a large blast radius?
- Why do AI-powered fraud campaigns weaken one-time verification?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org