Every one of twelve fake FIFA domains named in an FBI fraud warning was already sitting in Global Signal Exchange (GSE) data before the World Cup began.

 

The domains were flagged by the FBI in May 2026 as likely spoofing attempts against FIFA infrastructure. The GSE, the non-profit fraud signal clearing house administered by Oxford Information Labs (OXIL), checked its own data against that list and found a complete match.

 

The GSE had in fact been watching the threat build for months. Running seven keyword patterns covering FIFA and World Cup variations, plus the typosquats designed to dodge standard filters, it tracked a steady rise in suspicious signals from September 2025, when ticket sales opened, then a sharp spike in the weeks before kick-off.

 

“The GSE allows us to get sharing right away,” said Raúl Burgos, Security Policy Manager at Meta, speaking at the Global Anti-Scam Summit in Lisbon in June. He noted that agreeing a bilateral data sharing deal with a partner normally takes two years, during which the fraud continues.

 

That speed was exactly what caught the World Cup network. Visa’s Scam Disruption Practice spotted unusual payment and domain activity ahead of the tournament and shared it with Meta through the GSE. Meta mapped and took down a network of fake Facebook pages promoting fraudulent World Cup sites before they reached fans at scale.

 

Other partners at the Lisbon summit reported similar results from the same shared infrastructure. GovTech Singapore has contributed 180,000 high-confidence scam signals tied to real cases and financial losses, and other GSE partners have used them to uncover at least 80,000 further scam enablers. Between October 2025 and February 2026, Meta removed more than 30,000 fraudulent entities from Facebook and Instagram driven solely by GovTech’s signals. Microsoft has ingested more than 20 feeds totalling 160 million signals from the GSE marketplace to strengthen its own automated defences.

 

Fraud does not pause after one win, and neither has the network built to catch it. The GSE has expanded its data architecture from 60 to 95 distinct threat feeds this month. A major portion of the new pipelines comes from an integration with global scambaiting communities, people who deliberately engage fraudsters to disrupt their operations and, in doing so, receive a constant stream of scam screenshots from the public. The GSE now processes those images using AI, pulling out the malicious URL, hosting provider, phone number or crypto wallet buried in each one, and turning them into structured signals members can act on while the scam is still running.

 

The GSE’s world-leading tech team continuously evolve the platform’s technology. Version 2.8.0, released this month, adds CSV export from the GSE’s Compass query tool, custom dashboards for enterprise users, and new data sources including Cifas, Amazon and a dedicated feed of high-integrity domains linked to actively exploited malware. A push API, due to finish testing shortly, will deliver signals to members the moment they are received.

 

Lucien Taylor, Co-Founder and Chief Technology Officer at GSE comments: “It has been a fascinating month, from watching a fraud network get caught out months before the World Cup even began, to hearing from partners in Singapore and Microsoft about the scale of what shared signals can achieve. It’s a real pleasure to hear that kind of feedback but it also tells us there is still a huge job to do, which is exactly why we keep expanding our network and evolving the platform. Fraud does not stand still, and neither can we.