HUMAN Security said June brought a record release of stolen streaming logins as U.S. authorities seized illegal domains and researchers warned fake apps are being used to target banking and crypto wallet users.
Growing demand to watch the 2026 FIFA World Cup has helped drive a dark-web trade in stolen streaming logins, with HUMAN Security’s Satori Threat Intelligence team identifying more than 12 million compromised user accounts linked to 10 services carrying tournament matches and estimating nearly $220 million in potential black-market sales. The market peaked on June 27, the final day of the group stage, when threat actors released a record 802,000 compromised accounts worth an estimated $14.8 million in potential single-day revenue. HUMAN later said 802,000 compromised streaming accounts were released by threat actors in June 2026 alone, while noting that figure reflects accounts newly released during the period rather than the full stock of stolen credentials circulating in broader World Cup-related markets. The cybercrime activity has drawn law-enforcement attention. The U.S. Department of Justice seized about 400 illegal streaming domains on June 29, and federal authorities warned such sites can expose visitors to malware as well as steal login credentials. HUMAN also flagged thousands of fake FIFA-branded domains and credential-theft operations in early June. Researchers said malicious Android streaming apps linked to the Massiv and Perseus banking trojan families pose a particular risk to digital-asset holders. The apps can request permissions that allow fake login overlays on legitimate banking and crypto wallet apps, creating a route to intercept credentials or transaction activity. That threat is amplified by password reuse across services, which can feed credential-stuffing attacks against exchanges and wallet platforms. Android users face added exposure because sideloaded apps from outside official stores are more common on the platform.