The FIFA World Cup has come and gone — and it confirmed what we expected: threat actors plan around major global events. The Super Bowl and the Olympic Games are still ahead, both landing in California. Nation-state groups and ransomware organizations don't sit out these moments — they prepare for them months in advance. The events are in California. The threat exposure is nationwide.
+
The FIFA World Cup ran June 11 through July 19, 2026, across 16 host cities in the U.S., Mexico, and Canada — and the threat landscape played out largely as predicted. Security researchers tracked over a million leaked credentials tied to the tournament, ransomware activity against hospitality providers, and DDoS attacks that knocked regional ticketing portals offline. Threat actors had infrastructure staged and waiting for months before kickoff, including large volumes of fraudulent domains impersonating FIFA-branded ticketing, merchandise, and job sites.
The takeaway for organizations gearing up for Super Bowl LXI and the LA28 Olympics: this is not a hypothetical risk. It is a documented pattern, and it repeats with every major global event, at greater scale each time.
For SLED organizations and critical infrastructure operators, the stakes are especially high. A successful cyberattack — particularly one targeting identity systems — doesn't just disrupt IT. It disrupts public services, emergency operations, and community trust in real time, in front of a global audience.
It's also important to understand that host-city exposure doesn't stay in the host city. The infrastructure supporting these events — power, telecommunications, financial networks, supply chains, emergency services — is deeply interconnected across state lines. U.S. organizations well outside California should expect to see the same probing activity in the run-up to the next two events.
Preparedness isn't optional. And the window to act is now.


The infrastructure supporting these events — power grids, telecommunications, financial networks, emergency services, supply chains — doesn't stop at California's border. Neither do the threat actors targeting them. During the 2026 FIFA World Cup, threat activity extended well beyond the host cities themselves, echoing what nation-state groups did during the 2024 Paris Olympics. Groups like Volt Typhoon have already established persistence inside U.S. critical infrastructure in preparation for exactly these moments. When the world is watching, threat actors are too — and they're not just watching California.
The Preparedness & Identity Resilience Assessment is a structured evaluation of your organization's readiness for identity-based attacks and operational disruption. Delivered by Tec-Refresh, with Semperis supporting the identity infrastructure components.
Assessment spots are limited. Tec-Refresh is working with organizations across the U.S. through Q3 and Q4 2026. Request yours while capacity is available.
Every assessment maps directly to all five NIST CSF 2.0 functions. You'll know exactly where you stand — and what to do next.
Tec-Refresh and Semperis bring complementary expertise to every engagement — from assessment through remediation and ongoing resilience.
+
Every industry faces a different compliance landscape and threat profile. We built dedicated resources for the organizations most exposed ahead of the U.S. global event window.
Thought leadership and webinars from Tec-Refresh and Semperis — updated as new content is published.
A look back at how the tournament's sprawling vendor ecosystem and months-of-advance phishing infrastructure mirror the exposure every organization carries daily — and what that means heading into Super Bowl LXI.
Read the blog →The Super Bowl, FIFA World Cup, and Olympic Games are coming to California — and so are the threat actors who plan around them.
Read the blog →A joint piece from Tec-Refresh and Semperis on why Active Directory is the primary target for attacks against SLED organizations — and what to do about it.
Read the blog →A practical breakdown of the compliance mandates shaping public-sector cybersecurity — what CMMC 2.0 and CISA KEV directives mean for state agencies, school districts, and municipalities.
Read the blog →Fill out the form below and a Tec-Refresh advisor will be in touch within one business day to discuss your organization's needs and confirm next steps. You'll also get access to our on-demand webinar, Identity Under Siege — Are You Ready for 2028?, now available to watch.
Your information will only be used to follow up on your assessment request. Tec-Refresh does not sell or share contact information.