← Back to Feed

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave

July 29, 2026 · Malwarebytes · Severity: HIGH

The EU has begun enforcing key provisions of the AI Act, introducing new transparency rules and bans on high-risk AI applications. As of August 2, AI-generated content—including chatbots, deepfakes, and synthetic media—must be clearly labeled, while certain uses, such as non-consensual intimate imagery and child abuse material, are now prohibited. Violations can result in fines up to €15 million or 3% of global revenue. The EU’s AI Office has also launched complaint and whistleblower tools to report violations, targeting unsafe AI behavior, discrimination, or ignored security risks. The rules aim to curb deceptive AI practices by increasing accountability, though enforcement won’t eliminate abuse entirely. While the transparency measures apply immediately, bans on harmful AI-generated content take full effect in December 2026. The AI Act marks a shift toward stricter oversight, making it harder for companies to deploy manipulative AI systems unchecked within the EU. However, malicious actors may still exploit unregulated tools outside the bloc. The changes prioritize user awareness and legal recourse, though challenges remain in global enforcement.

The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems.

From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails.

The AI Act moved from theory to practice for three big areas:

  • General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
  • Transparency obligations: Transparency rules kick in for interactive systems and AI‑generated content: chatbots must say they are bots, and synthetic audio, images, video and text need to be marked as AI‑generated or manipulated.
  • Banned AI uses: A set of “unacceptable risk” AI uses is now formally prohibited, with enforcement shared between the AI Office, national authorities and the European Data Protection Supervisor for EU institutions.

Note that content that was generated and published before August 2, doesn’t need to be retro‑labelled, but anything published on or after that date falls under the rules, even if it was generated earlier.

From a security perspective, the AI Act’s transparency push is less about banning AI and more about taking away its best camouflage: pretending to be human.

Non‑compliance with transparency obligations can attract fines up to 15 million Euros (17.3 million USD) or 3% of worldwide annual turnover, whichever is higher, which should be significant enough to get large providers’ attention.

To make enforcement more than a paper tiger, the AI Office has launched tools aimed at people who see problems from the inside or as users:

  • Complaint tool: Individuals and organizations can report alleged infringements of the AI Act by providers or deployers of AI systems supervised by the AI Office.
  • Whistleblower tool: People professionally connected to AI providers or deployers get an anonymous channel to flag potential violations that could endanger fundamental rights, health or public trust.
  • Downstream complaints channel: Firms building on top of GPAI models can report suspected breaches by the underlying model providers.

This creates a formal path for reporting systemic issues: think unsafe model behavior, ignored red‑team findings, or deployments that quietly cross legal lines around manipulation or discrimination.

Bans on “nudifiers” and abusive content

The AI Office has introduced explicit prohibitions on AI systems that generate non‑consensual sexually explicit or intimate content (including “nudifier” apps) and child sexual abuse material.

For victims of these abuses, that’s more than a symbolic move. It gives regulators and law enforcement a clear legal basis to go after both providers and deployers of such systems in the EU, rather than trying to squeeze them into older, less specific laws.

These rules will apply from December 2, 2026, with companies given time to bring their systems into compliance or pull them from the EU market.

Regrettably, this will not stop abuse completely. Attackers will still use unlabeled tools and infrastructure outside the EU. But it raises the bar for legitimate services and makes it harder for mainstream platforms to ignore the risks of deceptive AI‑driven features.

The AI Act won’t make AI safe overnight, but it shifts the default from “anything goes” to “you must play by some basic rules if you operate in the EU.” For users, that’s a step toward AI systems you can at least recognize and question, instead of having invisible technology quietly shape our online experience.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Key Takeaways

  • Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup.
  • Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan.
☕ Buy a Coffee