TLDR
- A new report from fraud prevention platform SEON found fraud activity rose across sportsbooks during the 2026 World Cup.
- Dormant betting accounts were the top entry point for fraudsters, with activity up 83% compared to before the tournament.
- Average blocked fraudulent withdrawals rose from $202 before the World Cup to $436 during it.
- Stolen credential logins jumped 115% in Europe during match-day traffic spikes.
- Experts warn similar fraud patterns could return when NFL and college football seasons begin.
The 2026 World Cup ended with Spain lifting the trophy in July. But according to a new report from fraud prevention company SEON, the tournament also became a target for fraudsters.
SEON studies gambling activity across global markets. Its report looked at fraud attempts before, during, and after the 48-team tournament.
George Pace, lead product marketing manager for betting and gaming at SEON, called it the “World Cup of fraud.” He said large sportsbook promotions during major events attract criminals looking for weak spots.
Dormant Accounts Became a Target
The report found that dormant betting accounts were the main way fraudsters got in. These accounts had already passed identity checks earlier, so operators trusted them more.
Activity from these accounts rose 83% compared to before the World Cup. In Latin America, that number reached 118%.
Pace said many operators assume returning accounts are safe because they were verified months earlier. Fraudsters buy or steal these accounts, then use them to claim retention bonuses, which are often larger than sign-up bonuses.
Blocked fraudulent withdrawals also grew during the tournament. The average blocked amount rose from $202 before the World Cup to $436 during it. SEON said this shows fraudsters focused on fewer, larger transactions instead of many small ones.
Stolen login activity also spiked. Europe saw a 115% rise in logins using stolen credentials during match-day traffic surges.
How Sportsbooks Responded
The report also found a 16% drop in block rates during the tournament. Pace said this wasn’t only because more fraud got through.
Operators were less willing to block suspicious accounts outright, worried that blocked users would simply sign up with a competitor instead. Instead, some used what SEON calls “dynamic friction,” watching risky accounts closely and blocking withdrawals only once a payout was requested.
Pace said fraud in this context often means bonus abuse rather than a traditional crime. Multi-accounting and synthetic identities were also used to farm welcome and retention bonuses. He said the activity becomes a crime when accounts are used to move money and hide its origin, which SEON also observed during the tournament.
Matthew Wein, who writes the Secure Stakes newsletter, said the report shows progress in fraud detection but not an end to the problem. He said artificial intelligence tools now let attackers scale their efforts against more victims at low cost.
Wein also pointed to a pattern in the report: operators loosened checks at times to reduce friction for new users. He said the same approach could happen again for the start of football season in the United States, which begins September 9, and could lead to more fraud incidents.
He said bettors should be cautious with dormant accounts tied to saved card or banking details, avoid reused passwords, and understand what data they share when signing up.
SEON’s report reviewed data from roughly 340 betting and gaming operators worldwide, comparing pre-tournament predictions with what happened during the event itself.
