Phishing, API security, Threat Intelligence

Expected cyber threats in Winter Olympics examined

Officials preparing for cyber attacks, scams as Olympics nears

Threat actors are poised to launch credential-harvesting phishing and spoofed websites, as well as harness event system software and API flaws ahead of the Milano-Cortina Winter Olympics next month, according to Infosecurity Magazine.

Ticketing platforms, event websites, and payment systems could also be subjected to distributed denial-of-service intrusions, as well as other attacks involving previously stolen credentials, findings from Palo Alto Networks' Cyber Threats to Milan-Cortina 2026 report showed. Most cyberattacks during the Olympics have been initiated via phishing, with 76% of such cases being associated with business email compromise. Olympics-targeted intrusions have been conducted by ransomware operations, state-sponsored cyberespionage groups, and hacktivist gangs, with Dark Scorpius and Fighting Ursa being notable attackers.

"The biggest risks to large events like the Olympics don't come from new exploits. Instead, they originate from people misusing legitimate apps, identities, and corporate processes," said Cequence Security Chief Information Security Officer Randolph Barr.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds