Ghost Stadium: usavisaworldcup.com
FIFA 2026 Visa Fraud & Passport Harvesting
A Lovable.app-built fraudulent visa portal targeting FIFA World Cup 2026 attendees remains live and actively harvesting passport data and payments 31 days after the tournament ended. Backend is Supabase (xknhixtjnhiafccbfica) — HTTP 401/500 confirms the project is running. Part of the Ghost Stadium cluster: 4,300+ fraudulent domains, 47,000+ victims, Chinese-speaking operator.
usavisaworldcup.com presents as an official-looking "USA World Cup 2026 Visa Service — Apply Now" portal. As of August 19, 2026 — 31 days after the FIFA World Cup final (July 19, 2026) — the site returns HTTP 200 and is actively serving victims.
The FIFA World Cup 2026 ran June 11 to July 19 in the United States, Canada, and Mexico. The tournament is over. No legitimate visa application for this event has any meaning. The site's continued operation is deliberate: it targets fans who followed up late, missed the tournament news, or are researching past travel requirements. Every new form submission in August 2026 is a fresh victim.
The site was registered April 12, 2026, during the final tournament preparation phase — timed to catch peak demand. Registrar is Spaceship Inc. (IANA ID 3862). No SPF records and no MX records: the domain has zero legitimate email infrastructure, a consistent pattern across all Ghost Stadium phishing properties.
The operator built this fraud site using Lovable.app, a commercial AI-powered frontend builder. This is an unusual OSINT finding: the OG and Twitter card meta tags in the page source expose the original Lovable.app project ID, the Cloudflare R2 asset bucket, and the internal preview URL — all of which were generated when the operator used the platform and failed to sanitize the output before deploying to their custom domain.
The original Lovable deployment returns HTTP 404 — the operator deleted or unpublished the Lovable source. However, the custom domain usavisaworldcup.com is still routing to Lovable's Cloudflare infrastructure, meaning the site remains live through their CDN even though the source project is gone. This is a common mistake when operators move from an AI builder to a custom domain without understanding the underlying hosting relationship.
Flock analytics (/~flock.js) returns HTTP 200 from a Munich Cloudflare edge (MUC) — visitor tracking is actively running, meaning the operator is monitoring traffic and victim behavior in real time.
Analysis of the JavaScript bundle (/assets/index-yRY5RnWi.js, 796KB) extracted the Supabase project endpoint hardcoded in the React application. The backend at xknhixtjnhiafccbfica.supabase.co is the repository for all victim-submitted data.
Passive HTTP probes confirm the backend is alive. The REST API returns HTTP 401 with error code UNAUTHORIZED_MISSING_API_KEY — the database tables are locked behind an API key, but the project itself is fully operational. The Edge Function at /functions/v1/chat returns HTTP 500, confirming it is deployed and responding.
The data fields extracted from JS bundle string analysis reveal exactly what the form collects: email, firstName, lastName, country, purpose, Passport data, and applicationId. The presence of applicationId and newStatus fields confirms the operator maintains a victim tracking queue, processing each submission as a case.
This constitutes a GDPR Article 5 violation: personal data (including passport details) is being collected from EU residents with no lawful basis, no privacy notice, and no data controller registration. Supabase AB (Swedish data processor) is potentially implicated as a processor of unlawfully collected personal data.
Ghost Stadium is a Chinese-speaking, financially motivated threat actor first documented by Group-IB in November 2025. The operator runs a custom React-based phishing kit supporting 11 languages, enabling simultaneous targeting of fans from across Europe, Asia, and the Americas. Their infrastructure uses Cloudflare for fronting (146 domains confirmed), making IP-level blocking ineffective.
The scale of the operation is exceptional: Group-IB documented 4,300+ fraudulent FIFA-themed domains. CybelAngel independently catalogued 468 IOCs across four distinct fraud vectors: ticket fraud (355), betting/gambling (87), employment fraud (14), and travel/visa fraud (12). The usavisaworldcup.com domain falls into the travel/visa category.
The financial impact is documented at losses of up to $10,000 per premium ticket transaction, with 47,000+ confirmed victims. The Bitcoin, Litecoin, and Monero payment rails used ensure transactions are irreversible and untraceable. Group-IB estimated potential losses "reaching billions of dollars" across the full campaign.
The 185.158.133.1 Cloudflare anycast IP serves usavisaworldcup.com from EU edge nodes (Frankfurt, Munich), meaning European victims receive the content with EU-sourced TLS and low latency — increasing victim trust. A reverse IP lookup on this Cloudflare anycast address showed it shares infrastructure with thousands of other sites, consistent with shared Cloudflare origin servers.
European fans attending the FIFA World Cup 2026 — including Belgian, French, German, Dutch, and other EU nationals — are within the primary target demographic for this visa fraud site. The site explicitly targets international fans requiring US travel documentation. EU residents visiting this site and submitting forms are having their passport data, full names, country of origin, and payment details transmitted to a Supabase project with no lawful basis under GDPR.
The GDPR violations are multiple: Article 5 (lawful basis for processing), Article 13 (no privacy information provided at point of collection), Article 14 (no data subject notification), and Article 25 (privacy by design, given the fraudulent nature of the data collection). The data controller is the operator of usavisaworldcup.com; Supabase (Swedish entity, Supabase AB) is the data processor and is obligated under GDPR Article 28 to process only on lawful instructions.
No privacy policy, no cookie notice, and no data controller identity is visible on the site. The Flock analytics tracker collects visitor data without consent — an additional ePrivacy Directive violation for EU visitors.
The attack chain is straightforward but effective: the operator uses Lovable.app (a legitimate AI tool) to generate a credible-looking visa application website, registers a convincing domain, fronts it through Cloudflare for trust signals and EU performance, and uses Supabase as a zero-effort backend. The victim submits their passport and payment; data goes directly to the Supabase project. No phishing email required — organic search traffic, social media, and World Cup fan forums drive victims to the site.
The post-tournament continuation is the most operationally notable aspect: the operator invested nothing in maintenance and the infrastructure runs indefinitely. Every day the site stays live is additional victim exposure with no additional cost to the operator.
Reporting Targets
Investigation Method
Indicators of Compromise
| Type | Value | Notes |
|---|---|---|
| Domain | usavisaworldcup.com | Primary fraud domain — HTTP 200 live Aug 2026 |
| IP | 185.158.133.1 | AS13335 Cloudflare anycast — EU PoPs FRA/MUC |
| Backend | xknhixtjnhiafccbfica.supabase.co | Supabase project — victim data repository |
| Edge Function | xknhixtjnhiafccbfica.supabase.co/functions/v1/chat | HTTP 500 — deployed and responding |
| App ID | e7658ee8--0a96dab1-06c2-4fac-a0f6-b6cb31ee2eed | Lovable.app project ID — leaked via OG tag |
| R2 Bucket | pub-bb2e103a32db4e198524a2e9ed8f35b4.r2.dev | Cloudflare R2 — assets served |
| Deployment ID | 9dc6bd98-0398-474b-8cb9-009eed9c048d | Lovable deployment fingerprint in response header |
| info@usavisaworldcup.com | Operator honeypot contact embedded in bundle | |
| Registrar | Spaceship Inc. — abuse@spaceship.com | IANA ID 3862 — registered 2026-04-12 |
| Threat Actor | Ghost Stadium | Chinese-speaking — Group-IB attribution Nov 2025 |
| Domain (Cluster) | fifa-careerpath.com / fifa-hr.com / jobs-fifa.com | Related cluster — 91.195.240.94 (SEDO/parked) |
| IP (Cluster) | 91.195.240.94 | AS47846 SEDO GmbH Munich — shared FIFA domain host |
| IP (Cluster) | 3.71.180.249 | AWS eu-central-1 Frankfurt — fifaworldcup-careers.com |
Evidence