Justin Miller, M.S., Program Director of Cybersecurity at the University of Tulsa
As the 2026 FIFA World Cup unfolds across the United States, Canada, and Mexico, cybersecurity has become a critical concern for organisers, governments, travel providers, and hospitality businesses alike. With millions of fans travelling between host cities and relying on digital platforms for tickets, accommodation, transport, and payments, the tournament's vast interconnected ecosystem presents a lucrative target for cybercriminals.
From ticketing scams and ransomware attacks to misinformation campaigns and threats against critical infrastructure, even minor disruptions can have far-reaching consequences. In this exclusive interview with Travel Daily Media, Justin Miller, M.S., Program Director of Cybersecurity at the University of Tulsa, discusses the key cyber risks surrounding the tournament, the lessons the industry can learn from recent incidents, and how travel and tourism stakeholders can strengthen their cyber resilience during one of the world's biggest sporting events.
Travel Daily Media (TDM): From your experience protecting critical systems, which cyber risks concern you most ahead of the tournament—ticketing fraud, transportation disruptions, ransomware, misinformation campaigns, or attacks on critical infrastructure?
Justin Miller (JM): My greatest concern is not any single cyber threat in isolation, it is the convergence of several smaller attacks creating operational disruption. Ticket fraud will absolutely occur, but from a public safety standpoint, transportation disruptions and attacks against critical infrastructure concern me most because they create cascading effects.
A ransomware incident affecting airport systems, rail scheduling, stadium access controls, or municipal systems can quickly move from an IT problem to a public safety issue. Add misinformation campaigns spreading false reports of threats, venue changes, or transportation disruptions on social media, and you can create confusion at scale. Large international events are attractive targets because attackers know even minor disruptions gain global attention.

TDM: Major sporting events often attract cybercriminals targeting ticket sales, accommodation bookings, and travel arrangements. What scams and cyberattacks should travelers and travel companies be preparing for?
JM: Travellers should expect an explosion of fraud tied to urgency and scarcity: fake ticket sites, fraudulent lodging offers, phishing emails impersonating airlines or FIFA-related organisations, and fake customer support scams. Criminals exploit emotion. When people fear missing out on tickets or hotels, they click before they think. We will likely see cloned booking websites, QR-code ticket scams, fraudulent mobile apps, and spoofed customer-service phone numbers designed to steal payment information.
Travel companies should also prepare for credential stuffing attacks against loyalty accounts, business email compromise targeting reservations staff, and ransomware attempts designed to interrupt booking systems during peak travel periods.
TDM: With millions of fans expected to travel across the U.S., Canada, and Mexico, how realistic is the risk of cyber incidents affecting airports, airlines, rail networks, or urban transport systems?
JM: The risk is very realistic, not necessarily in the form of catastrophic attacks, but operational disruption. We have already seen ransomware, outages, and third-party vendor incidents disrupt airlines and transportation systems worldwide. The most probable scenario is not a Hollywood-style takedown of an airport, but temporary service degradation: delayed check-ins, reservation outages, baggage disruptions, payment failures, or scheduling confusion caused by cyber incidents affecting interconnected systems. Transportation systems are increasingly digitized and dependent on third-party vendors, which expands the attack surface considerably. During an event like the World Cup, even a short outage can have outsized consequences.
TDM: What lessons can World Cup organisers learn from recent cyber incidents affecting airlines, airports, and major public events?
JM: One of the biggest lessons is that resilience matters just as much as prevention. Organisations must assume they will experience attempted compromises and prepare to operate through them. Recent incidents show the importance of network segmentation, backup communications, offline contingency plans, and tabletop exercises that include cyber scenarios. If ticket validation systems fail, what is the manual backup? If transportation apps go offline, how do fans receive trusted information? Another lesson is vendor risk management. Major events depend heavily on contractors, cloud providers, payment processors, and third-party logistics. Security is only as strong as the weakest connected partner.
TDM: Beyond government agencies and tournament organisers, what practical steps should hospitality and tourism businesses take to protect guests, payments, reservations, and operational systems?
JM: Hotels, restaurants, and tourism providers should think like high-value targets because, during the World Cup, they will be.
At a minimum, organisations should implement multi-factor authentication, train staff to identify phishing attempts, patch internet-facing systems, segment payment networks from guest Wi-Fi, and rehearse ransomware response procedures. Equally important is incident response planning. A hotel should know exactly what happens if reservation systems fail or payment systems go down during peak occupancy. Preparedness often determines whether an incident becomes an inconvenience or a crisis.

TDM: What does effective collaboration look like between governments, stadium operators, transport providers, hotels, and technology companies when preparing for a global event of this scale?
JM: Effective collaboration means moving beyond information sharing to operational coordination. The organisations involved should establish joint communication protocols, pre-identified points of contact, and shared incident reporting mechanisms before the event begins. Governments, stadium operators, transportation providers, and private industry need a common operating picture. In my experience protecting major events, the organisations that perform best are the ones that already know each other before the crisis. Relationships built during planning matter far more than relationships built during an emergency.
TDM: What advice would you give travellers attending the World Cup to protect themselves from cybercrime?
JM: My advice is simple: slow down and verify! Buy tickets only from official sources. Be skeptical of discounted offers or last-minute ticket opportunities. Avoid public Wi-Fi for financial transactions unless using a trusted VPN. Turn on multi-factor authentication for airline, hotel, and banking accounts before traveling.
I also recommend charging devices before travel and carrying backup access methods because account lockouts abroad can become major headaches. Finally, if a message pressures you to act immediately, whether it is about tickets, accommodations, or transportation, treat it as suspicious.
TDM: If there is one cyber vulnerability that World Cup organisers and travel stakeholders are underestimating today, what is it, and why?
I believe many organisations underestimate third-party risk and interconnected dependencies. Modern events rely on an enormous ecosystem of vendors: ticketing providers, payment processors, transportation contractors, cloud services, hotel systems, and temporary event technology. Attackers often target the smaller, less secure partner to reach the larger ecosystem.
The challenge is that organisations tend to focus on protecting their own network while overlooking the fact that operational disruption can arrive through someone else’s compromise. For an event this large, cyber resilience across the ecosystem may matter more than the security of any single organisation.