As FC Juárez prepare to host Puebla in the Liga MX Apertura 2026, thousands of fans across the United States are hunting for last-minute tickets and streaming links — and criminals are counting on it. In July 2026 the FBI publicly warned soccer supporters that fake ticket sites and phishing pages are surging ahead of a World Cup year, and Liga MX matches are being swept into the same fraud machinery. The bargain "boleto" in your WhatsApp inbox may cost you far more than face value.
The scam wave hitting soccer fans right now
The numbers behind this fraud are not hypothetical. Security researchers tracking World Cup–related scams have counted more than 13,000 tournament-themed domains registered in a single five-month stretch, roughly 9% of them flagged as suspicious or outright malicious. One phishing operation nicknamed "Ghost Stadium" is reportedly running over 300 fake login pages that imitate official ticketing screens, some even pulling real graphics from legitimate servers to look convincing. Investigators have already linked more than 270,000 stolen credentials to these ticketing scams.
Mexican fans are squarely in the crosshairs. The Consejo Ciudadano in Mexico City estimates individual losses of 1,000 to 100,000 pesos — about $55 to $5,500 — per victim. And the risk is not limited to online fraud: during the recent Cruz Azul–Pumas final, authorities detained 66 people for illegal resale as part of a broader crackdown by Profeco. When demand spikes for a fixture like Juárez versus Puebla, the same tactics get recycled.
Why a regional Liga MX match is a target
You might assume scammers only chase the biggest finals. They don't. Fraudsters follow attention, and a mid-table Liga MX clash still generates enough search traffic, social buzz, and desperate last-minute buyers to make a fake-ticket page profitable. The playbook is cheap to run: spin up a lookalike domain, copy a stadium's seating map, and buy a few sponsored posts on Facebook, Instagram, or WhatsApp.
The messaging is engineered to rush you. Phrases like "last pieces" and "limited-time offer" are designed to short-circuit the pause that would otherwise let you verify a seller. Once you're anxious about missing the match, you stop checking the URL — which is exactly the moment the scam works.
How an IT security expert spots a fake in seconds
This is where professional judgment pays for itself. An IT security consultant looks at the same "ticket offer" you do and sees a checklist most fans never learn. Here is what they check first.
The payment method is the tell. Legitimate marketplaces support chargeback-protected payment. Scammers steer you toward instant, irreversible apps — Zelle, Venmo, or Cash App — precisely because that money is almost impossible to claw back. A seller who insists on an instant transfer for a "safer, better deal" is describing your loss, not your discount.
A QR code is not proof of anything. A screenshot, a PDF, or a photo of a QR code can be duplicated, edited, or already used before you ever scan it. Ten buyers can each be sold the "same" seat. Genuine mobile tickets live inside an official app tied to your account, not in an image forwarded through a chat.
The URL rarely survives inspection. Fake sites lean on tiny spelling changes, extra hyphens, or unusual domain endings. An expert copies the link into a plain text field, reads it character by character, and confirms it against the club's or league's verified channel before anything is typed into a payment form.
Pressure is a red flag, not a feature. Countdown timers and "only 2 left" banners on an unverified page are manipulation, not scarcity. Real sellers do not need you to panic.
If any of this feels like more than you want to untangle before kickoff, that is a reasonable moment to talk to a professional. Fans who have already been through one ticket or cricket ticket scam know how convincing these operations have become, and the same social-engineering tricks now power deepfake investment scams that reuse the faces of star players.
What to do before you buy — and if you've already paid
Before you spend a peso or a dollar, slow down. Buy only through the club's or Liga MX's official sales channel, and open that channel yourself rather than following a link someone sent you. Verify the exact domain, refuse any deal that demands an instant-payment app, and treat every forwarded QR image as unverified until it loads inside an official account.
If you think you've already handed money or personal data to a fake seller, act the same day. Contact your bank or card issuer immediately to attempt a stop or reversal, change any password you reused on the fake site, and enable two-factor authentication on your email and payment accounts. In the United States, report the fraud to the FBI's Internet Crime Complaint Center at ic3.gov, which is actively collecting reports tied to 2026 soccer ticket scams. Fast reporting improves the odds of recovery and helps investigators shut down the domain before it reaches the next fan.
The expert takeaway
The Juárez–Puebla fixture is a small event inside a very large scam season. The criminals do not care whether you are buying a World Cup final seat or a regular-season ticket; they care that you are in a hurry. A short conversation with an IT security expert before you buy — or right after something goes wrong — can be the difference between watching the match and watching your money disappear. If you're unsure whether an offer or a link is safe, an ExpertZoom IT specialist can review it with you before you click "pay."

Richard Thomas