Cyber Siege: Over 2.1 Million Digital Identities Exposed in Morocco During AFCON 2025

More than 2.1 million digital identities were compromised in Morocco during AFCON 2025, according to a joint report by Kaspersky and INTERPOL, exposing widespread cyber threats tied to fraudulent ticketing platforms and malware campaigns.

Salma Mubarak
Cloud Security & AI Security Contributor2 min read
Cybersecurity analyst investigating stolen digital identities linked to AFCON 2025 cyberattacks in Morocco.

Cybersecurity analyst investigating stolen digital identities linked to AFCON 2025 cyberattacks in Morocco.

A new cybersecurity investigation has revealed that Morocco experienced a major surge in cybercrime during the 2025 Africa Cup of Nations tournament. A joint report released by Kaspersky in collaboration with INTERPOL found that more than 2.1 million digital identities were compromised during the event.

The stolen data—ranging from login credentials and passwords to browser session information—is now circulating on various dark web marketplaces, raising concerns about financial fraud and identity theft targeting football fans and online users.

Cybercriminals Exploit Tournament Hype

Researchers found that threat actors strategically exploited the surge in online traffic surrounding the tournament. Attackers deployed multiple deception techniques designed to trick fans eager to watch matches or purchase tickets.

These tactics included:

  • Fraudulent ticketing websites impersonating legitimate vendors
  • Fake match streaming platforms designed to steal user credentials
  • Counterfeit mobile applications disguised as official AFCON tools

Once users interacted with these platforms, their personal data was silently captured.

Infostealer Malware Driving the Attacks

A large share of the stolen information was collected using infostealer malware, a category of malicious software designed to extract sensitive data from infected devices.

Security analysts identified several prominent malware families involved in the campaign, including:

  • Lumma
  • RedLine
  • Vidar

These tools are capable of harvesting banking details, browser cookies, stored passwords, and cryptocurrency wallet data, allowing attackers to access financial accounts or sell the information on underground forums.

Rise of Hacktivist Activity

The report, conducted under the international cybersecurity initiative Project Stadia, also revealed a surge in politically motivated cyber activity.

Investigators monitored nearly 300 online messages encouraging coordinated cyberattacks, including:

  • Distributed Denial-of-Service (DDoS) attacks
  • Website defacement campaigns targeting organizations connected to the tournament

These activities indicate that major sporting events are increasingly becoming targets for digital disruption as well as cybercrime.

Cybersecurity Implications for Global Sporting Events

The incident is being viewed as a critical stress test for Morocco’s cybersecurity resilience, particularly as the country prepares to co-host the FIFA World Cup 2030.

Security experts warn that safeguarding digital infrastructure is now just as important as protecting physical venues when hosting global events.

As international tournaments attract millions of fans online, cybercriminal groups are likely to continue exploiting the massive digital footprint surrounding sports entertainment.

Salma Mubarak

Cloud Security & AI Security Contributor

Salma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.

At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.