Ticket Heist fraud gang uses 700 domains to sell fake Olympics tickets

Share:

A large-scale fraud campaign with over 700 domain names is likely targeting Russian-speaking users looking to purchase tickets for the Summer Olympics in Paris.

The operation offers fake tickets to the Olympic Games and appears to take advantage of other major sports and music events.

Researchers analyzing the campaign are calling it Ticket Heist and found that some of the domains were created in 2022 and the threat actor kept registering an average of 20 new ones every month.

Overpriced fake Olympic Games tickets

In late 2023, researchers at threat intelligence company QuoIntelligence noticed increased conversation about the Olympic Games in Paris scheduled to start this July 26th.

Because the event has always been used for geopolitical influence and the International Olympic Committee’s decision to ban Russian and Belarusian athletes’ participation under their country flag, researchers kept monitoring the topic and looked for suspicious activity online.

QuoIntelligence kept an eye on specific keywords (e.g. ticket, Paris, discount, offer) used in newly registered domains and discovered operation Ticket Heist which relies on 708 domains hosting convincing websites claiming to sell valid tickets and provide accommodation options for the Olympic Games in Paris.

The first such domains discovered were ticket-paris24[.]com and tickets-paris24[.]com, the latter being a clone of the first.

“Despite minor spelling and grammar mistakes, likely due to direct translation from Russian to English, the website and its user experience were comparable to those of a high-end site” – QuoIntelligence

The user interaction that the Ticket Heist operators created for visitors appears legitimate and encourages engagement with the site and ticket selection.

Ticket Heist page for fake Olympic Games tickets
Ticket Heist page for fake Olympic Games tickets
source: QuoIntelligence

In a report today, the researchers say that the same UI framework is present across all websites related to Ticket Heist, with only minor variations in content and language making the difference between the fraudulent websites.

Apart from the design of the websites, what stands out in the scheme is the price of the fake tickets offered. QuoIntelligence notes that the prices are inflated compared to the legitimate ones.

“For example, a random event and seat location on the official website could cost less than EUR 100, whereas the same tickets and locations on the fraudulent websites were priced at a minimum of EUR 300, often reaching EUR 1,000” – QuoIntelligence

QuoIntelligence threat researcher Andrei Moldovan told BleepingComputer that while there is no confirmation, the higher prices could be part of a trick to make victims believe they get “premium treatment” for the extra money since the tickets are not available through the official distribution channels.

Alternatively, a higher price could also make victims believe that it’s a scalping operation that takes advantage of the shortage of tickets.

While trying to test their theories about the objective of Ticket Heist and to gather information that could lead to who is behind it, QuoIntelligence attempted a purchase from one of the fraudulent websites.

They found that all transactions are carried out through the Stripe payment processing platform and the money is transferred only when the card has sufficient funds.

This means that the operator’s goal is not to collect credit card information but to steal money from the victim.

Furthermore, this test also revealed the company name VIP Events Team LLC, which was created on November 26, 2021, and is still active but its website has never been indexed by public search engines.

“The domain was registered on the same day the company was formed. There are no mentions of VIP Events Team LLC on Google, social media, TrustPilot, or any other available OSINT sources” – QuoIntelligence

The researchers say that while the company appears to be based in New York, the “contact us” section on ticket-paris24[.]com lists the company behind it as located in Tbilisi, Georgia.

Analyzing the infrastructure behind the Ticket Heist operation, the researchers discovered that all the fraudulent domains were hosted at the same IP address, 179[.]43[.]166[.]54, belonging to a provider is linked to malicious activities by multiple services.

While every website has a unique SSL certificate, QuoIntelligence noticed a pattern in the structure of the domain and unique subdomain names used.

They observed that the subdomains often included jswidgetwidget-frame, or widget-api, which, combined with DNS records and common JavaScript files, helped them uncover the entire network of 708 domains.

Every month, the threat actor registered an average of 20 new domains but last November the number recorded a significant increase with 50 new domains being created.

Currently, 98% of the domains linked to Ticket Heist are considered clean of malware by crowdsourced analysis services, which supports the theory that the objective is to steal directly from victims through a legitimate payment service.

Event lures and victims

The Olympic events in Paris were not the only lures in operation Ticket Heist. The fraudsters also tried to lure victims with fake tickets for the UEFA European Championship this year.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:13 am, Jun 19, 2025
weather icon 19°C
L: 17° | H: 20°
few clouds
Humidity: 75 %
Pressure: 1024 mb
Wind: 5 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 21%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 20°°C 0 mm 0% 10 mph 74 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 27°°C 0 mm 0% 10 mph 71 % 1025 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
18° | 32°°C 0 mm 0% 11 mph 64 % 1021 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
20° | 28°°C 1 mm 100% 14 mph 79 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
17° | 23°°C 0 mm 0% 15 mph 78 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
17° | 19°°C 0 mm 0% 0 mph 74 % 1024 mb 0 mm/h
Today 7:00 am
weather icon
19° | 19°°C 0 mm 0% 0 mph 68 % 1025 mb 0 mm/h
Today 10:00 am
weather icon
26° | 26°°C 0 mm 0% 2 mph 46 % 1025 mb 0 mm/h
Today 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 2 mph 33 % 1025 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 9 mph 32 % 1024 mb 0 mm/h
Today 7:00 pm
weather icon
26° | 26°°C 0 mm 0% 10 mph 42 % 1024 mb 0 mm/h
Today 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 56 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 69 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,322.69
0.24%
Ethereum(ETH)
€2,198.25
0.40%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.89
0.41%
Solana(SOL)
€127.55
-0.88%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.148538
0.51%
Shiba Inu(SHIB)
€0.000010
0.32%
Pepe(PEPE)
€0.000009
1.89%
Scroll to Top