Global Signal Exchange identified all 12 fake FIFA-related domains later named in an FBI fraud warning. The network said the domains had appeared in its data before the World Cup began.
The non-profit fraud-signal clearing house, administered by Oxford Information Labs, had tracked a rise in suspicious FIFA- and World Cup-related activity for months before the tournament. Using seven keyword patterns, including variations designed to catch typosquatted domains that could evade standard filters, it saw activity build from the opening of ticket sales before a sharper rise in the run-up to kick-off.
The findings offer a window into how large technology groups, payments firms and public agencies are trying to share fraud indicators more quickly. Visa, according to the organisation, identified unusual payment and domain activity ahead of the tournament and shared that information with Meta through the exchange.
Meta then mapped and removed a network of fake Facebook pages promoting fraudulent World Cup websites before they reached users at scale. Raúl Burgos, Security Policy Manager at Meta, said the exchange had shortened what is normally a much slower process under formal information-sharing arrangements.
"The GSE allows us to get sharing right away," said Raúl Burgos, Security Policy Manager at Meta.
He contrasted that with direct one-to-one arrangements between organisations.
"Agreeing a bilateral data-sharing deal with a partner normally takes two years, during which the fraud continues," Burgos said.
Broader network
The World Cup-related activity was one of several examples cited by organisations using the exchange. GovTech Singapore has contributed 180,000 scam signals linked to real cases and financial losses, and other participants have used those signals to identify at least 80,000 additional scam enablers, according to the organisation.
Between October 2025 and February 2026, Meta removed more than 30,000 fraudulent entities from Facebook and Instagram based solely on GovTech Singapore's signals. Microsoft, meanwhile, has taken in more than 20 feeds comprising 160 million signals from the exchange's marketplace for use in its automated fraud defences.
The organisation has also expanded the volume of data flowing through the system. Its architecture grew from 60 to 95 distinct threat feeds this month, with much of the increase coming from an integration with global scambaiting communities.
These groups deliberately engage scammers to disrupt their operations and often receive screenshots from members of the public during live scams. The exchange now uses artificial intelligence to analyse those images and extract data including malicious web addresses, hosting providers, phone numbers and crypto wallet details, which are then converted into structured signals for members.
Platform changes
The latest software update added CSV export from the Compass query tool, custom dashboards and new sources including Cifas, Amazon and a dedicated feed of domains linked to active malware exploitation. A push API is also nearing the end of testing and will send signals to members as soon as they are received, the organisation said.
Global Signal Exchange was launched in January 2025 and is owned by Oxford Information Labs, with Google named as a co-founder. It describes itself as a cross-sector clearing house for fraud and cybercrime signals, bringing together data from technology companies, financial firms and public bodies to expose the infrastructure behind scams.
Lucien Taylor, Co-Founder and Chief Technology Officer at Global Signal Exchange, said the latest examples showed both the benefits of the network and the scale of the remaining problem.
"It has been a fascinating month, from watching a fraud network get caught out months before the World Cup even began, to hearing from partners in Singapore and Microsoft about the scale of what shared signals can achieve. It's a real pleasure to hear that kind of feedback, but it also tells us there is still a huge job to do. That is exactly why we keep expanding our network and evolving the platform. Fraud does not stand still, and neither can we," Taylor said.