Inside the World Cup security operation

Jamie Squire via Getty Images
A massive effort years in the planning at the federal, state and local level helped keep the tournament safe, even as it faced enormous threats of many kinds that all needed mitigating.
The end of the FIFA World Cup earlier this month marked not only the culmination of years of hard work for the 48 teams, but also thousands of security professionals who worked behind the scenes to keep the tournament safe.
The U.S. Department of Homeland Security said 12 of its constituent agencies were involved in the effort to protect the World Cup that was hosted in the U.S., Canada and Mexico. That included inspecting vehicles, making arrests on human trafficking charges and flying air missions, as well as seizing unauthorized drones.
Combined, DHS and the Federal Bureau of Investigations said they seized more than 700 unauthorized drones, with the Federal Aviation Administration establishing no-drone zones to help with that effort.
“In one of the most complex security environments we’ve faced, DHS and our components helped deliver a safe and secure tournament while showcasing American exceptionalism. I want to thank the state and local law enforcement agencies across the country, as well as our federal partners, who worked around the clock to help keep millions of fans and visitors safe,” Homeland Security Secretary Markwayne Mullin said in a statement. “Watching this tournament unfold and seeing the coordination behind the scenes has been extraordinary.”
Keeping the skies safe has been just one facet of World Cup security. Another major aspect was ensuring the venues, host cities and other activations like fan viewing areas did not suffer from cyberattacks. Alongside federal, state and local agencies — as well as private-sector partners, fusion centers and others — the Center for Internet Security joined with FIFA at its security operations center to monitor and mitigate the numerous threats the tournament faced.
John Cohen, executive director of CIS’ Office of Strategic Programs & Initiatives, said the worst-case scenario for organizers of any major event is not one specific event, like a cyberattack or an attack on physical infrastructure by a terrorist organization. Instead, he said organizers prepared for an attack that combines cyber and kinetic strikes, as well as the potential for public misinformation and first-responder communications being impacted to further scramble the response.
“What we were really concerned about is an integrated attack vector that integrated a physical attack, a mass casualty attack, whether it was a vehicle ramming or a mass shooting, simultaneously with a cyberattack, disrupting law enforcement's and first responders' ability to communicate,” Cohen said. “Then at the same time there was an information operation taking video from that attack and blasting it out all over the world. Those were the types of scenarios we focused on."
Planning for the World Cup took a great deal of coordination between the various agencies, something Cohen said FIFA handled well as a convening body. FIFA was also “smart,” Cohen said, in identifying those who had already worked in law enforcement at various levels of government who could be brought in and use their pre-existing relationships to “hit the ground running.”
Last year’s FIFA Club World Cup in the U.S. was seen as something of a dress rehearsal for the security operations effort, which Cohen said also involved building relationships across regions where games would be held, mapping critical infrastructure, holding tabletop exercises and training officials at every level on how to respond if there was any kind of attack.
And Cohen said it wasn’t like the World Cup this summer did not face threats; far from it. Instead, an “all hands on deck” approach helped mitigate those threats, he said.
“It wasn't that there weren't any threats, and it wasn't that nothing happened,” Cohen said. “In fact, we saw a considerable amount of threat-related activity. There were disruptions that took place by law enforcement to prevent attacks from occurring. There were cyber incidents that were in facilitation of criminal activity and other efforts. There was actual criminal activity, illegal ticketing, credentialing. They were just prepared for it, and it was handled really well.”
Combatting fraud was a crucial part of various security efforts during the World Cup, especially as fans looked to secure hard-to-come-by match tickets, as well as merchandise and other items. DHS said Customs and Border Protection seized more than 473,000 counterfeit merchandise items with a genuine retail value estimated to be $33 million. And the U.S. Department of Justice said it seized more than 1,000 internet domains that were used to illegally stream matches during the tournament. CIS had previously warned of illicit betting, fraud and athlete safety risks during the World Cup.
Meanwhile, identity verification and protection company Socure found fraud related to the World Cup originating in all manner of countries, including several that were not participating in the tournament itself. Socure said the fraud took various forms, including fraudsters creating multiple accounts to claim various bonuses or incentives; abusing referral programs and abusing synthetic identities to increase their return on investment in various scams.
The relentless nature of international sporting events means the world will once again descend on the United States — primarily Los Angeles — in two years for the Olympic and Paralympic Games. Planning is already well underway, especially at the local level, with state and federal partners alongside the private sector.
Officials at all levels need to balance the safety of all those involved in an age of heightened threats with the desire to host major events. Cohen said it is always possible, but challenging at the same time.
“We can't live in our basements,” he said. “We have to be able to experience and enjoy life. For many people, it's through these types of sporting events. Unfortunately, they're happening at a time where the threat environment is pretty volatile and dangerous. That's the challenge facing law enforcement and security professionals in this day and age.”




