What Large Events Teach Us About Cyber Risk

August 1, 2026
LinkedIn

Over the weekend, I had the pleaser of attending Megacon in Orlando Florida over the weekend. While it was a great experience - it served as a pretty vivid reminder of how important security is, in every sense of the word.

Walking around an event like Megacon, you notice the physical security side farily easily. There are staff at the entrances, bag checks, cameras, crowed management. It's visible, and makes sense - organizers are responsible for the safety of tens of thousands of people in a shared space. The Cybersecurity and Infrastructure Security Agency notes that public gatherings are particularly vulnerable because of their open accessibility and large volume of people, making them heightened targets for a wide range of security risks. (CISA, n.d.)

What's harder to see - but just as critical - is what's happening on the digital side.

The invidible layer

Whie physical security teams are working to protect people and property, cybersecurity teams are quietly working in the background to protect something less tangible but equally valuable: your data, payment information, and personal details.

The treats you can't see are ofton the ones which do the most damage.

Large events are generally attractive targets for cybercriminals. You have thousands of people making credit card transaction, connecting to a shared Wi-fi network, and moving through vendor systems which may not meat enterprise -level security standards. A report from Microsoft's Cyber Signals threat intelligence found that cybercriminal group are drawn to large-scale events specifically because of the financial opportunities embedded in venue IT environments. (Cyberthreats Increasingly Target the World’s Biggest Event Stages| Security Insider, 2024) Datamine's analysis of major event cyber threats highlight how the interconnected web of internal teams, contractors, and third-party vendors create an enormous and fragmented attack surface which is difficult to defend in any unified way. (Most Common Cyber Threats Targeting Major Events - Dataminr, 2025)

What could actually go wrong

Without proper security measures in place, a few things become real risks. Endpoint breaches happen when a compromised devices - a vendor's tablet, a staff member's laptop - become a doorway into a larger system. A 2026 venue cybersecurity report notes that every internet-connected device at a venue, from ticket scanners to smart thermostats, represent a potential entry point for attackers, and that venue ticketing databases can hold millions of names, emails, and payment details - making them valuable targets. (Ticket Fairy, 2026)

Man-in-the-middle (MITM) attacks allow a bad actor to silently intercept communications between you and a legitimate service, often without either side knowing. Fortinet's threat research on large event cybersecurity explains that venue Wi-Fi networks are especially vulnerable to this type of attack, and that given the size of crowds, MITM attacks at events can be particularly difficult to detect in real time (Lakhani, 2019). Attackers often set up fake Wi-Fi hotspots which mimic legitimate networks, silently capturing all traffic which passes through them. (Imperva, 2025)

And malware can be delivered through rogue networks or phishing attempts, sometimes sitting dormant long after events wrap up. CrowdStrike's 2026 Global Threat Report found that 82% of detections in 2025 were malware-free intrusions - meaning attackers increasingly log in through stolen credentials rather than deploying traditional malicious code, making detection even harder for security teams. (CrowdStrike, 2024)

The result can be stolen credit card data, leaked attendee information, and compromised company records. For instance, in the 2024 Ticketmaster breach, hackers claimed access to data on hundreds of millions of customers and remains of the clearest illustrations of how a single third-party vulnerability can cascade across an entire live event ecosystem. (Ticket Fairy, 2026)

This isn't just an IT problem

What I want to leave is that security as events like this isn't just the sole responsibility of whoever's running the network. It's shared. Everyone has a role. The World Economic Forum's Global Cybersecurity Outlook 2026 reports that nearly three-quarters of respondents said someone in their network was personally affected by cyber-enabled fraud in 2025, with phishing, vishing, and smishing being the most common methods (Joshi & World Economic Forum, 2026). Awareness genuinely is part of the defense.

QUICK TIPS WORTH KEEPING IN MIND

  • Attendees: Be cautious on public Wi-Fi - use a VPN if you have one, and check you accounts after the event.
  • Vendors: Make sure your systems are patched and compliant before you show up. Don't collect data you don't need.
  • Organizers: Bring in cybersecurity professionals during the planning phase, not just on the day. Conduct a post-event security review.

The threat landscape doesn't pause because there's a convention in town. If anything, it intensifies. Guidance on large event security recommends that organizer prioritize securing Wi-Fi networks, protecting event databases against phishing, and training staff to recognize and respond to cybersecurity threats - all well before the doors open (ben, 2025).

References