" "

Cybercriminals use fake Odyssey streaming sites to harvest personal and financial data


People searching for Christopher Nolan’s The Odyssey should be careful about where they enter their personal or payment information. Cybercriminals have created fake streaming websites that promise free access to the film, only to ask visitors for personal details, passwords and banking information. The scam, identified by Kaspersky researchers, is targeting movie fans across multiple countries and languages.

The websites have been designed to resemble legitimate streaming services, giving visitors the impression that they can watch the film after completing a quick registration process. Kaspersky researchers found that the campaign is appearing in multiple languages, suggesting that the operators are adapting the same basic scheme for audiences in different countries.

The timing gives the scam an obvious advantage. The Odyssey, directed by Nolan and distributed by Universal Pictures, opened in cinemas in July 2026 and remains a major theatrical release. Universal lists the film as having opened in theaters on July 17, 2026, with the production shot entirely using IMAX film cameras.

How the Odyssey Streaming Scam Works

The fraudulent sites typically advertise free access to The Odyssey, sometimes claiming that viewers can watch dubbed versions in their preferred language. Some also promise unlimited access, quick registration and the ability to watch across several devices, all features intended to make the offer resemble a conventional streaming subscription.

The deception becomes clearer when a visitor tries to play the film. Instead of showing the movie, the site presents a fake video player and asks the user to create an account before continuing.

JOIN OUR TECHTRENDS NEWSLETTER

The registration form initially appears relatively harmless. It can ask for a name and email address, followed by a request to create a password. The site then introduces another step, asking for banking or payment information on the pretext of activating a free trial.

That sequence gives the operators several opportunities to collect information that can be useful beyond the fake streaming account. An email address and password, for example, may become valuable if the same credentials have been used on another website.

The approach resembles other streaming scams documented by Kaspersky, where criminals use the popularity of major live or entertainment events to direct people towards fraudulent websites. The company’s research into fake streaming operations during the 2026 World Cup found sites offering free broadcasts before asking users to register, illustrating how the same basic social-engineering technique can be adapted around whatever audiences are eager to watch.

Fake Reviews Add Credibility to the Sites

The scam websites do more than simply place a movie title on a page. Kaspersky researchers found fabricated reviews and ratings designed to make the services appear established.

The supposed viewers describe having already watched the film, creating the impression that other people have successfully used the platform. For someone arriving through a search engine or a shared link, those details can provide just enough reassurance to continue.

The promise of free access is another important part of the setup. People looking for a film online may encounter numerous pages claiming to offer a free stream, a trial or access in a particular language. A polished interface, familiar film imagery and positive reviews can make a fraudulent service appear credible at first glance.

That is why the address of the website matters more than how convincing the page looks. A professional design does not establish that a service is authorised to distribute a film or that the company behind it is legitimate.

Why Password Reuse Makes the Scam More Dangerous

The immediate risk is the loss of information entered into the fake registration form, but the consequences can extend further when users reuse passwords.

If a person creates an account on a fraudulent streaming site using the same password they use for email, social media or another online service, the stolen credentials could potentially be tested against those accounts. Kaspersky has previously reported that credential theft remains a major objective of phishing attacks, with its analysis finding that 88.5% of phishing attacks examined between January and September 2025 were focused on stealing account credentials.

Banking information creates another concern. Giving card or other payment details to an unfamiliar streaming website provides criminals with information that could potentially be used in attempted financial fraud. That does not mean every victim will automatically lose money, but there is little reason to provide sensitive financial information to a service whose legitimacy cannot be established.

Kaspersky Senior Web Content Analyst Olga Altukhova warned that major film premieres can give scammers an opportunity to exploit the excitement surrounding popular releases. Her advice is particularly relevant when a film is still in cinemas and unfamiliar websites begin promising immediate or free online access.

How Movie Fans Can Avoid Fake Streaming Sites

The simplest protection is to treat unexpected offers of free access with caution, particularly when a film is still primarily being shown in theaters. Before registering, users should check the website address carefully and verify that the service is an authorised platform rather than relying on its logo, reviews or overall appearance.

Banking or card information should never be entered simply because a website claims that it is required to activate a free trial. If a streaming offer comes from an unfamiliar domain, users should first establish who operates the service and whether it has legitimate distribution rights for the film.

Using a different password for every important online account also limits the damage if credentials are exposed. Two-factor authentication should be enabled wherever it is available, particularly for email, financial and other accounts that could be used to reset passwords elsewhere.

People who have already entered financial information into a suspicious streaming site should monitor their accounts and statements for transactions they do not recognise. Anyone who reused the submitted password on another service should change it there as well, preferably using a unique password that has not been used elsewhere.

The wider lesson from the Odyssey campaign is straightforward: a popular film can be used as bait just as effectively as a fake bank, retailer or social network. The website may promise a few hours of entertainment, but the information requested during registration can be far more valuable to the people operating it.

Download the FREE Kaspersky Next Enterprise Security Guide here to explore the complete framework for simplifying security operations and building cyber resilience.

Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.

Follow us on WhatsAppTelegramTwitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke

Facebook Comments

By Tawheda Ali

I cover innovation, startups, sustainability and digital trends shaping Africa's tech landscape. Got a scoop? Reach out at tawheda@techtrendsmedia.co.ke
Back to top button
×