July 29, 2026

Kenya Named in Cross-Border Government Website Gambling Operation

 Kenya Named in Cross-Border Government Website Gambling Operation

If you searched for an online casino through Google and unknowingly landed on what appeared to be a legitimate government website, you could have become part of a sophisticated cyber scheme that has quietly spread across Africa, including Kenya.

A new investigation, first reported by Techpoint Africa, has uncovered how an Indonesian gambling syndicate infiltrated official government websites in at least 16 countries, using them to secretly host illegal online casino and lottery pages. The operation was designed not to steal government data but to exploit the trust and authority associated with government domains to improve the visibility of gambling platforms on Google search results.

According to Techpoint Africa, the campaign has compromised around 20 government websites across Africa. The affected countries include Kenya, Uganda, Ghana, Nigeria, Egypt, South Africa, Tanzania, Rwanda, Ethiopia, Mozambique, Malawi, Mauritania, Niger, Burkina Faso, Libya and Madagascar.

The investigation was based on findings by independent cybersecurity researcher and founder of Zend Cybersecurity Threat Labs, Chris Nwobi, who first identified the operation.

Gambling pages hidden inside trusted government websites

Unlike many cyberattacks that aim to steal confidential information or demand ransom payments, this campaign followed a different approach.

The attackers quietly embedded illegal gambling pages within legitimate government websites. Because Google generally considers government (.gov) domains to be highly trustworthy, these hidden casino pages received a significant boost in search rankings, increasing the likelihood that users searching for gambling websites would encounter them.

Nwobi compared the tactic to placing an advertisement on a government-owned billboard.

“A government domain is like a billboard on a highway, with the syndicate pasting their advert on it,” he explained.

He added that some websites were manipulated so carefully that ordinary visitors would never notice anything suspicious. However, users arriving through specific Google searches related to gambling would instead be redirected to hidden casino pages.

Kenya among countries affected

Kenya was identified as one of the earliest countries affected by the operation.

According to Techpoint Africa, the first wave targeted six countries: Kenya, Nigeria, Uganda, Ghana, Egypt and South Africa. The campaign later expanded into ten additional African nations, demonstrating what researchers believe is a coordinated operation rather than isolated incidents.

Researchers found no evidence that the attackers intended to compromise sensitive government databases or steal citizens’ personal information. Instead, the primary objective was to use trusted government websites as marketing tools for illegal online gambling businesses.

Everything uncovered during the investigation pointed towards Indonesia.

The source code was reportedly uploaded through GitHub accounts operating during Indonesian working hours. Payment pages relied on Indonesia’s national QR payment system, while customer support contacts also traced back to Indonesia.

Operation remained hidden for months

Nwobi first noticed suspicious activity in May 2026 after discovering Indonesian gambling content appearing on several Nigerian federal government websites.

Those affected included the National Institute for Legislative and Democratic Studies (NILDS), the National Emergency Management Agency (NEMA) and the Agricultural Extension and Research Liaison Services (NAERLS).

One compromised page even displayed a “SLOT88” copyright notice, suggesting a direct connection to an Indonesian gambling platform.

Historical records later revealed that some compromised government websites may have been hosting hidden gambling pages since late 2024 without detection.

As investigations continued, more government websites across multiple countries were found to be affected, highlighting weaknesses in website security maintenance.

Outdated systems opened the door

The investigation found that many of the compromised government websites shared similar security weaknesses.

Several servers were reportedly running outdated software, unpatched content management systems and exposed administration panels connected directly to the internet.

According to Nwobi, the attackers did not rely on advanced hacking techniques.

Instead, they simply exploited security gaps that had remained unattended for years.

He noted that removing the gambling pages alone would not solve the underlying problem if the vulnerabilities allowing access remained unfixed.

Financial motive behind the campaign

Researchers believe the operation was entirely profit-driven.

Instead of stealing information, the syndicate generated revenue by directing internet users towards illegal gambling platforms operating from Indonesia.

Nwobi said it was impossible to estimate exactly how much money the syndicate earned because transactions were processed through Indonesia’s QRIS national payment system using intermediary accounts.

He also revealed that the same group had allegedly operated fake pages impersonating well-known companies such as PayPal, Amazon and AT&T, indicating broader financial fraud activities beyond illegal gambling.

Difference from Kenya’s recent presidential website attack

The findings also distinguish this operation from the recent cyberattack targeting the Kenyan Presidency’s website.

In that incident, attackers reportedly defaced the website with political messages directed at President William Ruto and demanded payment in Bitcoin before government officials restored the platform.

Nwobi explained that the objectives behind the two attacks were completely different.

While the presidential website attack sought publicity through a visible website defacement, the Indonesian gambling syndicate preferred to remain unnoticed.

Its strategy relied on quietly using trusted government websites to funnel internet traffic towards gambling platforms without attracting public attention.

Strengthening cyber defences

Following the discovery, Nwobi outlined several measures governments should prioritise to prevent similar attacks.

The first involves thoroughly cleaning compromised websites while patching the security vulnerabilities that allowed attackers to gain access.

He also recommended continuous monitoring of government websites so suspicious pages can be detected within days instead of remaining online for months.

Because the campaign spans multiple African countries, he urged national Computer Emergency Response Teams (CERTs) to strengthen cooperation through regional cybersecurity initiatives such as AfricaCERT.

Finally, he called for minimum cybersecurity standards across all government websites, noting that many of the compromises stemmed from outdated WordPress plugins hosted on poorly managed servers.

According to Nwobi, fixing individual websites can take as little as an hour, but protecting government digital infrastructure across the continent will require sustained commitment and investment.

The revelations serve as a reminder that cybercriminals continue to evolve their methods, often exploiting trust rather than simply stealing information. As more public services move online, cybersecurity experts say African governments must treat website security as an essential public service, ensuring official digital platforms remain safe, credible and resistant to exploitation.

 
 

Festus Chuma

https://www.linkedin.com/in/festus-chuma-210958a9/

Festus is the Founder and Editorial Director of Kenya Frontline, with over 18 years of experience in digital journalism. A Makerere University alumnus, he is also the Founder of the Global Sports Digital Network (GSDN) and a former Managing Editor of Pulse Sports Kenya. Reach him at festuschuma@gmail.com

Leave a Reply

Your email address will not be published. Required fields are marked *