2 min read

Scottish council website hijacked to promote offshore casinos

Sixteen links on the official Scottish Borders Council website were found redirecting users to offshore casino sites instead of pages for local community councils.

According to the BBC, most of the affected links were originally associated with Online Borders, a platform that was shut down around eight years ago. Local councils were later advised to create their own websites, but the old domains remained active.

The expired domains were subsequently acquired and redirected to a gambling portal promoting no-Gamstop casinos — gambling sites operating outside the UK’s Gamstop self-exclusion system.

Expired domains used to add credibility

University of Strathclyde cybersecurity specialist Daniel Thomas described the incident as domain squatting, where expired domains are acquired and reused for other purposes.

The old links were particularly valuable because they remained listed in an official council directory. This meant users searching for local community council information could potentially be redirected to gambling sites that appeared to have an association with the local authorities.

After the BBC reported the issue, Scottish Borders Council removed the affected links and reminded community councils to keep their websites updated and secure.

TELEGRAM ПЕРЕД ВТОРЫМ H2

Similar incidents reported elsewhere

The incident is not the first case of public-sector websites being exploited to promote gambling content.

In June 2026, the website of Old Catton Parish Council in Norfolk was compromised. Its contact page was replaced with Indonesian-language content promoting slot games, while the homepage displayed an image of a woman playing a slot machine.

That same month, more than 100 government and public-sector websites in India were targeted in a similar campaign. Attackers used cloaking to show gambling-related keywords to search engine crawlers while redirecting mobile users to offshore betting apps.

A similar incident occurred in Nigeria in 2025, when a vulnerable page belonging to the National Population Commission was used to redirect visitors to an Australian casino platform.

Share:
This website uses cookies to ensure its proper operation and to improve user experience. By continuing to use the website, you confirm your consent to their use.