Skip to content

Indonesian gambling group hits 16 African government sites

Anchal Verma
Written by Anchal Verma

An Indonesian gambling operation has used compromised government websites in 16 African countries to push illegal casino and lottery pages higher in Google search results.

The campaign affected about 20 government websites, according to an investigation by Techpoint Africa. Chris Nwobi, founder of Zend Cybersecurity Threat Labs, identified the activity after finding Indonesian gambling content hosted within official government domains.

The affected countries include Nigeria, Egypt, Kenya, Uganda, Ghana, South Africa, Mozambique, Malawi, Mauritania, Rwanda, Niger, Burkina Faso, Ethiopia, Libya, Madagascar and Tanzania.

Gambling pages hidden on official websites

The operation did not rely on changing government homepages or taking websites offline. Instead, the attackers added gambling pages to existing government websites and kept much of the activity hidden from normal visitors.

The pages could then appear in Google searches for terms linked to online casinos, lotteries and gambling. This gave the operators access to the search authority already built by official government domains.

Nwobi first identified the activity in Nigeria in May 2026. Three federal websites, belonging to the National Institute for Legislative and Democratic Studies, National Emergency Management Agency and National Agricultural Extension and Research Liaison Services, were among the first sites found carrying gambling content.

Further checks uncovered affected websites in other African countries. Historical records also showed that some gambling-related pages had been hosted on government domains for extended periods.

Nigeria sees several government sites affected

Nigeria emerged as one of the main areas examined during the investigation. Besides the sites initially identified, the research found gambling content linked to government bodies including the Federal High Court, Economic and Financial Crimes Commission, National Broadcasting Commission and Nigeria Extractive Industries Transparency Initiative.

The investigation found that some affected websites continued to operate normally for users who visited them directly. Gambling content could instead be served when users reached specific pages through search engines.

Nwobi also found evidence pointing towards Indonesia. The investigation identified Indonesian payment systems, support numbers and code linked to accounts operating on Indonesian time.

Security weaknesses opened the door

The campaign appears to have taken advantage of weaknesses in website security rather than using complex methods to break into government networks.

Outdated software, unpatched plugins, exposed administrative panels and poorly managed hosting were among the issues identified. These weaknesses gave attackers opportunities to add new pages without immediately affecting the wider operation of the websites.

The investigation found that some gambling pages had been online for more than a year. This indicates that certain compromises remained undetected for long periods before being identified.

A wider cross-border operation

The findings expanded from six countries initially identified by Nwobi to 16 across Africa. The campaign therefore involved government domains in multiple regions rather than being limited to one country’s websites.

Some compromised pages have already been removed. In Nigeria, three sites identified in the initial disclosure were taken down after Nwobi contacted Communications Minister Bosun Tijani. Further affected websites were identified after those removals.

The investigation recommends regular monitoring of government websites, timely software updates and cooperation between cybersecurity agencies to identify similar compromises.

Personalise your news with the voices shaping global iGaming. Pick SiGMA World as your source preference for exclusive interviews, prediction markets, regulatory shifts and smarter industry coverage worldwide.