The website of a UK Member of Parliament is suspected to have been targeted in a cyberattack after redirecting visitors to gambling platforms in Southeast Asia, underscoring the rise of illicit online promotion channels and cross-border threats.
Sir David Davis’s website, Conservative MP for Goole and Pocklington, was compromised on 23 April. He described the breach as a “direct interference” with his parliamentary duties after discovering that malicious code had been inserted into the site, which rerouted users to gambling pages, before the platform was shut down.
Escalation to DDoS attack
Although the website was restored, it was soon hit by a large-scale distributed denial-of-service (DDoS) attack. According to Sir Davis, the assault generated around 142 million requests and nearly 800 GB of traffic within 24 hours, overwhelming the site’s defences.
Other politicians are facing similar cybersecurity concerns as these cyberattacks continue to grow. These attacks range from phishing and ransomware to nation-state attacks. Their goal: to undermine their victims’ democratic processes.
Additionally, aside from compromising sensitive data, these threats erode public trust and the ability of elected officials to serve constituents, as reported by several media outlets.
They are also prime targets for cyberattacks because of their influence and visibility. Strengthening cyber hygiene, investing in resilient infrastructure and coordinating with national and international security agencies are essential to protect democratic processes.
What is a DDoS Attack?
A DDoS attack floods a server with traffic from multiple sources, disrupting normal operations and rendering services inaccessible. Attackers use a botnet, a network of compromised devices like computers, IoT gadgets, and servers, to send huge volumes of requests to the target.
Legitimate users cannot access the service, leaving it to downtime, lost revenue, reputational damage, or disruption of critical operations. Common types of DDoS attacks include volumetric attacks, such as flooding bandwidth with massive amounts of data; protocol attacks that exploit weaknesses in network protocols; and application-layer attacks that target specific functions like login pages or APIs and consumer server resources.
In the past, other incidents include Amazon Web Services (AWS). The organisation suffered the largest recorded DDoS attack in February 2020, surpassing earlier attacks on GitHub, according to media reports.
DDOS attacks are not about stealing data. But rather, they’re about denying access. For politicians, businesses, and governments, investing in resilient infrastructure and proactive monitoring is essential to safeguard against these increasingly sophisticated disruptions.
Suspected origins of malicious traffic
Sir Davis told Parliament that the malicious traffic appeared “traceable to China,” though his office also detected activity from other jurisdictions. His team is now working with hosting providers to strengthen defences and prevent further incidents.
For one, the UK’s cybersecurity policy combines a long-term strategy, which includes the Government Cyber Security Strategy (2022-2030) and the new Cyber Security and Resilience Bill (2025). Together, they aim to strengthen resilience against hostile states, cybercriminals, and large-scale attacks on critical infrastructure. These frameworks emphasise protecting government services, improving incident response, and raising security standards across sectors.
Speaking to parliament, Sir Davis said, “this is not a minor nuisance. It’s a direct interference with a Member of Parliament carrying out his duties.”
Don’t just read the news — stay ahead of it. Subscribe HERE to SiGMA’s Top 10 News countdown for stories shaping iGaming’s future, weekly insights from the world’s biggest iGaming community, and exclusive subscriber-only offers.


