Skip to content
Regulation

NHS Health App Website Hacked to Promote Unlicensed Gambling Operators

The website for My Therappy, an NHS-affiliated health app platform, was compromised in a cyber-attack to display promotions for illegal offshore casinos. The incident is the latest in a series of similar attacks targeting UK public sector websites to advertise unlicensed gambling.

By Gambling SatelliteGambling Satellite
2 min read
Share
NHS Health App Website Hacked to Promote Unlicensed Gambling Operators
  • An NHS health app review website, My Therappy, was cyber-attacked to feature adverts for illegal offshore gambling platforms.
  • The site, which appears to have been dormant since 2020, is now under investigation by the Royal Devon University Healthcare NHS Foundation Trust's cyber security team.
  • This breach follows similar incidents at the Scottish Border Council and Old Catton Parish Council, indicating a trend of public sector sites being targeted by illicit operators.

LONDON – A website connected to the National Health Service has been compromised to promote illegal gambling operations. The site for My Therappy, a health application review platform originally developed by an NHS Trust, was found to be displaying advertisements for unlicensed, offshore betting and gaming companies following a cyber-attack.

The illicit promotions appeared under the name of a fictitious author, 'Daniel Reeves', who was described on the site as a 'Lead Casino Analyst'. The persona's biography claimed he had spent over a decade 'pressure-testing offshore and crypto casinos that serve US players'. The promoted operators were identified as non-UK based and not registered with the GAMSTOP self-exclusion scheme, posing a significant risk to vulnerable individuals.

Dormant Site Exploited

My Therappy was established in 2013 by a Devonshire-based healthtech company as the first review platform for health apps aimed at stroke patients. The platform was initially created and developed by the Northern Devon Healthcare NHS Trust. Responsibility for the initiative now lies with its successor, the Royal Devon University Healthcare NHS Foundation Trust.

The website appears to have been largely inactive prior to the breach, making it a potential target for attackers seeking security vulnerabilities. The last official news update on the My Therappy website was dated October 2020, and its corresponding page on the social media platform X has been dormant since the beginning of 2021.

In a statement issued to Digital Health News, the Royal Devon University Healthcare NHS Foundation Trust acknowledged the breach. A spokesperson confirmed the trust has “raised the issue with our digital and cyber security teams for investigation” and is also working to “establish the status of the My Therappy website domain.”

A Pattern of Public Sector Attacks

The incident is not an isolated case but follows a pattern of public sector websites being exploited to push unlicensed gambling. Just two weeks before the My Therappy discovery, the Scottish Border Council experienced a similar problem when illegal gambling adverts appeared on 16 of its 69 community council webpages. That breach was attributed to an outdated backlog system.

Furthermore, in June, the website for the Old Catton Parish Council was found to be unknowingly hosting an advertisement for an Indonesian online slots casino. These repeated incidents suggest a concerted effort by illicit gambling promoters to leverage the perceived authority and security weaknesses of unmaintained public sector digital assets to reach UK consumers.

Filed under Regulation · 2 min read
Share

The Gambling Satellite briefing

A short email summarising the betting and gaming stories we have published, with links to the original sources behind each one.

Gambling industry news, straight to your inbox.

Sign up for theGambling Satellite briefing.

No spam, no sponsored placements — unsubscribe anytime.

See more articles