Government websites across 16 African countries exploited by Indonesian gambling syndicate, investigation finds
An investigation found around 20 government websites were compromised to boost the visibility of illegal online gambling pages in Google search results, with evidence linking the operation to Indonesia.
Nigeria.- Government websites across 16 African countries were exploited by an Indonesian-linked gambling syndicate to boost the visibility of illegal online gambling pages, according to an investigation published by Techpoint Africa. The campaign reportedly compromised around 20 government websites, using trusted official domains to improve the pages’ visibility in Google search results.
The investigation, published on July 23 by Techpoint Africa and conducted by Chris Nwobi, founder of Zend Cybersecurity Threat Labs, found government websites across Nigeria, Egypt, Kenya, Uganda, Ghana, South Africa, Mozambique, Malawi, Mauritania, Rwanda, Niger, Burkina Faso, Ethiopia, Libya, Madagascar and Tanzania had been compromised as part of the campaign.
According to the report, researchers initially identified compromised government websites in six African countries before the investigation expanded to uncover affected websites across 16 countries.
Rather than stealing government data or defacing websites, the attackers embedded gambling content within trusted government domains, allowing the hidden pages to benefit from the credibility and search authority associated with official websites. Techpoint Africa said this was a coordinated operation by an organised group rather than the work of one person, exploiting weak website security rather than sophisticated hacking techniques.
Nwobi said: “It’s like putting your ad on a government billboard,” describing how the syndicate took advantage of the authority associated with government websites to improve the visibility of hidden gambling pages without altering the appearance of the official websites.
Instead of redirecting visitors away from government websites, the attackers created concealed webpages that appeared in Google search results when users searched for gambling-related terms. By exploiting the authority of government domains, the operation increased the visibility of illegal gambling content while leaving the legitimate government websites largely unchanged. According to the investigation, many of the compromised websites were running outdated software, unpatched plugins or exposed administration panels, making them vulnerable to exploitation.
Attack spreads across Africa
While much of the investigation focused on Nigerian government websites, it identified compromised websites belonging to organisations including the Federal High Court, the Economic and Financial Crimes Commission (EFCC), the National Emergency Management Agency (NEMA), the National Institute for Legislative and Democratic Studies (NILDS) and the National Agricultural Extension and Research Liaison Services (NAERLS). The investigation found the operation had also spread to government websites across the remaining affected African countries, highlighting its regional scale.
The investigation also highlighted the rapid response by Nigerian authorities after the findings were disclosed. Nigeria’s Minister of Communications, Innovation and Digital Economy, Bosun Tijani, acknowledged the report and said steps were taken to remove some of the malicious content, although researchers later identified additional compromised websites.
Techpoint Africa said the Indonesian-language content, QRIS payment system and customer support numbers suggest the gambling pages were primarily aimed at Indonesian users, while the compromised African government websites were exploited to benefit from Google’s trust in official domains and improve their search visibility.