Illegal gambling operators have largely stopped advertising from their own websites and now put casino pages on domains belonging to somebody else, either by breaking into a live site or by buying one after it expires. Great Britain, Italy and the Netherlands each reach for a different instrument when that happens, and only one of the three was built for a case where the domain owner is the victim rather than the offender. The instrument decides how quickly a page comes down, so it matters more to an operator than the headline count of sites any regulator has blocked.
Key Takeaways
Illegal casino advertising is moving onto hijacked and expired domains rather than the operator’s own site. BNR Nieuwsradio found illegal casino promotions on more than 1,000 Dutch domains in September 2026 and put the likely figure above 8,000, and Infoblox tracked one actor it calls Sable Squirrel spending close to USD 7m on expired domains in the first half of 2026 and running more than 10,000 of them as streaming and betting funnels aimed at Vietnam, South Korea, Japan, Taiwan, Singapore and Australia.
The three markets use three different instruments. Italy’s Agenzia delle Dogane e dei Monopoli orders internet service providers to block whole domains, adding 61 on 24 September 2026 for blocking by 9 October and taking its blacklist to 12,699. Great Britain’s Gambling Commission has no blocking power and works through registrars, hosts and search engines, reporting 447,778 URLs referred to Google and Bing and 287,961 removed since April 2024. The Dutch Kansspelautoriteit has neither route, and the cabinet is drafting DNS blocking legislation for consultation in early 2027.
Domain-level blocking is the wrong instrument for a hijacked site because blocking the domain takes down the compromised site itself, not only the casino pages inserted into it. The search-engine route removes the inserted pages and leaves the rest of the domain alone, which is why Great Britain’s slower model fits this particular problem better than Italy’s faster one.
Google changed how it enforces one of the three policies that cover this on 30 August 2026, so the ranking effect of a site reputation abuse manual action no longer applies to searchers inside the European Economic Area, while it still applies outside it. That policy covers a willing host, such as a publisher that sells casino pages behind its own reputation, and Great Britain sits outside the EEA, so the same page can be pushed down in British results and left where it is in Italian and Dutch ones.
What counts as a hijacked gambling advertising site?
Three separate things get described with the same phrase, and the difference between them decides which remedy can work at all.
Pages inserted into a live site. A content management system or a plugin is out of date, somebody gets in, and casino pages appear under a domain whose owner has no idea they are there. BNR Nieuwsradio’s September 2026 investigation named former sites of the VVD branches in Zeeland and Brabant, and the site of the Dutch broadcaster Wilfried de Jong, among more than 1,000 compromised Dutch domains.
Domains bought after they expire. A registration lapses, somebody picks it up at auction, and the old address is rebuilt as a casino referral page on top of the links the previous site earned. Domain Name Wire’s review of the July 2026 NameJet and SnapNames sales recorded GoodwoodBrewing.com going for USD 6,086 and then drawing roughly 500,000 organic visits a month under a Turkish gambling buyer, and AfroPunk.com going for USD 9,250 and being pointed straight at Infinite-Energy.com, a French casino site bought in the same auction cycle for USD 6,501.
A host that agreed. A publisher sells the audience and the reputation it spent years building, and casino content follows. Press Gazette’s March 2026 investigation set out Clickout Media’s purchases of Esports Insider, Videogamer, Techopedia and Sportslens, with casino content appearing on them afterwards and several of the sites later removed from Google’s index.
The three cases look identical in a search result and behave completely differently in an enforcement file. In the first, a victim wants help; in the second, nobody cares what happens to the domain; and in the third, the owner signed a contract. A regulator that only has one instrument will use it on all three, which is where most of the current friction comes from.
The second category is now being bought at scale by people with real money behind them, and most operators have a drawer of these somewhere, from markets they left and brands they retired. Infoblox put Sable Squirrel’s spend on expired domains at close to USD 7m in the first half of 2026 alone, across a portfolio of more than 10,000 domains feeding sports streaming brands such as Xoilac, Cakhia and 90phut into betting brands including VSBet, ColaScore and 8xbet. Nobody spends that opportunistically, and most of the domains it goes on were somebody’s working business the year before.
How do Great Britain, Italy, the Netherlands and Brazil compare?
On whether the regulator can order a domain blocked, who carries out the order, and what happens when the domain belongs to an innocent third party. The table sets out all four.
| Market | Can the regulator order a domain blocked? | Who executes it | Reported scale | Route when the domain belongs to a third party |
| Great Britain | No. The Gambling Commission has no blocking power under the Gambling Act 2005 | Registrars, hosts and search engines acting voluntarily on Commission referrals | 3,140 cease and desist and disruption notices, 447,778 URLs referred to Google and Bing, 287,961 removed, since April 2024 | Page-level removal from search, which leaves the rest of the domain untouched |
| Italy | Yes, at domain level, under Article 102(1) of Decree-Law 104 of 14 August 2020, converted by Law 126 of 13 October 2020 | Internet service providers on ADM order, redirecting to an ADM notice page | 12,699 domains on the blacklist, 61 added on 24 September 2026 with blocking required by 9 October 2026 | None specific. A block removes the whole domain, including the owner’s own pages |
| Netherlands | No, not yet. DNS blocking legislation was in drafting as at September 2026, with consultation due early 2027 | Nobody. The Ksa uses binding instructions and works on search visibility | Not published at domain level | None. The 2023 binding instructions to Cloudflare were withdrawn in April 2024 and replaced by information sharing |
| Brazil | Yes, at domain level, through the Secretaria de Premios e Apostas | Anatel instructs internet providers on SPA notification | 66,482 domains blocked between 15 January 2025 and 2 September 2026, with R$18.019m in fines and R$3.091m collected | None specific. The block is at domain level |
Sources are footnoted at the end. The Dutch column describes the position before the DNS blocking legislation announced on 7 September 2026, which was still being drafted at the time of writing.
Read down the columns rather than across the rows. Italy and Brazil have the power and use it heavily, Great Britain does not have it and compensates with volume at the page level, and the Netherlands has neither and is about to copy Italy. Nobody in the table has an instrument designed for a domain whose owner is a victim.
The Italian numbers are worth holding next to the British ones, because they count different things. ADM’s 12,699 figure counts domains it has ordered providers to block since the list began, and the Commission’s 287,961 counts individual web addresses removed by Google and Bing since April 2024. A single compromised site can generate hundreds of the second and exactly one of the first, so the Italian list looks small and the British number looks enormous while both describe the same volume of illegal advertising.
Some of the Dutch urgency comes from an earlier attempt that did not work. In November 2023 the Kansspelautoriteit issued binding instructions to Cloudflare over two illegal affiliate sites, onlinecasinosspelen.com and nederlandscasinos.net, giving it until 17 November to stop serving them. Those instructions were withdrawn in April 2024 once it became clear Cloudflare could not technically do what was being asked, and were replaced by an agreement that Cloudflare would answer the regulator’s questions about who was hosting what. An information-sharing arrangement is a reasonable outcome, but it is not a takedown.
Why does domain blocking fail on a hijacked site?
Because the domain belongs to somebody who has not broken any law, and a block is all or nothing.
An ADM order sends every name on it to a notice page, and since April 2026 that redirect points to an HTTPS address, sito-inibito-giochi.adm.gov.it, rather than to the IP address used before. For an offshore casino’s own domain that is exactly the right outcome, since the whole domain is the offence. Apply the same order to a cycling club or a former political party branch whose site has had casino pages pushed into it, and the legitimate site goes dark alongside the inserted pages, and the owner then has to clean the site and apply to come off a government blacklist. There is no partial version of a DNS block. A name resolves or it does not.
The search-engine route works at the level of the individual page, which is why it fits this case. Removing twelve inserted addresses from an index leaves the owner’s own pages ranking where they were, and the owner may never need to know an enforcement process happened. The ratio in the Commission’s own reporting shows where the work actually sits: 447,778 URLs referred against 3,140 notices issued since April 2024, so for every formal enforcement step there are more than 140 page-level removals.
Google and Bing are not regulators, and nothing in the Gambling Act 2005 obliges either of them to act on a referral, so they do it because they have chosen to. A regulator with blocking powers does not have to ask, and one without them is negotiating, which is what the Dutch government has spent much of 2026 doing, with six-monthly reports on illegal gambling advertising now promised by Meta and Google. The Commission has not claimed otherwise.
What changed in search enforcement on 30 August 2026?
Google stopped applying the ranking effect of a site reputation abuse manual action to searchers inside the European Economic Area, having agreed changes with the European Commission, while keeping that effect in place for searchers everywhere else.
Three different Google policies cover the three cases set out above, and only one of them changed:
Hacked content, which covers casino pages inserted into a site through a security weakness. Action here is algorithmic and was not affected.
Expired domain abuse, which covers a lapsed domain bought and rebuilt mainly to rank. Action here is also algorithmic and was not affected.
Site reputation abuse, which covers third-party content published on a host site mainly because of the standing that host already has. This one carries a manual action, and this is the one where enforcement now works differently depending on where the searcher is.
Great Britain left the European Economic Area at the end of 2020, so it sits on the side where the manual action still bites. A publisher that has been bought and filled with casino pages can therefore be suppressed in British results and left in place in Italian and Dutch ones, and the site owner still gets the notification in Search Console either way. For an operator trying to work out why a competitor’s affiliate outranks its own brand in one market and not in another, that is usually the explanation.
Compliance teams should price in what tends to happen next. Where search enforcement weakens, regulators lean harder on the instruments they do control, which in Italy and Brazil means more domain blocking and in the Netherlands means legislating for it. The result is that the remedy an operator’s own affiliate faces is becoming less predictable across a licence portfolio, at the same time as licence conditions continue to hold the operator responsible for what its affiliates do.
What should operators do about their own domain estate?
Treat the domain estate as a compliance register rather than an IT asset list, because the exposure usually comes from a domain the business stopped paying for rather than one it still runs. Work through it in this order.
1. List every domain the group owns across every brand, market and retired campaign, with its renewal date and the registrar account that controls it, and name the one person who is told before any domain is allowed to lapse.
2. List every domain the group has let expire in the last three years and look at what is on each one today. A closed market microsite or a retired brand still carries the links and the history it earned, which is precisely what the auction buyers are paying for, and a former operator domain now promoting an unlicensed casino is a conversation with a regulator rather than a curiosity.
3. List every domain in the affiliate programme with the real owner behind it, and test each one against the three Google policies and not only against the advertising code. An affiliate running compliant creative on a dropcatched domain is still a licence problem.
4. Record the enforcement route per licensed market: whether the regulator can order a block, who executes it, how long it actually takes and what evidence it asks for. Italy, Brazil and in due course the Netherlands take the whole domain, Great Britain takes the page, and the submission is different in each case.
5. Set a standing check for the brand appearing on domains the group does not own, and decide now who owns the takedown, because a registrar, a host and a search engine each want a different request in a different format and only one of them answers quickly.
6. Write the reverse procedure as well, for the day a group domain is compromised: who confirms the inserted pages are gone, who asks each search engine for reinstatement, and who checks whether the domain has been added to any national blacklist while the pages were live.
None of this requires new technology, and most of it is a spreadsheet somebody has to own. The reason it does not exist in most operators is that the domain list belongs to the technology team, the affiliate list belongs to marketing, and the enforcement routes belong to compliance, so the three never sit on the same page until a regulator puts them there.
Boardroom Questions
- How many domains do we own across all brands and markets, and can we produce that list today with renewal dates and the registrar account for each one?
- Which domains have we let expire in the last three years, and has anyone looked at what is published on them now?
- For each licensed market, do we know whether the regulator can order a domain blocked, who executes it and how long a wrongful block would take to reverse?
- Are any of our affiliates operating on dropcatched domains or on bought publisher sites, and would we know if they were?
- If one of our own domains were compromised with casino pages tomorrow, who would notice first, and who would be responsible for getting the pages removed from search and off any national blacklist?
Sources
1. Google Search Central, Spam policies for Google web search: hacked content, expired domain abuse and site reputation abuse. The site reputation policy applies where third-party content is published on a host site mainly because of that host’s already-established ranking. Accessed 1 October 2026.
2. Search Engine Land, ‘Google won’t respect manual actions for site reputation abuse in European Economic Area’, reporting the change effective 30 August 2026 and Google’s statement that it agreed changes to its enforcement approach for users in Europe to address the European Commission’s concerns.
3. Gambling Commission, Illegal online gambling: disruption of illegal online gambling, summary of disruption activity, published and last updated 21 October 2025. Figures since April 2024: 3,140 cease and desist and disruption notices (2,032 cease and desist, 774 registrar referrals, 402 host referrals, 3 payment provider referrals), 447,778 URLs referred (339,757 to Google, 108,031 to Bing), 287,961 URLs removed. Quarterly detail runs to April to June 2025.
4. Agenzia delle Dogane e dei Monopoli, blacklist update published 24 September 2026: 61 additional unauthorised gambling domains, total 12,699, internet service providers required to complete blocking by 9 October 2026 with redirection to https://sito-inibito-giochi.adm.gov.it. Legal basis Article 102, paragraph 1, of Decree-Law 104 of 14 August 2020, converted with amendments into Law 126 of 13 October 2020. The 5 August 2026 order (protocol 00540333) covered 190 domains with a 20 August deadline, and ADM has required an HTTPS notice address rather than an IP address since April 2026.
5. Dutch House of Representatives debate, 7 September 2026: Justice State Secretary KT van Bruggen confirmed the cabinet is developing legislation to introduce DNS blocking for illegal gambling sites, with consultation due in early 2027, and that six-monthly reports on illegal gambling advertising were agreed with Meta and Google.
6. BNR Nieuwsradio investigation, 3 September 2026: illegal casino promotions found on more than 1,000 Dutch domains, with BNR estimating the true figure above 8,000. Named examples include former sites of the VVD branches in Zeeland and Brabant and the site of broadcaster Wilfried de Jong.
7. Infoblox threat intelligence research on dropcatched domains, published August 2026: the actor it names Sable Squirrel spent close to USD 7m on expired domains in the first half of 2026 and controls more than 10,000 domains, operating streaming brands including Xoilac, Cakhia, 90phut, Socolive and MiTom as acquisition channels for betting brands including VSBet, ColaScore and 8xbet, targeting Vietnam, South Korea, Japan, Taiwan, Singapore and Australia.
8. Domain Name Wire, 23 September 2026, on the July 2026 NameJet and SnapNames expired domain auctions: GoodwoodBrewing.com sold for USD 6,086 and reached approximately 500,000 organic visits a month under a Turkish gambling buyer using subdomains; AfroPunk.com sold for USD 9,250 and was redirected to Infinite-Energy.com, a French casino site sold for USD 6,501 in the same cycle.
9. Press Gazette, 25 March 2026, updated 30 March 2026, on Clickout Media (trading as Finixio) and its acquisitions of Gambling Insider, Esports Insider, Videogamer, Techopedia, Sportslens and others, the appearance of casino content on those sites, and Google de-indexing under its site reputation abuse policy.
10. Kansspelautoriteit binding instructions to Cloudflare, 3 November 2023, over the illegal affiliate sites onlinecasinosspelen.com and nederlandscasinos.net, with a deadline of 17 November 2023; instructions withdrawn in April 2024 and replaced by an agreement that Cloudflare would provide information on hosting providers behind illegal operators and affiliates.
11. Secretaria de Premios e Apostas data released under Brazil’s Access to Information Law, reported 14 September 2026: 66,482 domains blocked between 15 January 2025 and 2 September 2026, 1,511 profiles removed, R$18.019m in penalties across resolved administrative cases of which R$3.091m collected.