Gambling LawTuesday, 22 September 2026 · 10:20 GMT · 2 min read

How Major iGaming Providers Ended up Inside Scam-casinos Turning Over Millions of Dollars

The investigation led to an international criminal network that operates not as a collection of isolated phishing sites, but as a fraud infrastructure built to scale.

INiGaming.News NewsdeskiGaming.News Contributor
How Major iGaming Providers Ended up Inside Scam-casinos Turning Over Millions of Dollars

A large-scale fraud scheme has recently been exposed in iGaming: players were sent to near-perfect copies of well-known international casino sites, where deposits were accepted and routed straight to the people behind the scheme. One of the systems identified in the investigation is SlotXHub, used to deploy replicas of major casino brands. It quickly became clear that this was not a handful of phishing domains, but an industrialized operation with its own technical infrastructure and turnover running into millions of dollars.

The investigation led to an international criminal network that operates not as a collection of isolated phishing sites, but as a fraud infrastructure built to scale. Its participants, technical nodes and payment routes are spread across several Eastern European countries, while the scheme itself expands through replicas of well-known casinos and recognizable gaming content. According to the materials collected by investigators, part of the network grew out of scam call centers in Eastern Europe and brought familiar social-engineering tactics into iGaming.

The case has already been covered by several industry publications, including outlets in Eastern Europe, which have reported on the mechanics of the scheme in detail.

On both sides of Stake

We compared a phishing replica of Stake with the original. Inside, the provider catalogue and familiar slots are almost identical and the games do not just appear as static images,  they actually launch. To a player, it looks like a normal Stake experience. The replica exploits two layers of trust at once: the casino brand and the familiar game studios.

That is how major providers can effectively end up on both sides of Stake. On the original casino, they operate as B2B partners; on the phishing copy, the same recognizable products help scammers convince players they are on the real Stake and push them toward a deposit. This is not evidence that providers such as Pragmatic Play, Hacksaw, Evolution, PG Soft and other major industry brands knowingly integrate with scammers. The more uncomfortable reality is that their products can be used against legitimate partners while players worldwide lose money to fraudulent copies and operators take the reputational hit. That is precisely why providers themselves need to be aware of the scale of the problem and treat it as something that requires attention.

If providers choose to treat cases like this as simply «not our games», that will not solve the problem. Scammers can still use familiar games and brands to make a phishing casino look legitimate, deceive players and damage an operator’s reputation. If such cases are ignored, it becomes increasingly difficult to treat them as somebody else’s operator-security problem.

What happens next?

This is also an issue for the bodies responsible for the industry’s legal and licensing framework. B2B licensing authorities, the bodies that license providers and oversee compliance with licensing requirements, have a role to play when products associated with licensed providers appear inside fraudulent platforms. Cases like this should raise questions about how abuse is identified, how quickly it is addressed and where responsibility sits when legitimate gaming products are used in scam operations. If such cases reveal breaches of licensing requirements, those authorities have enforcement tools at their disposal.

But regulatory attention alone will not solve the problem. In B2B gambling, reputation is one of the industry’s most valuable assets, and it is the first thing to suffer when a legitimate provider’s product helps a phishing copy deceive players and damage the brand of its partner. The fallout does not stop with one company; it erodes trust in the market as a whole.

That is why the response has to be collective. Operators, providers, platforms, media and regulators need to share information on phishing domains, copied games and the schemes built around them, rather than letting each case fall into the gaps between one party’s responsibility and another’s. If the gambling community recognizes this as a shared problem and starts acting together, networks like these will have far less room to operate. Public scrutiny here is not an attack on the industry; it is a way to separate legitimate business from scams and clean up the market.

TopicsiGaming ProvidersiGaming News
Gambling Law

Related coverage

Categorised news

More from the newsroom