Trusted Domain, Untrusted Destination: A Hacked Educational Site in an iGaming Redirect Chain
A reputable domain often feels like a safety net, especially when the destination URL sits on a university or a government site. However, the assumption that such a domain is strictly controlled and poses no risk to users broke years ago, and fraudsters have built schemes around that gap ever since.
ADEX recently uncovered a campaign built entirely on exploiting a trusted domain. On paper, the client’s campaign was spotless: a valid URL, a respectable educational website, and a creative that passed every check. However, the fraud happened after the click, which is why no amount of domain checking would have found it.
In this piece, we will describe how the scheme worked in detail, explain why safe domain logic cannot catch this type of fraud, and what advertisers, networks, and site owners can do about it.
Contents
What ADEX Found Out: The iGaming Platform Instead of A College Site
Our monitoring team spotted a suspicious advertising campaign in our clients’ ads. Instead of a landing page, the ad sent people on a detour that looked completely ordinary – a Google search in Thai. At the end of that detour was an iGaming platform, which is precisely why the detour existed.
Before the campaign
Someone plants an iGaming page on the genuine domain of a real educational institution.
⚠ COMPROMISED SITEThe page never earns that position. It inherits the authority of an academic zone reserved for education. The crawler is the only reader it ever gets.
TRUSTED ZONECampaign live
Destination URL is google.com/search?q=… with the query already filled in. Not the advertiser’s site, not the final destination.
A second click, made by the user, on a third party’s results page. That click is what carries the traffic onward.
OUTSIDE THE AD’S CLICK PATHIt never renders. The user lands on the iGaming site without ever seeing the college page they passed through.
⛔ iGaming DESTINATIONHere is how the scheme worked step by step:
- Step 1. The college website was compromised. Before the campaign launched, someone planted an iGaming-themed page on km.chpc.ac.th, the genuine domain of a Thai educational institution.
- Step 2. Google indexed the planted page. The page appeared as the top result for a specific Thai-language query. Instead of building a new domain’s reputation, the operator used a page hosted on an established educational domain.

- Step 3. The ad pointed to a Google search results page. The ad pointed at the Google search results, not a landing page. A search results page has an ordinary URL, and an ordinary URL can be dropped into a creative like any other: in this campaign, the destination was google.com/search?q=…, with a Thai query already filled in. Neither the advertiser’s own site nor the iGaming-related page appeared anywhere in the campaign. Whatever a reviewer opened, and whatever a crawler followed, resolved to Google.

- Step 4. The user clicked the top search result. This second click occurred on Google’s results page and led to the compromised college domain, placing the next stage outside the ad’s direct click path.
- Step 5. The compromised page redirected to the iGaming site. The planted page redirected immediately instead of rendering visible content. The user therefore reached the iGaming platform without seeing the college page through which the traffic had passed.
Is This a One-Off Or a Common Issue?
This case was not an isolated incident; here is what the public record says.
In 2023, the Ministry of Digital Economy and Society of Thailand reported roughly 30 million iGaming-related URLs sitting across about a thousand public-sector sites.
The Ministry of Public Health alone accounted for some 8 million injected scripts. Neighboring Indonesia tells the same story: its Ministry of Communication and Informatics blocked 683 government and educational sites that had been injected with iGaming content, 461 in the .go.id zone and 222 in .ac.id.
Independent researchers have measured it, too: an academic study published in August 2025 spent a single month crawling Indonesian domains for iGaming keywords and found 147 compromised domains and 346 pages, with the academic .ac.id zone in first place at 65 sites.
On 51.7% of pages, the injected iGaming text sat in the page’s code with a CSS instruction not to display it; on another 22.8%, it was shoved thousands of pixels off the edge of the screen. A visitor sees an ordinary university page; Google’s crawler reads a page full of iGaming-themed keywords. It is the same trick ADEX found on the Thai college site – done with markup instead of a redirect.
Beyond the aggregate numbers, there are several individual case studies – also showing how little this technique depends on vulnerabilities, certain verticals, or a victim:
Documented cases of abusing trusted domains
- Open redirects abused on nine universities, two city and state government sites and a national government’s web resources
- Payload was scams, fake news, phishing and malicious extensions, not iGaming
What it proves The technique isn’t tied to a vertical.
Reported by BleepingComputer, 26 February 2024.
- 1,200+ spam-optimised PDFs planted on that single subdomain
- 3,000+ compromised pages found on a state government portal
- Verticals: iGaming and assorted grey-area services
What it proves Borrowed authority delivers an audience at a scale no fresh domain can buy.
Reported by Ilias Ism, 12 September 2025.
- In 150+ cases nothing was hacked. Attackers simply claimed abandoned cloud DNS delegations left behind by closed projects
- One pharma subdomain had sat unclaimed for 6.5 years
- One telecom operator was the exception: stolen DNS credentials, 1,000+ iGaming subdomains on a dead charity subdomain, each with a valid TLS certificate and a padlock in the address bar
What it proves You don’t even need to break in. It’s enough to claim what was left unclaimed.
Reported by Cyble, “Borrowed Trust”, 12 June 2026.
All figures above are as reported by the source cited on each card.
Has the industry reacted? To some extent, yes: in March 2024, Google added a rule to its spam policies called site reputation abuse. It prohibits one specific thing: publishing someone else's content on a trusted site to borrow that site's ranking. In November 2024, the rule was tightened, and a site owner's involvement is no longer an excuse.
However, it helps very little for a case like this one with a Thai college, as it is written for sites that knowingly rent out their reputation. A hacked college was not a willing participant, but also a victim and most likely nobody there knows the planted page exists. To anyone who saw the page in Google, it could look as if the college had published or supported irrelevant or untrusted content. This could harm its reputation and put visitors at risk.
So what does help?
How to Recognize and Avoid Site Reputation Abuse?
We put this question to our expert to understand: which signals should raise a flag when an advertiser or ad network reviews a redirect chain, and how can publishers avoid being hacked for cloaking?
For ad networks and advertisers
According to the expert, the first thing to watch for during the check is restricted domain zones – ac.*, .gov, .edu, .mi.*, .go.*. – and treat them as a flag rather than a pass. If one of those turns up anywhere in a redirect chain, it’s worth looking at the campaign itself: it may be perfectly justified, for instance, a university advertising its own programs.
Checking a single landing page isn’t enough, because the target URL itself, as in this case, is entirely unremarkable, and whatever is malicious sits behind it.
The rest of the checklist involves the following:
- Compare what a crawler sees with what a real user sees using the geo and device profile from the campaign's own targeting.
- Re-check campaigns that have already been approved. A redirect chain can be rewired after review, and an injected page can appear on a clean domain at any time.
- Don't read a valid TLS certificate as a trust signal. In the Borrowed Trust case (see Is This a One-Off Or a Common Issue block), the iGaming site had a perfectly good certificate on a Fortune 500 domain.
For publishers
The site owners, whose sites are compromised, are also victims in this chain. How do they check that their site is clean, and what should they do if it isn't?
Here is what our expert suggests:
Keep the software on your servers and workstations up to date. A large share of compromises happen for exactly this reason. And be careful with suspicious emails and messenger messages: phishing through social engineering is one the most common ways an attack begins. If you already suspect a compromise, you can start with antivirus tools, but if you run a large site, bring in a company that specializes in cybersecurity as early as you can.
And, two tips to add, suggested by the cases mentioned above:
- Inventory your own subdomains. The Borrowed Trust campaign lived entirely on forgotten ones, and a subdomain you no longer use is still lending your name to whoever claims it.
- Search for yourself the way an attacker would: query your own domain in Google alongside misleading keywords. Injected pages are usually hidden from visitors, but are perfectly visible to search.
What Does It Mean For The Industry?
According to our expert, this case is not unique or special. As he puts it,
Using compromised infrastructure started a long time ago – attackers were just more modest about it, sticking to semi-abandoned or obscure domains. The domain as a trust signal stopped working long before this, back when malware started being distributed through the CDNs of major players.
Thus, what has actually changed is the fraudsters' ambition, which leads to a simple conclusion: the only thing still worth checking is where the click actually ends up, and a respectable domain in a redirect chain is a good reason to look one step further.

