An NHS health app website has become the latest UK public sector platform to be targeted by a cyber attack promoting illegal casinos to British consumers.
My Therappy, a Devonshire-based healthtech company established in 2013 as the first health app review site for stroke patients, appears to have had its website hijacked by promotions for non-UK and non-GAMSTOP casinos.
The site does not appear to have received an official news update since October 2020, potentially leaving it vulnerable to exploitation by bad actors operating in the unlicensed gambling space.
An author named Daniel Reeves is listed across the site’s content, showcasing illegal offshore gambling platforms to UK visitors who may stumble across the compromised pages.
The author’s introduction on the site concludes with the line: “Put the kettle on; we’re about to unpack the best offshore gambling spots open to British punters in 2026.”
A Daniel Reeves profile has also been found on other sites promoting illegal online casinos, where he is described as a “Lead Casino Analyst” who “has spent more than a decade pressure-testing offshore and crypto casinos that serve US players.”
Royal Devon University Healthcare NHS Foundation Trust issued a statement in response to the story, which was originally broken by Digital Health News, confirming its teams were investigating the matter.
The statement read: “We have raised this with our digital and cyber security teams for investigation. We are currently establishing the status of the website domain and will provide a further update once we have completed our enquiries.”
The Trust added: “We take matters relating to online safety and security seriously and are looking into this as a priority.”
This incident follows a similar attack on Scottish Borders Council’s website just two weeks prior, which resulted from an outdated backlog system and impacted 16 of the 69 community council webpage listings.
In June, Old Catton Parish Council was also caught up in a comparable situation after unknowingly displaying an advertisement for an Indonesian online slots casino on its website.
These repeated incidents highlight an ongoing and serious problem with unlicensed gambling operators deliberately targeting vulnerable consumers, including those who have already self-excluded through GAMSTOP.
The pattern of attacks on public sector and community websites points to a coordinated effort by illegal gambling networks to reach UK audiences through trusted, and often poorly maintained, institutional web platforms.

