iGaming & Sportsbook

Scammers Turned Rainbet's Affiliate Program Into Their Business Model

Rainbet, a global online casino and sportsbook, discovered scammers had built a distributed campaign of fake domains and social accounts to hijack its own affiliate commissions across six international markets.

Share

Rainbet is a global online casino and sportsbook operating across more than six international markets, including Germany, France, Australia, Denmark, Czech Republic, and Poland.

Most brand impersonation is built to steal credentials, or trick users into moving funds into a fraudulent account. Rainbet’s attackers found a more subtle way to use Rainbet’s legitimate affiliate program to steal commission.

The Scheme

Scammers registered dozens of Rainbet-branded domains, localized to each market Rainbet operates in: rainbet-de.com, rainbet-au.vip, rainbetdk.com, fr-rainbet.com, rrainbet-casinoo.pl, and more.

They drove players to those domains through a network of fake social media accounts: 288 Instagram profiles, 91 Telegram groups, 36 TikTok accounts, and 12 Facebook pages, all posing as Rainbet affiliates. They even created fake influencers that would \u201cwin big\u201d through Rainbet’s iGaming platform, and then point the viewer to the affiliate link in their bio.

From there, a player landed in one of two places. Some were routed to a competitor’s casino and those customers were lost permanently. Others were routed back to the real Rainbet, but through the scammer’s affiliate link, causing every dollar that player spent to generate a commission for the scammer who did nothing but register a domain.

No credentials stolen. No obvious red flag for the player. Just a brand’s own affiliate infrastructure, turned against it.

What Our Threat Detection Found

Once monitoring went live, the scale of the campaign became clear fast.

Key Results

1,571

1,571

Threats Detected

462

462

Takedowns Completed

1,149

1,149

Threats Watchlisted

1,565

1,565

Takedowns Filed

Nearly every threat found had a takedown filed against it. That filing rate is what drove the completions.

Fake domains made up the largest share of the campaign by far, with Instagram as the main channel pushing traffic to them:

Source

Threats Found

Details

Fake domains

1,047 threats found

Localized, market-specific fakes with affiliate redirects

Instagram

288 threats found

Fake Rainbet pages promoting the fake domains

Telegram

91 threats found

Fake groups and channels

Landing pages

43 threats found

Phishing pages

TikTok

36 threats found

Video content impersonating Rainbet

Twitter/X

22 threats found

Impersonator accounts

Fake crypto addresses

20 threats found

Facebook

12 threats found

Business pages

Pinterest

6 threats found

Fake brand pins

YouTube

3 threats found

Fake video content

Google App Store

2 threats found

Fake apps

Fake domains get blocked at the browser level within minutes of detection. Social accounts and pages go through platform review, so those takedowns run on a longer timeline, days rather than minutes, and Rainbet’s 462 completed takedowns reflect that mix.

What Nobody Had Seen Before

Before monitoring started, Rainbet had 45 threats on record. All from a single gap analysis. No one had been watching what was happening in between.

Stage

Threats

Before monitoring

45 total

First week live

79

Wave 1 (48 hours)

335

Wave 2 (48 hours)

353

Wave 3 (48 hours)

325

Wave 4

136

Ongoing, steady state

~183 and counting

Once our detection went live, the backlog surfaced in four distinct waves as new sources came online, each clearing hundreds of threats in a matter of days:

By the fifth week, daily volume settled into a steady monitoring rhythm. Not because the threats stopped, but because they were being caught as they appeared instead of piling up for years unnoticed.

Domain Pattern

Details

rainbet-casino.site and other direct typosquats

21 instances

eu.com

13 instances, targeting the EU broadly

.com.de and .co.de

10 instances combined, targeting Germany specifically

Regional domains

Dedicated fakes for France, Australia, Denmark, Czech Republic, and Poland, each with its own domain and its own Instagram account pushing traffic to it

A Campaign Built for Six Markets at Once

The domain data tells its own story. Fake Rainbet sites weren’t limited to one country or one language:

This wasn’t one opportunist. It was a distributed operation running the same playbook across multiple markets and languages at once, coordinated enough to give each region its own localized fake front door.

Where It Stands Now

Rainbet went from 45 known threats after years of no monitoring to 1,571 threats detected and 462 fully removed within five weeks of working with ChainPatrol. The affiliate fraud pattern, scammers riding on a brand’s own commission structure, is now caught and actioned on as it appears instead of being discovered long after the damage is done.

If your affiliate program, loyalty program, or referral links could be used in the same way, it’s worth finding out before the scammers do.

Get a free scan of what’s already targeting your brand. Results in 48 hours, no credit card required.

Want to see what’s slipping through?

Get your free brand scan. Results in 48 hours, no credit card required.