iGaming & Sportsbook
Scammers Turned Rainbet's Affiliate Program Into Their Business Model
Rainbet, a global online casino and sportsbook, discovered scammers had built a distributed campaign of fake domains and social accounts to hijack its own affiliate commissions across six international markets.

Share
Rainbet is a global online casino and sportsbook operating across more than six international markets, including Germany, France, Australia, Denmark, Czech Republic, and Poland.
Most brand impersonation is built to steal credentials, or trick users into moving funds into a fraudulent account. Rainbet’s attackers found a more subtle way to use Rainbet’s legitimate affiliate program to steal commission.
The Scheme
Scammers registered dozens of Rainbet-branded domains, localized to each market Rainbet operates in: rainbet-de.com, rainbet-au.vip, rainbetdk.com, fr-rainbet.com, rrainbet-casinoo.pl, and more.
They drove players to those domains through a network of fake social media accounts: 288 Instagram profiles, 91 Telegram groups, 36 TikTok accounts, and 12 Facebook pages, all posing as Rainbet affiliates. They even created fake influencers that would \u201cwin big\u201d through Rainbet’s iGaming platform, and then point the viewer to the affiliate link in their bio.
From there, a player landed in one of two places. Some were routed to a competitor’s casino and those customers were lost permanently. Others were routed back to the real Rainbet, but through the scammer’s affiliate link, causing every dollar that player spent to generate a commission for the scammer who did nothing but register a domain.
No credentials stolen. No obvious red flag for the player. Just a brand’s own affiliate infrastructure, turned against it.
What Our Threat Detection Found
Once monitoring went live, the scale of the campaign became clear fast.
Key Results
Threats Detected
Takedowns Completed
Threats Watchlisted
Takedowns Filed
Nearly every threat found had a takedown filed against it. That filing rate is what drove the completions.
Fake domains made up the largest share of the campaign by far, with Instagram as the main channel pushing traffic to them:
Source | Threats Found | Details |
|---|---|---|
Fake domains | 1,047 threats found | Localized, market-specific fakes with affiliate redirects |
288 threats found | Fake Rainbet pages promoting the fake domains | |
Telegram | 91 threats found | Fake groups and channels |
Landing pages | 43 threats found | Phishing pages |
TikTok | 36 threats found | Video content impersonating Rainbet |
Twitter/X | 22 threats found | Impersonator accounts |
Fake crypto addresses | 20 threats found | — |
12 threats found | Business pages | |
6 threats found | Fake brand pins | |
YouTube | 3 threats found | Fake video content |
Google App Store | 2 threats found | Fake apps |
Fake domains get blocked at the browser level within minutes of detection. Social accounts and pages go through platform review, so those takedowns run on a longer timeline, days rather than minutes, and Rainbet’s 462 completed takedowns reflect that mix.
What Nobody Had Seen Before
Before monitoring started, Rainbet had 45 threats on record. All from a single gap analysis. No one had been watching what was happening in between.
Stage | Threats |
|---|---|
Before monitoring | 45 total |
First week live | 79 |
Wave 1 (48 hours) | 335 |
Wave 2 (48 hours) | 353 |
Wave 3 (48 hours) | 325 |
Wave 4 | 136 |
Ongoing, steady state | ~183 and counting |
Once our detection went live, the backlog surfaced in four distinct waves as new sources came online, each clearing hundreds of threats in a matter of days:
By the fifth week, daily volume settled into a steady monitoring rhythm. Not because the threats stopped, but because they were being caught as they appeared instead of piling up for years unnoticed.
Domain Pattern | Details |
|---|---|
rainbet-casino.site and other direct typosquats | 21 instances |
eu.com | 13 instances, targeting the EU broadly |
.com.de and .co.de | 10 instances combined, targeting Germany specifically |
Regional domains | Dedicated fakes for France, Australia, Denmark, Czech Republic, and Poland, each with its own domain and its own Instagram account pushing traffic to it |
A Campaign Built for Six Markets at Once
The domain data tells its own story. Fake Rainbet sites weren’t limited to one country or one language:
This wasn’t one opportunist. It was a distributed operation running the same playbook across multiple markets and languages at once, coordinated enough to give each region its own localized fake front door.
Where It Stands Now
Rainbet went from 45 known threats after years of no monitoring to 1,571 threats detected and 462 fully removed within five weeks of working with ChainPatrol. The affiliate fraud pattern, scammers riding on a brand’s own commission structure, is now caught and actioned on as it appears instead of being discovered long after the damage is done.
If your affiliate program, loyalty program, or referral links could be used in the same way, it’s worth finding out before the scammers do.
Get a free scan of what’s already targeting your brand. Results in 48 hours, no credit card required.
Want to see what’s slipping through?
Get your free brand scan. Results in 48 hours, no credit card required.