Articles

Cybersquatters Clone Chichester Baptist Church Site, Run Secret Casino for Three Years

Nils Sullivan · Mar 26, 2026

Cybersquatters Clone Chichester Baptist Church Site, Run Secret Casino for Three Years

Exterior view of Chichester Baptist Church building under clear skies, highlighting the modest structure targeted by cybersquatters

The Unexpected Hijack Unfolds in Chichester

Observers note how a simple church website in the UK became ground zero for an elaborate online scheme, as cybersquatters cloned the Chichester Baptist Church's domain and transformed it into a covert casino operation that ran undetected for three full years. According to a Telegraph report from March 2026, the church remained oblivious while scammers raked in bets under the guise of familiar religious branding. What's interesting is that visitors stumbling upon the site might have expected sermons or service times, yet encountered slot machines and roulette tables instead, all hosted on a mirrored version of the original page.

The church, nestled in Chichester, West Sussex, maintains a modest online presence meant to connect with the local community; that digital footprint, however, served as the perfect camouflage for illicit gambling activities since around early 2023. Experts who've studied domain hijackings point out that such tactics exploit trust in established names, drawing in unwitting users who assume legitimacy from the cloned layout and logos. And while the congregation carried on with weekly gatherings, the shadow site processed transactions, offered promotions, and even streamed live dealer games, all without triggering alarms at the real church's end.

Discovery Shocks Church Leaders

Church officials first caught wind of the anomaly in early March 2026, when a member mentioned odd pop-ups and gambling prompts while trying to access event schedules online. Turns out, the legitimate site had been overshadowed by its rogue twin, registered under a nearly identical domain that cybersquatters snapped up through lax oversight. Researchers at the Internet Corporation for Assigned Names and Numbers (ICANN), which oversees global domain policies, highlight how these squatters often use variations like misspellings or expired registrations to mimic targets seamlessly.

Upon investigation, IT volunteers from the church uncovered layers of redirection scripts embedded in the fake site, funneling traffic to offshore servers where casino software hummed away 24/7. Data from similar cases reveals that operators employed VPNs and proxy networks to mask their locations, likely operating from jurisdictions with minimal enforcement on unlicensed gambling. The revelation hit hard; pastors recall members expressing confusion over "gambling ads" tied to their searches for Bible studies, although no direct financial losses struck the church itself.

Inside the Cloned Casino Operation

Close-up of a computer screen displaying a cloned church website overlaid with casino games like slots and poker tables

But here's the thing: the cloned site didn't just slap casino links onto the homepage; scammers rebuilt the entire structure, embedding slots, blackjack tables, and virtual roulette wheels within iframes that mimicked church photo galleries and prayer request forms. According to cybersecurity analyses of archived versions, the operation boasted over 200 games from lesser-known providers, complete with deposit options via e-wallets and cryptocurrencies that bypassed traditional banking scrutiny. Players, many from the UK and Europe, deposited funds thinking they'd hit a legit niche casino, lured by the innocent domain's air of trustworthiness.

Those who've dissected the backend code note sophisticated SEO tricks, like keyword stuffing with terms such as "faith-based entertainment" alongside "free spins," which propelled the site up search rankings for unrelated queries. And while the church's real domain pointed to static pages updated sporadically, the fake one pulsed with dynamic content—leaderboards updating in real-time, bonus codes flashing during peak hours, even chat support responding in multiple languages. Figures from domain monitoring tools indicate the site handled thousands of visits monthly, generating revenue streams that experts estimate in the low six figures over the three-year span.

Now, the ball's in the domain registrars' court; post-discovery, the church pursued takedown notices through ICANN's dispute resolution process, leading to the site's shutdown within weeks. Yet remnants lingered in search caches, prompting warnings to parishioners about phishing risks tied to the lingering URLs.

Technical Tricks That Kept It Hidden

Such longevity stems from clever evasion tactics, where cybersquatters registered the doppelganger domain via anonymous services in low-regulation countries, then overlaid casino platforms using content management systems cloned from open-source church templates. Observers familiar with these schemes explain that SSL certificates—those green padlocks signaling security—were easily obtained for the fake site, fooling browsers into displaying "secure" warnings even as bets flowed. Studies from the European Union Agency for Cybersecurity (ENISA) underscore how cloned sites often evade detection because antivirus tools prioritize malware signatures over subtle content swaps.

The reality is, no malware infected the church's servers; this was pure domain squatting, a practice where opportunists park illicit content on lookalike addresses without touching the original. Church admins, relying on volunteer tech support, conducted routine checks that missed the parallel operation, since traffic metrics stayed normal on their end. That's where the rubber meets the road: without proactive monitoring like WHOIS lookups or brand alerts, even small organizations remain vulnerable.

Impact Ripples Through the Congregation

Members of Chichester Baptist Church, a community of around 150 active attendees focused on local outreach, faced awkward conversations once news spread; some reported attempts to access the site for youth group info only to dodge gambling prompts mid-scroll. Pastors addressed the issue in services, clarifying the church's stance against gambling while emphasizing digital vigilance in an era where online threats blur lines between sacred and scams. No reports surfaced of congregants falling victim to the casino, but the breach eroded trust in everyday web navigation.

Broader data on religious institutions reveals they're prime targets; one analysis from US-based cybersecurity firm Recorded Future found non-profits suffer domain clones at rates 40% higher than commercial sites, owing to weaker defenses and high trust factors. In this case, the church pivoted quickly, migrating to a new domain with enhanced security like DNSSEC verification, and now partners with local IT firms for monthly audits.

Lessons from the Shadows of Cybersquatting

Experts who've tracked similar incidents, such as those mimicking charity sites for crypto scams, stress the importance of domain vigilance; tools like Google Alerts or services from GoDaddy's brand protection suite can flag squatted domains early. And while law enforcement in the UK launched inquiries post-exposure, pinning down operators proved tricky due to international servers, echoing challenges in global cyber probes.

People often find that education forms the front line: churches now incorporate cyber hygiene into newsletters, teaching two-factor authentication and URL verification. This Chichester episode, unfolding in March 2026, serves as a stark reminder that even wholesome digital spaces aren't immune, prompting a wave of self-audits among UK faith groups.

Take one parallel case observers reference—a US synagogue site hijacked for sports betting in 2024—where recovery took months but yielded stronger protocols; patterns like these show squatters recycle tactics across borders, targeting entities with evergreen appeal.

Wrapping Up the Casino Church Saga

In the end, Chichester Baptist Church reclaimed its online identity, emerging wiser from the three-year subterfuge that turned prayer pages into poker dens. The swift takedown, fueled by media spotlight and registrar cooperation, underscores how exposure accelerates resolution in domain disputes. Yet as digital footprints expand, those stewarding non-profit sites know the writing's on the wall: vigilance isn't optional, it's essential, especially when scammers lurk just one typo away. With enhanced measures in place, the church continues its mission, a testament to resilience amid evolving online threats.