Former poker pro exposes fraud farms, behavioural signals and the latest threats for this summer’s World Cup
Hacking the House +
The Gaming Ledger + Alea’s Alex Tomic on how games are being breached and the power of proper API Governance
A new column from Russell Mifsud, Director, Head of Gaming Europe, KPMG on regulation, risk and strategy
Editor’s Note
Defenders of Trust
Welcome to a GamblingIQ issue packed with experience, knowledge, urgency, and the hard truths about building trust in an industry under relentless attack.
We begin with Michael Tobin, the sort of founder who doesn’t just spot where an industry is heading; he builds the road and shows everyone else the way. From a single data centre vision to a global backbone of gambling infrastructure and security, Tobin has spent two decades proving that resilience is not a slogan but a commercial necessity.
In this Defenders of Trust edition, his message is unmistakable: security is no longer just a department. It is the product. That thinking runs through our story on Threat Exchange, a bold product which shifts cyber-defence from isolated panic to coordinated action. Instead of every operator learning the same painful lessons alone, the industry is being urged to share intelligence in real time, to see attacks forming before they land, and to turn collective visibility into collective protection. It is a grown-up answer to a grown-up problem.
Because the problem is now enormous. GamblingIQ’s reporting makes clear that fraud and cybercrime are no longer background noise; they are commercial threats capable of destabilising entire businesses. Criminal networks have become more professional. Toolkits are sold. AI is weaponised. The era of the lone hacker is over. What we face instead is an industrial-scale assault on platforms, payments, identities and reputations.
We introduce the new Russell Mifsud column. Not a conventional think-piece, but a practical, clear-eyed assessment of leadership decisions under regulatory pressure. The KPMG in Malta supremo dissects the uncomfortable truth many prefer to dodge; that trust today must be audited and evidenced, not asserted. He goes after box-ticking compliance, and lays out why explainability, accountability and board-level ownership are the next battlegrounds. His argument is simple: if you cannot explain your systems, you do not control them. And if you do not control them, regulators — and the courts — eventually will.
This Defenders of Trust edition is about competence and asks whether the gambling industry chooses to professionalise its approach to risk at the same speed it has professionalised its approach to growth. Michael Tobin has already made his choice. The challenge, laid bare in these pages, is whether the industry will follow before they are forced to.
+ Russell Mifsud, (pictured), Director, Head of Gaming Europe at KPMG. Keep in touch with the latest trends in his new column, The Gaming Ledger. See pages 18 & 19
Index + Highlights
- Guardian of the Games: Alex Tomic, (pictured, right), Founder, Alea. Read about Reverse Integration, API Governance and why hackers moved downstream , (22 & 23)
The 8th Continent with Michael Tobin Alex Tomic on Reverse Integration, API Governance
“The idea just hit me. There are seven continents. The eighth is the Internet.” Continent 8 was born in 1998, created to serve financial services before veering, almost serendipitously, into online gaming.
Threat Exchange from Continent 8 is a real-time feed of indicators, actor profiles and automated investigations designed to turn the company’s unique network visibility into operational defence.
Given that iGaming operates continuous uptime, fraud prevention and managed security services (MSSPs) are mission-critical. Check out the annual GamblingIQ map of the leading companies in the space on page 10.
Former Poker Player showing iGaming how to call a Bluff
GamblingIQ speaks to Kris Galloway, Head of iGaming Product at Sumsub about how behaviour is outwitting identity. Plus, the five criminal business models behind today’s mass account attacks.
The World Cup presents a paradox for regulated iGaming: a moment of unparalleled commercial opportunity that also concentrates systemic risk.
Gaming Ledger, The Russell Mifsud Column
A new column from Director, Head of Gaming Europe at KPMG, Russell Mifsud. Here, he talks about how trust must now be proven; systems, controls, evidence, and decisions that withstand regulatory
Hacking & Data Breaches
Apart from on-chain crypto analysis, disclosure rules shape the narrative. Here, GamblingIQ looks into some of the most notable hacks and data breaches affecting operators & platforms.
Guardian of the Games, featuring Alea’s Alex Tomic
In response to a new generation of games hackers, Alea and security specialist Continent 8 launched a joint programme to harden Alea’s API ecosystem and provide verifiable security guarantees to clients.
Compliance
by Design, with Finnplay’s Jaakko Soininen
Finland’s imminent licence window raises an industry debate: how to reconcile regulators’ desire for reliable evidence with the engineering and commercial realities of running multi-market platforms.
Fraud Prevention, Annual Global Rankings, [3rd
GamblingIQ talks to the operators and Benchmarks the leading fraud prevention and digital identity providers globally, ranked on innovation, effectiveness & real-world impact.
Operators and identity providers can form a regulated trust framework with common APIs, standardised consent artifacts and shared revocation lists; akin to open banking payments rails, but for identity.
Fraud’s Cold Calculus: New Research shows First-Party Deception is the biggest Profit Leak; there are fewer headline breaches, but smarter attackers. Here’s what the numbers mean for gambling operators.
The Security 10
GamblingIQ presents the people protecting the gambling industry: the security leaders shaping defences, strategy and trust at the highest levels.
Timeline of an Industry Legend
+ 1950s
Michael was born in a US-Canada border town, growing up in rural southern Quebec, south of Montreal
+ 1970’s
Graduating from McGill University he began a career in Business, Accountancy and Entrepreneurship specialising in technology and real estate
+ 1990s
While working as a Chartered Accountant, Michael spotted an unmet need in data centre services. That initial spark became Continent 8, founded in 1998
+ 2024
Recognised for his contributions to the global gaming industry, Tobin was honoured at the SBC Summit North America and inducted into the Sports Betting Hall of fame
Michael Tobin
Founder & CEO, Continent 8 Technologies
To customers, Continent 8 appears as a single ecosystem. To the company, it is a choreography: hundreds of sites, thousands of regulatory rules, and an operational burden that Michael Tobin likens to “a global orchestra where every instrument must play in perfect harmony.”
Sustainability, too, has become part of that orchestration. The company’s ISO 50001 certification for energy management demanded new cooling strategies, renewable supply, and something less tangible: a cultural shift that asked engineers to think about efficiency as much as performance.
The 8th Continent: How Tobin Built an Empire
Responsible
Long before he became a Hall of Fame name in global gaming infrastructure, long before Continent 8 Technologies stitched together a private network spanning more than a hundred locations, Michael Tobin was an eightyear-old child in southern Quebec, Canada, negotiating the purchase of his cousin’s newspaper route for $8. It was, in retrospect, a child’s first lesson in risk: a few coins, a small bet, and the first spark of the entrepreneurial instinct that would animate everything that followed. Born in the 1950s and raised near the US border, Tobin imagined a life in numbers. He studied at McGill, after turning down, he notes with a certain dry amusement, an offer from Harvard, where he would have been in Bill Gates’s class. But the safer world of accountancy did not keep him for long. In the late 1990s, as he worked among financial services, real estate and technology clients, Tobin noticed a rising, unaddressed demand for digital infrastructure, particularly data centre capacity. The Internet, then still spoken of with a sense of wonder, was not yet a continent, but it felt like one forming in the .com era. “The idea just hit me,” he says. “There are seven continents. The eighth was being formed by the Internet.” Continent 8 was born in 1998, created to serve financial services before veering, almost serendipitously, into online gaming. An early opportunity with an online gaming pioneer redirected the company’s trajectory. The pivot set Tobin’s course as much as his company’s: he would become one of the defining infrastructure figures in an industry obsessed with latency, uptime, and regulatory precision. The company’s first year was part improvisation, part baptism. Tobin recalls the early days of advising the Kahnawake Mohawks in Canada when the newly regulated gaming world arrived in torrents rather than trickles.
“The idea just hit me,” Tobin says. “There are seven continents. The eighth was being formed by the Internet”
Continent 8 rapidly built out a global business, launching in new jurisdictions across Europe such as the Isle of Man, Gibraltar and Malta, constructing their first data centres. “But luck only gets you so far,” Michael says. “Retaining customers is vital, that’s about being agile in recognising market opportunities and ensuring you deliver a brilliant solution and service. We have customers on our books today that have been with us from the very start, the likes of Microgaming and Playtech – we have grown together over the last few decades.” If Continent 8 had an inflection point, it happened in the Isle of Man. “In all honesty it wasn’t our first choice, we looked at Guernsey, Jersey, Ireland. But it was Microgaming that made the necessary introductions for us to set up on the Island. One of the first people I met was Alan Bell, Treasury Minister at the time, (who became the Chief Minister) for the Isle of Man Government. He was an important factor in us coming here. We still very much see the Island as a home for Continent 8; we have a smart, capable team in our office, working closely with our global team.” As gaming went mainstream, so did cyber crime. Tobin had been anticipating digital threats as early as the 2000s, when the firm launched its DDoS mitigation service to protect their growing global network and locations. But the scale changed. Christmas 2022, following a World Cup final that had strained global operators, brought one of the largest “carpet bomb” attacks the ‘Net had seen, nine days of sustained targeting across 145 customers. It was a breaking point. “Security could no longer be an add-on,” he says. C8 Secure, the company’s managed security services division, and now Threat Exchange, is his answer: protection, detection and response woven directly into the same fabric that delivers gameplay. As he looks ahead, Tobin sees AI as the industry’s next great test and opportunity. “Fraud detection, compliance, risk scoring, infrastructure that scales itself, much will disappear into automation. Trust, however, will remain stubbornly human,” he says.
28 years of Reliability
Reuter
1998, Continent 8 is Established 2002, Strategic Pivot to iGaming
Having identified a growing demand for data centre services while working as a Chartered Accountant, Michael Tobin established Continent 8 to serve the financial services sector
A key opportunity with an early online gaming pioneer led Continent 8 to shift its focus toward the iGaming and online sports betting industry
2004, DDoS Mitigation Launched
Recognising that the digital revolution would lead to cyber crime, Continent 8 launched DDoS protection
2006, Isle of Man Operations
Following Microgaming introductions, Tobin formally set up the Isle of Man entity, which became a strategic hub for global expansion. It’s state-of-theart data centre hosts some of the largest iGaming brands to this day
2010s, Global Expansion
Under Tobin’s leadership, Continent 8 expands into major iGaming regions such as Malta, Gibraltar, and later into the US, Asia, & LatAm
2019, Atlantic City Data Centre
As it begins to power US sports betting, the company opens its New Jersey data centre partnering with the State’s Casino Reinvestment Development Authority, bringing a new era of world-class tech infrastructure
2020s, Cybersecurity & C8 Secure Tobin spearheads the launch of C8 Secure, a division focused on advanced cybersecurity solutions, including threat prevention, detection, and response across multiple industries
Michael Tobin, Speaking at SBC Summit North America
Introducing
Threat Exchange
By Continent 8
Inside the new cyber-intelligence platform with Patrick Gardner, Chief Security Officer, Continent 8 Technologies
For almost 28 years, Continent 8 Technologies has built a global network that nobody in the industry can match, one that monitors traffic across regulated gambling markets in Europe, North America and Asia. That long-held vantage, Patrick Gardner says, has made it increasingly clear that the company’s data could be used for far more than infrastructure oversight; not just to store logs, but to transform them into genuine, actionable intelligence. Enter Threat Exchange: “Continent 8 sits in a unique position to observe patterns, anomalies and threats across a global footprint,” Gardner explains. “With the right tools, we realised the data could become a powerful intelligence product. That’s how Threat Exchange was born, from the idea that shared intelligence makes everyone stronger.” The launch of Threat Exchange arrives amid a sharp escalation in the commercial cost of cyber-incidents in the gambling sector. Over the past five years, operators have seen both the frequency and sophistication of attacks rise, and the financial consequences have followed. Gardner cites the 2023 MGM Resorts breach as emblematic: attackers used social engineering to gain access “within ten minutes”, precipitating ten days of disruption and an estimated $100m hit in lost revenue and remediation. “For brands like BetMGM even short-lived outages during major sporting events can translate into millions in missed wagers.”
- That’s how Threat Exchange was born, from the idea that shared intelligence makes everyone stronger -
Vendor compromises are an equally troubling vector. The reported supplier breach that prompted Caesars to pay what was described as a multimilliondollar payment underlines a painful reality: “The weakest link in the chain is often outside your own perimeter, and it’s often human error,” Gardner warns. That externality, he argues, is central to modern incident economics, when suppliers hold privileged access, a single failure can cascade. Threat Exchange is presented as a cyber threat intelligence (CTI) platform, but its purpose extends beyond a standalone feed. “It doesn’t sit in isolation,” Gardner says. “It feeds realtime intelligence into our SOC, enabling analysts to detect and respond faster, and it enriches our MSSP services so protection scales across every customer environment. Threat Exchange provides the insight, our SOC delivers the action, and our MSSP ensures it reaches the whole estate.”
- Customers receive updates often while the attack is still under way elsewhere. It gives them precious time to block those same sources. It’s early warning in action -
Continent 8’s telemetry suggests a dramatic escalation: a 400 per cent rise in security incidents in recent periods. Gardner describes the figure as “staggering, but no surprise.” The sector’s attractiveness is plain — operators process high volumes of transactions, retain sensitive customer data, and must remain online around the clock — and those characteristics, combined with regulatory complexity, make gambling platforms prime targets. Meanwhile, automation and generative AI are enabling adversaries to scale attacks and refine socialengineering rigs. “Ransomware gangs are doubling down on big-game hunting,” Gardner says, “while credential stuffing spikes during major sporting events, when traffic provides cover.” The differentiator, he adds, is speed. Threat Exchange is designed to convert observation into early-warning. “When a DDoS attack begins anywhere across our network, we see the malicious IP addresses in real time,” Gardner explains. “We inject that data directly into Threat Exchange. Customers subscribing to high-confidence indicators receive updates immediately — often while the attack is still under way elsewhere. It gives them precious time to block those same sources. It’s early warning in action.”
Continent 8 Chief Security Officer, Patrick Gardner, pictured above alongside a detailed view of Threat Exchange, iGaming’s first dedicated cyber-intelligence platform. Gardner tells GamblingIQ: “Continent 8 handles a very large share of global iGaming data flows, but we always emphasise the limits: we only see what takes place within our own data centres. Our customers operate their own corporate networks and security teams with intelligence we don’t see directly. The Threat Exchange is designed to bridge those blind spots.”
A first
for Gambling: Threat Exchange delivers collaborative cyber intelligence
This is the first cyber threat intelligence (CTI) platform built for gambling. Threat Exchange is a real-time feed of indicators, actor profiles and automated investigations designed to turn the company’s unique network visibility into operational defence. Let’s break down the benefits for response teams, operators, platform providers, and regulators:
1. Happening Now: The platform delivers real-time platform-specific IOCs, threat-actor profiles, attack-vector mapping and event-focused analytics (for example: peak-traffic sporting events) so teams can prioritise what matters for uptime and wagering integrity. That vertical focus is the product’s headline USP.
2. Depth of Signals: The Exchange processes billions of signals every day and includes automated investigations to cut alert fatigue. Practically, that means correlation across DDoS telemetry, phishing domains, known malicious IPs and anomaly patterns generated by honeypots and sensor networks. The stated aim is to reduce false positives and push “high-confidence” indicators to customers so triage teams can act rather than sift.
3. Intelligence feeding security operations centre (SOC) and managed security service provider (MSSP) workflow: As an intelligence engine, the practical value is latency reduction: when an indicator appears on the Exchange, defenders can block or investigate before an attack escalates, a must in an industry where minutes of downtime equal tangible revenue loss.
4. Collective Defence: Operators can collaborate by contributing indicators manually (an analyst logging a phishing campaign) or automatically via anonymised telemetry from managed SOCs and integrations. Continent 8 frames this as “community immunity”: shared observations are redistributed to subscribers, enabling peers and regulators to detect reuse of infrastructure and recurring actor tactics.
5. Strategic: Threat Exchange addresses visibility and speed, two pressing gaps in modern cyber defence and what CISOs should do now. An organisation’s operational needs and cybersecurity maturity can be met with different tiers, right up to advanced High-Roller tiers offering predictive analytics and premium features.
Real Power Plays: Threat Exchange in Action
+ Event-Based Security: Attacks exploit peak betting surges and operators should treat major tournaments such as the upcoming World Cup finals as cyber-risk seasons. The Continent 8 service includes platform availability protection which means proactive detection of attacks on live betting feeds and third-party data providers during critical trading periods.
+ Multi-Vertical Operators: Cross-vertical correlation exposes patterns that siloed teams miss; unified intelligence ensures attackers can’t pivot between sportsbook, casino, and poker unnoticed. Also Continent 8 offers group-wide security posture for SOC teams managing multiple brands
+ Online Casinos: They must prioritise payout protection and threat actors increasingly target liquidity points, meaning financial infrastructure is now as attractive as gaming logic. Threat Exchange offers real-time monitoring of DDoS indicators targeting game servers and track ransomware campaigns. It also offers infrastructure protection with early warning for exploits and reconnaissance against systems.
+ B2B Gaming Providers: Hot topic - essentially Threat Exchange offers supply chain defence with a comprehensive monitoring of threats to white-label platforms and gaming APIs affecting downstream operators.
3 Secrets to Success
By Michael Tobin, Founder & CEO,
Continent 8 Technologies
Michael Tobin approaches infrastructure and cyber security with an accountant’s discipline and a founder’s instinct; part engineer, part strategist, part quiet contrarian who saw the Internet early for what it was: the “eighth continent,” a territory to map, colonise, secure and scale. He builds patiently, reads markets shrewdly, and treats reliability not as a feature but as a moral obligation, where others chase speed or spectacle. Below, Michael shares the three principles that have guided Continent 8’s rise from a single data centre to over 100 global locations and a regulated private network; rules forged in risk, resilience and the hard, daily work of keeping the Internet’s most demanding industry online.
1
What is your advice for the next generation
of entrepreneurs?
Partnerships. Mentors. Community. People. It’s people that make the difference. Talk and continuously learn.
2
Growth, Markets & Scale: You’ve expanded globally. What is your playbook for entering a new regulated market?
Entering a new regulated market is never a one-size-fits-all process. Our conversations when building out our Atlantic City data centre in partnership with the New Jersey Government would be very different to launching in Brazil.
We like to get ahead of regulation by working closely with regulators from the outset. And we build relationships throughout in terms of local partners, and of course customers, understanding their needs and if the market is viable.
3
What’s your operational advice about managing the 100+ site Continent 8 network?
It’s both a privilege and a challenge! The biggest operational headache I think, is maintaining independence, absolute consistency in performance and compliance across such a diverse footprint. Each jurisdiction has its own regulatory requirements, connectivity nuances, and physical infrastructure constraints.
Coordinating upgrades, security patches, and monitoring across multiple time zones while ensuring zero downtime is complex. Add to that the need for real-time threat detection and responseit’s like running a global orchestra where every instrument must play in perfect harmony. Our approach relies on automation, centralised monitoring, and a highly skilled team distributed globally to keep everything synchronised.
LEADING FRAUD PREVENTION & MANAGED SECURITY SERVICES
CRITICAL Mission
The Gambing industry has been the No. 1 targeted sector for four consecutive years. And given that it operates continuous uptime, fraud prevention and managed security services (MSSPs) are mission-critical. All gambling operators worth their salt rely on MSSPs for 24/7 SOC monitoring; Incident response; Log correlation; DDoS defence and threat hunting. The companies listed in our annual map collectively save operators billions each year. According to the latest Gambling IQ data, the global online gambling industry saves an estimated $15 billion annually via anti-fraud and security companies who are preventing huge losses. AI-driven fraud detection is now helping to reduce human error and allows operators to stay a step ahead of increasingly sophisticated fraud tactics.
> There has been a 4000% increase in cyber incidents impacting both online & land-based casino operators over the past 12 months >
Companies like Sumsub, GeoComply, Persona Jumio, and GBG are well-regarded for their advanced fraud prevention methods and comprehensive player verification solutions. Their security systems use various strategies including real-time transaction monitoring, behavioural analysis, and multi-factor authentication. AI and machine learning have greatly enhanced these companies’ abilities to detect and prevent fraudulent behaviour by analysing user patterns, device data, and betting trends to identify suspicious activity quickly and accurately. For instance, the Sumsub full cycle protection mode uses AI for identity verification through biometric checks, ensuring players are legitimate without interrupting their gaming experience. Meanwhile, GeoComply specialises in geolocation technology and machine learning with device fingerprinting and behavioural analytics.
Gambling IQ estimates global fraud losses nearing $1.6 billion in 2025. Alongside fraud, money laundering risks and regulatory penalties are on the rise. In 2025, the Dirección General para el Ordenación del Juego (DGOJ) in Spain issued €77.4 million in fines on 14 unlicensed operators. The DGOJ imposed fines ranging from €5 million to €10 million per unlicensed operator for distributing gambling services without licence.
In 2024, global merchants are expected to contend with an estimated $100 billion in Chargeback claims. Factoring in additional hidden expenses like administrative and operational costs, businesses are paying nearly four times the disputed amount. The average cost of a single chargeback claim has risen to around $190, underscoring the financial impact of disputes that reach well beyond the initial transaction.
$15bn
The cost per minute for operators during down time caused by
THE FIRMS ENSURING SECURE GAMBLING EXPERIENCES IN 2026
On average, 7.6% of all online casino bets worldwide will be linked to fraud
EDGE GEN AI
By integrating sophisticated AI-driven algorithms, anti-fraud leaders are identifying inconsistencies in digital media, making it significantly harder for fraudsters to use AI-generated content to bypass security checks. This helps ensure more secure and reliable player identification, protecting both users and operators in the iGaming industry.
*
Here’s how iGaming fraud impacts the industry, which underscores the urgent need for robust digital ID & fraud prevention in the sector.
Regulatory fines are on the rise
Increased fraud rates lead to higher operational costs and forces the platform to implement stringent security measures, such as enhanced player verification protocols. However, these changes can cause friction for some users, resulting in a loss of customers to competitors with stronger fraud prevention systems.
In 2025, the UK Gambling Commission issued around £18million in penalties against 12 iGaming operators; the largest single fine went to Platinum Gaming for serious anti-money-laundering (AML) and social-responsibility failures. Resorts World Las Vegas was hit with a US$10.5m fine for AML compliance failures and Caesars Palace was fined US$7.8m over an illegal bookmaker case, failing to verify the source of funds of a convicted bookmaker
Revenue & Processing Costs
FINES LOSSES
Financial Losses: Chargebacks, theft, and fraudulent transactions lead to costly financial hits for operators. Each instance of fraud not only impacts operators’ revenue but also increases processing costs due to handling these reversals. As fraud becomes increasingly complex, iGaming operators are investing more heavily in anti-fraud measures, aiming to safeguard their revenue and maintain compliance.
Fraud causes player concern
REPUTATION
In September 2023, Stake, a prominent crypto gambling platform, suffered a significant security breach, resulting in a $41 million theft. The hack, attributed to North Korea's Lazarus Group, exploited vulnerabilities in the platform's hot wallets. While Stake's team acted swiftly to contain the breach - the incident caused considerable reputational damage.
Everybody Loves Kris!
(...and his annoyingly brilliant thought leadership)
+ How BEHAVIOUR outwits IDENTITY
Operators must design defences like ecosystems not firewalls: “Sumsub Device Intelligence exposes device reuse, multi-accounting, collusion networks, and coordinated behaviour patterns long before they surface in transactions. It’s about early exposure rather than late-stage remediation”.
+ Fraud Teams need an OVERHAUL
“Old structures where fraud teams are stretched across detection, review and remediation no longer work. Instead, specialist squads are required - detection engineers, payments analysts, behavioural data scientists and human-review specialists working side-by-side. Regular redteam exercises should be the norm, simulating everything from deepfake onboarding to telemetry injection attacks.
+ Hard METRICS on Dash Boards
“Among those who actually measure their losses, 47% admit that 10% of their revenue disappears due to fraud, and 15% say it’s more than 20%. Those are brutal numbers. The antidote is to make median time-to-detect, average fraudulent cash-out and chargeback cost routine board metrics.”
+ Payment RAILS Instrumental
Micro-pattern analysis, rapid chargeback triage and BIN-level anomaly detection: “Payment-method fraud now outpaces document spoofing in pockets, and that requires a shift: onboard-and-forget is no longer safe, payments and KYC must be a single pipeline”.
Kris Galloway
Head of iGaming Product, Sumsub
+ Trust as a BRAND differentiator
Trust will not be a regulated metric in 2026, Kris says, but it will be a brand differentiator. Operators that can show players and regulators they have adopted continuous assurance, transparent models and industry-shared indicators will win market trust. “Trust won’t become a regulated metric in 2026,” Kris says, “but it will be defined by how clearly an operator can demonstrate transparency, safety, and integrity.”
The former Poker Pro showing iGaming how to call a bluff
Kris Galloway carries the unassuming swagger of someone who has spent a decade plus inside the business of play. He tells you first that he used to make his living at the poker table. “I was a professional poker player in my early twenties before realising I probably needed an actual job,” he admits. That admission, half joke, half confession, explains the curious blend of instinct and analysis that defines his approach: a gamer’s sixth sense married to a product manager’s unapologetically nerdy appetite for systems. And it shows in his work. He is as comfortable deconstructing betting sequences as he is explaining the poetry of a good UX flow. “Fraud isn’t a single event any more,” he says. “It behaves like an ecosystem, once someone gets through the door, everything else follows.”
Kris is capable of speaking in crisp product sentences, (‘device intelligence’, ‘session sequencing’, ‘multi-account graphs’), yet what grounds the tech-speak is his empathy for players. He still plays ARC Raiders and Rocket League, partly for fun. “Playing keeps you honest. You see the little tells, the microbehaviours.”
He has watched fraud mutate from clumsy bots into an arms race fuelled by AI. “When image-generation tools became mainstream, people suddenly believed they were master forgers. AI lowered the barrier to entry, now you get volume as well as ingenuity,” he says. Kris warns that major events like the World Cup, act as accelerants for coordinated abuse. “These are the times fraudsters synchronise,” he says. “They exploit attention, inflows and the human tendency to relax controls.” Beyond the tech lexicon, he is adamant about practical priorities. “Boards ask for dashboards; they rarely ask what we’re actually blocking,” he says. His point is simple: metrics must map to money. He wants median time-to-detect and average fraudulent cash-out visible alongside NPS and CAC. “If you can’t show the cost in money, you won’t get budget,” he adds.
‘ The most important conceptual shift operators should understand is the move from identity to behaviour. Identity is the bank door. The real crime happens inside ’
Kris believes the human element remains non-negotiable. “Machines triage; people adjudicate,” he explains. His teams run quarterly red teams that simulate deepfake onboarding and telemetry injection; those exercises, he says, are the acid test for any vendor. He returns to a comparative advantage born at the poker table: patience. “The best players read the room. In product, patience turns into calibration; and calibration beats panic.” He wants teams that can tune thresholds weekly and learn from each incident to make future detection more precise and less disruptive, and resilient.
He has seen the battlefield up close: the tournaments of emergent fraud where amateurs and syndicates play in the same arena. “As we head into a World Cup year, fraud isn’t just rising, it’s accelerating.” The calendar is tactical, global events concentrate attention, deposits and opportunity, and criminals respond. He frames the problem clearly: AI has democratised techniques once the preserve of elites.
Image-generation tools produced a spike of would-be forgers, and the result is a two-tiered threat: professional syndicates still orchestrate complex laundering channels, but millions of amateur miscreants now supply volume. “AI has lowered the barrier to entry so much that amateur fraudsters now present as much of a problem as the pros.” The most important conceptual shift he wants operators to understand is the move from identity to behaviour. “Identity is the bank door. The real crime happens inside”. Once a bad actor gets through onboarding, whether with a synthetic ID, a purchased identity or a direct deception, behaviour reveals intent.
Poker Face: Kris Galloway, Head of iGaming Product Sumsub: “I was a pro poker player in my early twenties before realising I probably needed an actual job. So I wrote to PokerStars, got hired, and fifteen years later I’ve worked across Flutter, Entain and a stack of major brands in roles spanning product, marketing, innovation and anti-fraud.
Winning
Expanded transaction monitoring
Sumsub expanded transaction monitoring in 2025, enabling real time detection of bonus abuse, money laundering, collusion, betting systems and session patterns, with deeper pattern and session analysis planned for ‘26.
Device intelligence sharpened
Sumsub strengthened device intelligence, deploying deep device fingerprinting, geolocation verification and behavioural signals to trace root devices, detect emulators, multi account webs and hardware manipulation, improving syndicate disruption for operators.
Historic documents unearthed
Advances in historic document analysis now let Sumsub surface affordability risks, flagging benefit payment indicators and other hidden signals in old KYC and financial paperwork to inform rapid remediation decisions. Using OCR and multilingual ML models to extract, normalise, and validate data fields, including MRZ, barcode, NFC, and hologram features.
Preparing for next-gen threats
Sumsub combines legal expertise, partnerships and rapid product innovation to anticipate next generation threats, XP farming, PvP, social exploits, promotional abuse, and design mitigations, adaptive controls before attacks scale globally.
Best Industry operational expertise
Sumsub’s team now includes veterans from Flutter, Entain, Betway and developers, enabling bespoke tools that reflect regional nuances, generational behaviours and legal fragmentation.
Milestones According to Galloway
The Fraud Farm Threat
Sumsub’s Kris Galloway on the five criminal business models behind today’s mass account attacks
Fraud has ceased to be a cottage industry. In 2025 it resembled assembly-line production: networks of talent, tooling and logistics that manufacture and launder identities at scale before they touch an operator’s ledger. “The big syndicates are still expanding,” says Kris Galloway, Sumsub’s chief product officer, “yet the number of individual ‘fraud pawns’ has exploded.” The effect is binary: operators face organised rings and opportunistic solo actors moving faster than legacy controls can respond.
Sumsub’s answer is deliberately industrial. Where once KYC was a post-signup checkbox, the firm now places pre-emptive sensors across the customer lifecycle. “In 2025, one of our biggest leaps was expanding transaction monitoring for gambling operations, allowing us to identify suspicious behaviour at both session and betting level,” Galloway says. That change exposes bonus abuse, collusion and laundering flows in near real time; Sumsub plans deeper session-pattern analysis in 2026, tracking micro-patterns within single-player sessions and cross-account correlation.
The technical stack reads like a catalogue of contemporary anti-fraud craft: deep device fingerprinting, geolocation triangulation, behavioural telemetry, real-time risk scoring and AI-assisted case orchestration. “We leverage deep device fingerprinting, geolocation checks and behavioural signals to trace the root devices behind fraud rings,” Galloway explains. Those signals routinely unmask emulators, multi-account webs and hardware-level manipulation that simple IP blacklists miss. The same feeds power Sumsub’s AI case manager, which “organises the case, surfaces the signal, and tells the analyst, ‘This is why you’re looking at this user’,” shortening investigation time and improving consistency.
Scale matters. Sumsub’s 2025 identity-fraud study analysed millions of verification checks and more than four million fraud attempts between 2024 and 2025; its iGaming report separately examined over three million attempts and surveyed more than 100 operators, producing sector-specific insights.
The firm’s headline metrics are blunt: 4,000+ clients in 220+ countries; support for 14,000+ document types; non-doc verification in as little as 4.5 seconds; and reusable ID workflows that cut onboarding
Industrial Identity / KYC farms
Organised onboarding call-centres that produce bulk fake IDs and resell verified accounts — typified by the Manila raids in 2025 that netted 400+ suspects from alleged scam farms supplying forged identities to online schemes
Affiliate–Influencer Networks
Influencers and affiliate webs funnel farmed traffic into promos; Brazil’s 2025 probes (Tainá Sousa, Bia Miranda and others) exposed influencer-driven affiliate networks promoting illegal casino products and moving funds via intermediary wallets
Account-rental marketplaces
Black-market services that lease verified accounts for syndicates and insider play — mirrored by 2025 U.S. and platform investigations into account-rental schemes (eg. national account rental trends affecting gig platforms), revealing similar mechanics.
Syndicates & collusion rings
Organised groups manipulating markets and bonuses; 2025 sports-betting scandals and law-enforcement inquiries showed coordinated multi-account play and suspicious correlated stakes across fixtures, prompting regulator probes.
AI as a Service Fraud Shops
Commercial sellers of deepfake selfies, voice clones and synthetic IDs fuel KYC bypassing. UNODC reported agentic-AI scams and transnational scam-centre networks exploiting coerced workers.
time and boost conversions. Those figures are not vanity, they are training data for models that see patterns operators cannot.
Thai law enforcement stepped up sweeps, seizing substantial assets, blocking tens of thousands of illicit URLs and arresting networks with financial links to border hubs such as Poipet; Bangkok raids recovered millions of baht and disrupted nominee layers used to launder stakes. The tactics are familiar: social promotion, intermediary wallets, and rapid cash-out routes that turn player flows into cleanable revenue streams.
Those episodes underline two hard lessons. First, fraud farms are social and economic phenomena: call centres, influencer networks and “fraud pawns” respond to incentives, not merely to software vulnerabilities. United Nations reporting and regional enforcement trackers document scam centres expanding into recruitment hubs, tying local unemployment and weak governance to transnational cybercrime. Second, defenders must be organisationally fit. Sumsub has instrumented detection, investigation and remediation as a continuous loop; detection feeds triage, triage feeds human review, review feeds model retraining.
Galloway is candid about limits. Technology surfaces signals and automates routine work, but the choice of where to add friction is commercial and political. “Zero fraud usually means overly strict controls and excessive churn; zero controls means chaos,” he says. Sumsub’s market is the pragmatic middle ground: calibrate controls, provide the analytics to justify them, and preserve compliant growth.
Practically, that translates into playbooks as much as code. Sumsub runs red-team exercises simulating deepfake onboarding and telemetry injection, embeds domain experts into operator teams and engineers signals that reflect regional regulatory idiosyncrasies and promotional behaviours. Staff with operator pedigrees make alerts operationally useful rather than academically pure.
Concrete cases in 2025 made the mechanics of farmed fraud visible. In Brazil, police operations targeted influencer-driven affiliate networks promoting slot-style games such as “Jogo do Tigrinho.” Prosecutors arrested promoters including Tainá Sousa; vehicles were seized and profiles removed after investigators traced Pix payment rails into intermediary wallets and shell companies. Separate inquiries in São Luís and São Paulo disrupted affiliate webs alleged to have moved millions through payment intermediaries into offshore accounts. Those proceedings exposed how influencers, affiliates and call-centre operators form a single supply chain. In Southeast Asia the scale was similar. Sumsub.com
In an era of agentic AI and fraud-as-aservice, Galloway’s prescription is blunt: “Industrial-scale fraud needs industrial-scale defence.” For now, Sumsub has assembled both the sensors and the playbooks to meet it.
STORIES FROM THE FIELD
Selfies Gave the Game Away: How reused backdrops exposed a bonus-abuse fraud ring at scale
“Our analysis grouped the accounts, exposed the network, and gave the operator the evidence to shut it down, and redesign their defences to stop anything like it ever happening again.
An operator arrived at Sumsub after a baffling spike in bonus abuse. They had used a different identity provider; that vendor’s checks all returned green— documents authenticated, selfies matched—yet promo theft surged. On paper everything looked fine. “We were handed a dataset that looked pristine,” says Sumsub’s Kris Galloway. “The previous provider validated documents, but their checks treated identity as a one-off event. They missed cross-account signals we consider fundamental.”
Sumsub reprocessed the operator’s onboarding and session logs within 48 hours. Device telemetry, image metadata and session traces revealed the pattern: dozens of verified users submitting selfies in the same room—identical walls, lighting and camera angles. Further clustering linked those accounts to intermediary wallets and repeat cash-out paths.
The apparent legitimacy hid a recruitment scam: people tricked into sharing documents for fake ‘jobs’, whose profiles were then sold to syndicates for organised promo abuse. Sumsub supplied a triage feed, collapsed related accounts into investigative queues and activated mid-session liveness checks on high-risk clusters. The operator closed compromised accounts, reversed suspect payouts and froze implicated affiliate contracts.
Longer term, they shifted from discrete, post-event checks to continuous, multi-signal monitoring. They implemented reused-background detection, dynamic verification, and stricter affiliate vetting, integrating device fingerprints, payment pathways and session analytics into a single playbook.
“Once you treat identity as continuous context, the network opens up,” Galloway says. The operator regained margins and reduced false positives; more importantly, its defences were rewritten, not merely repaired. “This wasn’t a one-off fix,” he adds. “It was a rewrite of how they think about identity: from a document event to a continuous, contextual signal.”
SUMSUB NAMED GARTNER LEADER AGAIN
Sumsub was named a Leader in Gartner’s 2025 Magic Quadrant for Identity Verification for the second year in a row, recognised for product innovation, RiskOS and reusable-ID advances that expanded its verification and AML suite, including sub-5-second non-doc checks and transaction monitoring.
Market Insights
4,000+
Clients in 220 Countries
Sumsub was founded in 2015, and in just over a decade it is now trusted by 4,000+ clients across 220+ countries and territories, supporting fintech, crypto, iGaming and marketplace platforms at scale.
Split-Second User Verification
Its Non-Doc workflow delivers identity decisions in as little as 4.5 seconds using device intelligence, database triangulation and risk modeling, enabling higher conversions.
Reusable ID Boosts Conversions
The Sumsub reusable ID suite can halve onboarding time and lift iGaming conversions by 30%, leveraging tokenised identity credentials, cross-platform interoperability, and automated risk decisioning to minimise friction and repeat KYC.
Major Support for document types 14K+ to be exact. Using OCR and multilingual ML models to extract, normalise, and validate data fields, including MRZ, barcode, NFC, and hologram features.
Leader in iGaming Research
Sumsub analysed an impressive 3M+ fraud attempts in its 2025 iGaming research. The company publishes a ‘State of Identity Verification’ in the iGaming Industry annually, drawing on internal data and survey responses.
2026 Prediction: Black Markets Force a Rethink of Gambling Regulation
“If I had to make one bold bet for 2026, it’s this: the black market will force the entire industry, regulators, operators, and suppliers, to finally take notice.” This is the forecast from Kris Galloway, who argues the warning signs are already here, with regulators and industry bodies indicating that unlicensed and grey-market operators are capturing a growing share of European play.
“You can already see who’s winning the younger audience,” he notes, pointing to rising appetite among under-18s and the ease with which black-market platforms reach them, often endorsed by online personalities and available without VPNs. Policies introduced in isolation, such as lifting minimum gambling ages in some countries, “don’t reduce demand, they redirect it to unregulated sites.”
His bet is clear: “2026 is the year regulators and operators finally sit at the same table, acknowledge the unintended consequences of fragmented policy, and build defences that compete on innovation, not paperwork.” And if that doesn’t happen? “That failure will be the story of the year,” Galloway says.
World Cup Defence
Threats Operators must tackle to defend profits this summer
The World Cup presents a paradox for regulated iGaming: a moment of unparalleled commercial opportunity that also concentrates systemic risk. For operators, the tournament is not merely a marketing calendar highlight; it is a stress test of identity systems, payment rails and risk orchestration. A sudden influx of customers, large bet sizes and novel market offerings combine to increase attack surfaces and magnify the downstream effects of seemingly small breaches. The following analysis sets out the top five fraud threats for the 2026 tournament and translates each into concrete operational challenges and mitigations for operators that prize trust as a product.
First Mobile Fraud World Cup in Brazil
56%
PEAK EVENT FRAUD
More than half of annual fraud surges cluster around major sporting events.
+ Identity attacks rise 30–70% on high-traffic match days.
+ Automated login attempts can triple within one hour of kick-off.
+ Cash-out fraud peaks immediately after unexpected match results.
Fraud attacks on betting accounts increased by an estimated 30–35% during the tournament window.
First major surge in bot-driven bonus abuse and low-quality account creation at scale during Brazil World Cup 2014. Bot-Driven Abuse
2026 FORECAST
North America - Biggest Target Yet: With expanded teams, global visibility, and unprecedented betting liquidity, risk concentration will peak. Fraud attempts expected to exceed 2022 levels by 90–120% during peak match days. Major exposure anticipated from fake World Cup ticketing websites feeding identity fraud pipelines. AI-scaled bots, automated arbitrage and real-time odds exploitation expected to dominate. Operators with weak onboarding provenance face high-volume mule infiltration within days of kick-off.
Credential-stuffing goes mainstream. Automated login attacks surged by up to 60% during groupstage matches. First notable use of synthetic IDs
Document-fraud attempts rose by 80%. Deepfake selfie submissions became a new frontline challenge. Qatar
Operators saw record traffic during Qatar, which masked multi-accounting syndicates operating at scale. Syndicates
2030 FORECAST
Jointly hosted by Morocco, Portugal, & Spain, trust will be a strategy, not a compliance checkbox. Operators who invest in resilient identity and payment stacks will outperform. Modelled reductions of 40–50% in loss rates where behavioural biometrics + document provenance systems are fully deployed.
Market winners will be those who treat trust as a feature—minimising friction for clean customers while escalating intelligently for risk.
CREDENTIAL SURGE
Compromised email–password pairs flood the market during tournament 300%
+ Drives mass account takeover attempts.
+ Enables bot-driven bonus abuse and rapid withdrawals.
+ Operators see ATO alerts spike by up to 60% in group stages.
Deepfake Selfies appear in Qatar
DOWNSTREAM IDENTITY FRAUD FROM FAKE WORLD CUP TICKET
Why it Matters?
Demand for tickets outstrips supply and a lucrative ecosystem of resale and fake ticket vendors proliferates. Fraudsters harvest and monetise identity documents submitted to these counterfeit sites — scanned passports, driving licences and selfies — and then reuse them to pass Know Your Customer (KYC) checks at betting sites. The impact is downstream and often invisible: an operator’s KYC pass rate improves, but the accounts belong to third-party fraud rings or money-laundering clients.
How it applies to Operators
Operators face increased onboarding of accounts that appear legitimate on paper but are sourced from compromised identity pools. The most immediate risks are identity reuse across multiple accounts, synthetic identities combining real and fabricated elements, and subsequent misuse for high-risk transactions or mule activity.
Countermeasures
Treat onboarding provenance as a first-class risk signal: enrich KYC with device and behavioural telemetry, cross-check ID selfies against liveness and contextual indicators (e.g. recent ticket purchases from suspicious domains), and adopt consortium-style «proof of provenance» feeds with ticketing platforms where possible. Flag and quarantine accounts with IDs that match patterns typical of resale-site leakage and require stepped-up verification before permitting withdrawals.
The most effective defenders in the 2026 World Cup will be those who combine technology with cross-industry collaboration, turning the tournament’s torrent of data into an advantage rather than a vulnerability.
Collaboration is Security
Multi-Accounting, Syndicated bonus abuse
Why it matters? Tournament promotions and zero-risk offers attract organised rings that open multiple accounts to farm bonuses and shift winnings through internal cash-outs. These operations are increasingly automated and able to mimic normal play patterns.
How it applies to operators: Bonus liability swells, margin is eroded and detection backlogs increase during peak match windows. Traditional rule-based systems suffer poor precision under tournament load.
Countermeasures: Move to probabilistic identity graphs that fuse device fingerprints, payment tokens and behavioural markers to detect clusters of linked accounts. Apply promotion throttling by risk cohort, introduce staggered bonus release tied to verified play, and run adversarial simulations pre-tournament to tune detection thresholds.
Market Manipulation & Suspicious Betting Patterns
The expanded 48-team format in the World Cup creates more niches where anomalous liquidity can distort prices. Bad actors may attempt small, targeted manipulations to exploit in-book exposures or launder funds via hedged positions. Operators risk financial loss through exploited odds and face integrity investigations if
Darknet and resale marketplaces offer a new, fast-moving pipeline: scanned passports and driver’s licences handed over to fraudulent World Cup ticket vendors are being re-sold to organised betting rings. Security researchers say the data is already being repurposed to pass KYC checks at regulated operators, enabling high-value accounts, rapid withdrawals and sophisticated bonus abuse ahead of the 2026 tournament. Ticket customers, not bookmakers, are the weak link — but the financial consequences are immediate for operators.
Why it matters? The tournament’s surge in staking volume attracts layered money-laundering attempts: rapid small deposits across many rails, use of e-wallets with weak KYC, and pre-paid instruments purchased via compromised cards.
How it applies to operators: Regulatory fines and licence jeopardy are real outcomes when systems fail to detect laundering typologies. Operationally, the strain of resolving disputed transactions during the event is costly.
Countermeasures: Harden payment acceptance by prioritising trusted, KYC-verified rails; apply behavioural scoring to payment flows (account age, deposit cadence, correlated device artefacts). Build cross-operator intelligence sharing on mule indicators and require enhanced DD for instruments with known abuse vectors. Ensure escalation path by rapidly freezing suspicious withdrawals.
Credential Stuffing & Account Take Over
Password reuse and mass credential dumps mean that credential-stuffing campaigns reliably scale during tournaments. Once an account is hijacked, fraudsters can empty balances, change payment details, or use accounts as staging points for laundering.
ATOs produce chargebacks, reputational loss and regulatory scrutiny. They also undermine responsible gambling safeguards if the original user remains unaware.
Enforce multi-factor authentication (MFA) for high-value actions, deploy real-time velocity checks on login attempts, and integrate credential-leak intelligence into the fraud stack. Increase automated challenge rates for logins from new devices, VPNs, or high-risk geographies; combine with fast customer outreach channels to verify suspicious sessions.
The most effective defenders in the 2026 World Cup in North America will be those who combine technology with cross-industry collaboration, turning the tournament’s torrent of data into an advantage rather than a vulnerability.
Gaming LEDGER
With RUSSELL MIFSUD
Russell Mifsud Director Head of Gaming Europe KPMG
Dear Reader,
I’m delighted to contribute a regular column to GamblingIQ, beginning with this Defenders of Trust edition. Having worked closely with operators, suppliers, regulators, and financial institutions across multiple jurisdictions over the past decade, I’ve seen first-hand how quickly the ground beneath our industry can shift, and how differently organisations respond when pressure mounts.
Across every major gambling market, the conversation is changing. Trust is no longer framed as a matter of intent, culture, or messaging. It is increasingly judged by systems, controls, and evidence. Regulators are moving decisively from guidance to enforcement. Investors are pricing governance risk into valuations. Boards are asking harder questions about whether their operating models can withstand scrutiny rather than simply pass inspections.
Yet the industry is also under intense commercial pressure. Margins are tightening, payment rails are fragmenting, cyber threats are escalating, and technology stacks are becoming more complex as innovation cycles accelerate. In this environment, organisations outperform when compliance, integrity, and risk management are built in, not bolted on.
This column is intended to be practical. It focuses on the decisions that matter: what to build, what to challenge vendors on, where risk is quietly accumulating, and how regulatory expectations are evolving in practice. It also reflects the collective insight of specialists across technology, cyber, risk consulting, AML, governance, and regulatory advisor. My aim is simple: to cut through noise and offer clear, evidence-led insight into how the industry can grow responsibly, competitively, and with confidence.
Enjoy the read, Russell.
What Leaders Should Be Doing This Quarter
To stay ahead of regulatory expectations and maintain operational resilience, I believe leadership teams should focus on four immediate priorities:
Ensure every material judgement - particularly across AML, responsible gambling, fraud, and incident response - has a clear owner, a documented rationale, and an accessible evidence trail.
Bring together AML, RG, cyber, payments, data, and product teams to map where ownership blurs. Most regulatory failures occur in the seams between functions, not within individual silos.
Implement a unified AI governance framework that mandates “explainability” as a standard for certain AI models that are used for decision-making purposes, ensuring that every recommended decision is transparent, auditable, and ethically aligned with player safety.
Simulate enforcement-style scenarios such as fraud spikes, system outages, affordability escalations, or cyber incidents. The objective is not to test tools in isolation, but to observe how people, processes, and systems behave together under pressure.
REGULATORY SIGNAL - EU AI ACT
The legal landscape is changing. Systems used for fraud detection, customer risk scoring, and player protection are increasingly classified as high-risk, requiring explainability, documented governance, and human-in-the-loop oversight.
You’ve got to earn it
What I see repeatedly across markets is that trust rarely fails loudly; it erodes quietly, through small design compromises that compound over time. For this Defenders of Trust edition, that expectation brings disciplines such as AML, cyber security, risk management, governance, and compliance, with advanced technology firmly in focus. These areas may not always dominate industry headlines, but today they form the backbone of credibility across regulated markets. Trust in online gambling is not judged in isolation. It is assessed simultaneously by regulators, payment institutions, tech partners, sports bodies, investors, policymakers, the media, and players themselves. Stakeholders are now aligned around a single expectation: trust must be demonstrable.
A Question every Board should be asking: If a decision was challenged by a Regulator twelve months from now, could we clearly explain who made it, why, and on the basis of which evidence?
TRUST SHIFT: Trust is now judged across entire ecosystems: platforms, suppliers, payments, data firms combined. It’s no longer assessed just from operator-to-operator.
Artificial Intelligence, (AI):
From Capability to Accountability
AI and advanced analytics are essential for fraud detection, AML, and player protection, but its complexity often creates “black boxes”. In iGaming, opacity is the enemy of integrity which in turn undermines trust. Regulators are moving beyond mere accuracy and are prioritising explainability.
For example, if AI is flagging a suspicious transaction, the logic must be explainable. An accurate model that cannot be explained is no longer an asset; it is a compliance risk.
To lead as ‘defenders of trust’, organisations must move from simple deployment to robust AI governance. This process involves:
• Model Oversight: Continuous monitoring to prevent bias and ensure fair player outcomes.
• Human Touch: Ensuring human intervention for critical affordability or risk decisions.
• Documentation: Rigorous and automated aligning controls with global standards (like the EU AI Act) for total auditability.
Behaviour under Pressure
Enforcement has become the starting point
A defining shift across regulated markets is the move from interpretive supervision to enforcement-led oversight.
Regulators increasingly test how organisations behave in real conditions: fraud spikes, affordability concerns, cyber incidents, or operational failures.
Designing for enforcement means assuming decisions will be examined long after they are taken. It requires clear accountability, decision records, data lineage, and defensible judgement - not as an exercise in regulatory appeasement, but as a foundation for organisational resilience.
In practice, many challenging regulatory conversations arise months after an event, when organisations are asked to reconstruct not just what happened, but why a judgement was made at the time. Regulatory scrutiny no longer tests intentions - it tests memory, evidence, and accountability.
“Reality Check:
In the majority of regulatory interventions we’ve encountered at KPMG in Malta recently, the failure is not a lack of policy, tooling, or investment, it is a breakdown in ownership at the point where judgement is required.
Built, Not Bolted On
The most resilient operators embed trust directly into their operating architecture: onboarding, payments, monitoring, decision logic, escalation paths, and audit trails. Controls operate continuously and consistently, rather than being layered through manual reviews or retrospective checks.
In several recent enforcement actions, the underlying weakness was not a lack of controls, but the absence of a coherent control architecture, and inability to show how decisions and controls connected across teams and systems.
Where trust is treated as an overlay, gaps emerge. Ownership blurs, workarounds proliferate, and evidential weaknesses appear during audits or enforcement enquiries. If trust only exists in policy documents, it will fail under pressure.
Commercial Pressure Makes Design Choices Visible
Rising duties, steeper fines, and increasing compliance costs are compressing margins across the industry. In this environment, poorly designed controls become unsustainable. Fragmented systems, duplicated reviews, and manual workarounds are expensive and fragile. Trust, when engineered well, becomes a commercial advantage rather than a constraint.
Trust Beyond Operators
Sustainable channelisation - drawing players into safe, regulated environments - requires policies, duties, and tax structures grounded in operational reality. Poorly calibrated regulation does not eliminate demand, it relocates it. When friction becomes excessive or regulated offerings lose competitiveness, blackmarket operators are quick to fill the gap. Effective regulation is as much about understanding incentives as it is about setting rules.
Keith Cortis, is Gaming AI Lead, KPMG in Malta, which supports organisations in embedding AI governance within their operating models
Valentina Franch Senior Manager, Gaming Regulatory Lead, KPMG in Malta
Giselle Borg Partner, Gaming GRC Lead, KPMG in Malta
Hacking & Data Breaches in Gambling
What we see ...and what we don’t
≠ Total Incidents
Apart from on-chain crypto analysis, disclosure rules shape the narrative.
Here are some notable hacks and data breaches affecting operators & platforms
Ransomware, Social Engineering, (2019, 2023, $45m class action settlements for 2019 breach)
Scattered Spider (UNC3944) gained access via social engineering/remote access, caused multi-day outages across properties and reportedly exfiltrated large volumes of customer data. 2019 attack led to class-action settlement for around $45million.
Social Engineering, Voice Phishing, (Oct 2023, $15million settlement with hackers)
Attackers launched a social engineering attack on a third-party IT support vendor that Caesars used. Through this attack, the threat actors were able to gain unauthorised access to the vendor’s credentials and then pivot into Caesars’ network.
Hot Wallets/Private Keys Breach, (Feb 2024, $4.6million cost of hacking)
What happened: A crypto-native casino had funds drained after attackers compromised keys/ private signing mechanisms and moved funds on Ethereum/BNB chains. This is an example of how crypto-treasury design failures (hot wallets / keys) lead to direct theft.
Unauthorised access to player account-related data & technical information, (July 2025) Flutter Entertainment confirmed that an unauthorised third party accessed internal systems affecting up to 800,000 customers of Paddy Power and Betfair in UK and Ireland.
Hot Wallet Breach - $41m theft, (Sep 2023). North Korea–linked Lazarus Group exploited access to Stake’s hot wallets transaction signing infrastructure, enabling unauthorised withdrawals.
Superbet & Playtech
Merkur, Germany
IQ COMMENT
€30m unintended payouts (Sept 2025): Romanian operator Superbet experienced a major glitch during play of the Playtech Fire Blaze Red Wizard slot. The malfunction apparently caused winning outcomes on every spin for several hours. Superbet ultimately paid out more than €30m in winnings to roughly 7,500 players. Issue did not originate in Playtech’s software.
Misconfigured gambling app database (API-backed logs): Allowed unrestricted access to API produced logs, including session/game move data, IPs, game activity. Stemmed from a misconfigured Elasticsearch instance fed by API traffic and served the stored data without protection.
Unsecured API/GraphQL (Feb 2025): Merkur had an unsecured API endpoint (GraphQL) that allowed unauthorised access to a vast amount of player information; account details, gaming history, KYC verification docs. Root cause was an unsecured authorised API interface.
What stands out on this page is not just the variety of attack vectors - social engineering, wallet compromise, API exposure, platform glitches - but how selective visibility defines what the industry believes its risk profile to be.
Every incident listed here is public because it had to be. Either regulators were involved, customer data crossed disclosure thresholds, funds moved on-chain, or class actions/litigation followed. That alone tells us something uncomfortable: we only see breaches when silence is no longer an
option. In online gambling, many security failures never make it this far. Minor API abuse, quietly reversed withdrawals, patched logic flaws, suspicious bot activity — these are routinely handled internally and logged as “fraud” or “operational issues”, not breaches. Yet the mechanics are often identical to the headline incidents shown above.
Social engineering dominates because it bypasses technical defences entirely. APIs appear repeatedly because gambling platforms are API-heavy by design - games,
wallets, KYC, CRM and payments all talk to each other constantly. Where access control or vendor oversight slips, exposure follows.
The real lesson is not that gambling is uniquely vulnerable, but that regulatory reporting thresholds shape the narrative. The breaches we know about are real — but they are almost certainly not the full story.
THE MERKUR CASE: HOW API FAILURES TRIGGERED REGULATORY ACTION
Core issues around GGL (Germany’s Gambling Regulator) formal regulatory warning
An unsecured backend interface (GraphQL/API) allowed unauthorised access to player accounts, KYC docs and gaming history. Who’s responsible: GGL held both the licence-holder and the platform provider accountable — outsourcing is no defence.
Regulatory tone: Formal public reprimand, a clear warning that basic IT hygiene failures are enforcement matters.
How APIs Failed
Missing/weak authentication & authorisation (no strong tokens, poor role checks).
Excessive data exposure via permissive endpoints (GraphQL returns too much by default).
Insufficient logging, alerting and vendor access governance delayed detection and containment.
Practical fixes the industry must adopt
Enforce strong API auth: OAuth2 + mutual TLS or signed JWTs; rotate keys and revoke quickly.
Least-privilege & granular RBAC: ensure endpoints only return fields required per role.
API gateway & rate limiting: block abnormal flows and bot abuse at the perimeter.
Input validation & query whitelisting for GraphQL to avoid overly broad queries.
Immutable audit trails & SIEM integration for rapid forensic response.
3rd party controls: contractual SLAs, regular pen tests, vendor attestation and supply-chain audits. Breach readiness: playbooks, tabletop exercises and mandatory, fast regulator notification.
“Regulators expect operators to own security end to end: verify vendor controls, enforce strict role separation, maintain audit trails, report breaches quickly — exposing KYC or player data invites public censure.
Ransomware/extortion against operators
Criminal groups (ransomware gangs) encrypt operator or vendor systems and demand crypto ransoms; can cause downtime, regulatory fallout and extortion leaks.
History: Large operators have been ransom/ extortion targets in 2023–2024; court filings and industry coverage show multi-million dollar ransom activity and FBI tracing of payments.
Attackers compromise a vendor used by several operators (CRM, support, hosting, wallets) and exfiltrate player PII or enable fraud across many brands.
History: Recent industry reporting shows CRM / supplier breaches that exposed casino customer data and triggered downstream incidents (industry breach trackers and iGaming threat reports).
“ The GGL warned that licence-holders must secure backend interfaces and cannot shirk responsibility by outsourcing. Failure to protect APIs, enforce robust access controls, maintain immutable audit trails and ensure forensic readiness contravenes basic IT obligations and will prompt public enforcement.
The GGL signalled that API endpoints must be inventory-mapped, authenticated, monitored and regularly tested. Uncontrolled vendor access, excessive data exposure and missing audit logs were framed not as oversights, but as structural compliance failures.
API / game-API exploitation (the “print-money” attack)
Why it matters? Weak or unauthenticated game APIs, predictable endpoints or flawed business logic allow attackers (or insiders) to credit accounts, place automated bets, spoof results or drain wallet balances. This is distinct from simple data theft, where attackers directly create profit by abusing game/ transaction APIs.
Concrete industry discussion & warnings: iGaming execs and platform security teams have publicly warned that exploited game APIs in emerging markets can “print money” for fraudsters and drain significant GGR — this has been a hot topic on LinkedIn and at iGaming conferences.
Mitigation: Strong API auth (mutual TLS / signed requests), rate limits, anomaly detection on wagering patterns, end-to-end request signing and replay protection.
Attackers compromise an innocuous IoT device on a hospitality/casino network and pivot to internal systems (high-roller DBs, back-office). The “weak device → jump to core systems” is a classic.
History: Well-reported incident where an Internet-connected aquarium thermometer was used as a foothold to exfiltrate a casino’s high-roller database.
Mitigation: VLAN segmentation for IoT, deny-by-default firewall policies, device inventory and hardening, unique device credentials.
RNG / firmware / game logic bugs exploited
Firmware bugs or PRNG weakness in physical or online game code can be discovered and abused to guarantee payouts (either by players or insiders).
The Game King video-poker firmware bug exploited in 2009–2010 (John Kane case) is a famous example of a software/firmware bug enabling outsized wins.
Mitigation: Secure SDLC, independent RNG audits, signed firmware and rigorous pre-release testing, rapid patching.
Leaky API: Insecure endpoints drain money & data
Guardian of the Games
Alexandre Tomic on Reverse Integration, API Governance and why hackers moved downstream
If you can generate wins without placing a bet, that’s the ultimate exploit. That’s why tested API governance has become a real competitive edge “
Exclusive
Alex Tomic
Founder & CEO, Alea
About three years ago, Alexandre Tomic and Charlotte Lecomte, Founders of Alea, noticed something unsettling beneath the industry’s glossy surface. “Many new game studio APIs coming to market were simply not secure enough,” he says. The response wasn’t a patch or a workaround, but a hard pivot in philosophy. Alea built its own API, and told studios to come to them. “We decided to build our own API and require studios to reverse-integrate into it.”
That decision came with a clear responsibility. “We needed to be certain that our own software met the highest security standards,” Tomic explains. As APIs increasingly became a target for attackers, Alea found strong alignment with Continent 8, which had identified the same trend. The partnership began with Vulnerability Assessment and Penetration Testing, followed by broader security assessments designed to strengthen both technology and governance.
From there, Alea took a clear public position. Rather than treating security as an internal milestone, the company chose collaboration and transparency. Working closely with Continent 8 and alongside its game studio partners, Alea is building a secure, end-to-end framework to protect the entire API supply chain, from the game provider to the aggregator, and ultimately to the operator.
“Security isn’t about telling people what to do,” Tomic says. “It’s about making sure we get it right ourselves first, testing it properly, and then working with our partners so the whole chain is strong. That’s how you actually make it safe for everyone.”
Why Alea Refused to Speak Your API
Alea first started as an operator over 12 years ago, and it spoke a hundred languages — technically speaking. All the game studios arrived like foreign envoys, each with its own API dialect; integration meant constant translation and reconciliation that never stopped. “We were effectively speaking one hundred different tech languages,” Tomic admits. “None of the APIs were the same. Reconciliation was a nightmare.”
The solution was unsentimental. When the market would not standardise, Alea imposed its own architecture: it created a single integration protocol and required suppliers to adapt to it. The impact was immediate. Established providers connected smoothly; newer studios exposed shortcomings almost at once with no rollback support, weak reconciliation or poor credential handling. “In the past, credentials were not handled properly,” Tomic recalls, “and IP whitelisting, which many relied on as a control, was in fact easy to bypass.”
Alea flipped the onus. Instead of endlessly adapting, the company published a single contract and insisted partners speak that language. “It puts pressure on studios,” Tomic says, “but it exposes whether they’re production-ready.” The policy is uncompromising by design. It has cost shortterm churn. But discipline breeds speed: fewer emergency patches, cleaner reconciliation cycles and faster rollouts.
IQ Directory:
www.gamblingiq.co.uk/directory
Cash, Control, and Containment
Layered Security and Llifecycle Accountability
Alexandre Tomic warns the industry is at an inflection point: “Less mature providers are more focused on closing a sale than securing the integration,” he says bluntly. “IP-whitelisting as security is dead, modern APIs must use token-based authentication, rotation, layered access controls and continuous testing.” Alea has pushed this gospel into its product roadmap, insisting buyers demand demonstrable proof of security from sellers. Alexandre adds that the threat landscape has accelerated. “Years ago you had hours to respond; now AI-assisted tooling lets attackers exfiltrate value in under an hour.” With huge cash flows moving through studio, aggregator and operator chains, API governance is “no longer a tech detail; it’s a commercial necessity,” he argues. Alea’s message is clear and stylishly uncompromising: treat APIs like products, own their lifecycle, bake in standards and accountability. Do that, and you scale safely; ignore it, and you learn about breaches the hard way.
‘The role of the aggregator has evolved — from reseller, to curator, to technical specialist’Alex Tomic
Fast Games, Fragile Code:
Founders Alexandre Tomic and Charlotte Lecomte were not chasing elegance with the first iteration of their platform, they were chasing survival. “We had to build our own internal aggregator simply to function”. Back then, even household-name suppliers struggled with fragile APIs. Games broke. Results didn’t reconcile. And when issues were raised, the response was often a shrug: everything is fine.
Fast-forward to today and the top-tier providers have cleaned up their act. Their APIs are solid, their integration teams sharp. The real risk, Tomic says, now comes from elsewhere. “There’s a wave of new studios entering the market, and security isn’t always their priority.” Speed and creativity take precedence; infrastructure comes later; if at all.
That gap has consequences. Weak game APIs can be manipulated to create fake wins, quietly draining revenue. “Operators tell us, ‘We’ve been hacked’and,” Tomic says. “And often they have , but it’s silent bleeding.” By the time the problem surfaces, losses can run into the millions. Banking APIs are no longer the soft target. “They’re hardened. But in gaming, money goes in and money comes out. If you can generate wins without placing a bet, that’s the ultimate exploit.”
Securing the Integration Ecosystem
As Alea expands its partner network, each new integration introduces potential cybersecurity risks that could compromise the platform’s integrity. In collaboration with security specialist Continent 8 Technologies, Alea has established an Integration Security Assessment Programme to ensure all prospective partners meet rigorous security standards before connecting to the platform.
The programme evaluates partner cybersecurity maturity through targeted assessments. API penetration testing identifies vulnerabilities in partner infrastructure, whilst security assessments provide a view of security posture. Continent 8 conducts these evaluations externally and non-intrusively, ensuring no operational disruption and supporting informed decisions across the supply chain.
It started in a Barcelona Flat
From Panic to €125m GGR per Month: Alea’s Impossible Dream
The internal game aggregator that powers Alea began in a small Barcelona flat. “We were a 10-person team, working with whatever we could cobble together,” Tomic recalls. The first version of Alea’s platform was built to keep Slots Million running despite fragile APIs and credentials.
From these beginnings, Alea’s growth was extraordinary. Its first B2B transaction on September 1, 2020, generated €2m monthly GGR. After CEO Jordi Sendra’s appointment in 2021, GGR rose to €4m, doubled to €8m in 2022, and reached €25m by 2023. By 2024 it tripled to €100m, with year-end 2025 GGR at €125m.
The early flat now reads as the platform’s origin story. Today, Sendra sits on the board with COO Ramon Glieneke, CTO Eduard Fumàs, Charlotte Lecomte, and Alexandre Tomic.
Charlotte Lecomte, CPO & Co-Founder, Alea.com
Jordi Sendra, CEO, Alea
AReal-Time or Real Over-Kill?
Regulators across Europe have already moved beyond quarterly or monthly returns to more frequent, structured data collection, but they differ sharply on form and purpose. Finland’s reform raises the question: when does oversight become overreach?
Taken together, the following regulatory models show one recurring lesson for multi-market operators: frequency alone is not the point. The practical test is standards, schemas and forensic readiness; the exact challenges Finnplay’s Managing Director Jaakko Soininen highlights when he urges “compliance by design”:
+ The Netherlands requires each licensed operator to run a dedicated Control Database (CDB) that exposes standardised regulatory data to the Kansspelautoriteit. The CDB is a live supervisory tool with technical specifications and a published data model; the Dutch regime is explicitly designed to allow the regulator fast, centralised access to platform activity.
+ Italy has gone further: ADM (working with state IT partner SOGEI) enforces mandatory gambling-management tools and technical controls that amount to near-real-time monitoring, including certified limits, behavioural controls and system-level logging for forensic inspection. Recent reforms have tightened that setup and consolidated licensing, a model that significantly raises the technical bar for operators.
+ Spain is designing a Central Monitoring System that integrates behavioural indicators and advanced analytics. The DGOJ’s plans include AI-assisted surveillance to track multiple risk indicators in short timeframes, a move intended to give the regulator predictive visibility across operators.
+ Sweden emphasises continuous supervision and mandatory reporting standards; the regulator requires ongoing transparency and technical access that supports inspections and forensic queries. The Swedish model stresses operator responsibility for robust logging and accessibility.
• Default to robust hourly/daily batches + tested forensic exports;
• Map the supply chain and contract report-liability clearly before go-live.
IDENTITY ASSURANCE: A FINNISH
EXPECTATION
Brian Forth, Finnplay Commercial Director: “Finland’s near-universal electronic identity systems (bank ID, mobile certificates, the Suomi.fi hub) mean that Pay & Play flows — instant verification tied to strong eID — are the natural default. Operators who treat ID checks as a conversion risk will misjudge local user expectations.
The 4-part operational checklist for license applicants in Finland: The core technology, marketing and operational decisions regulators will expect to see aligned at application stage
Confirm reporting cadence (stream vs batch) and test under load. Ensure logging is forensically robust and tamper-evident. - Choose Pay & Play or traditional flows with a clear rationale for each product and customer segment.
Map channels that fit Finnish media rules and consumer behaviour. Align promotional mechanics with regulated limits and responsible gambling protocols.
02. Marketing 03. Operations
Recruit and train customer service and player protection teams before launch. Document duty-of-care processes and escalation flows for incidents.
04. Small Operations
Short-term savings on compliance rarely pay — a slightly higher initial investment in a reliable partner reduces long-term operational drag.
From Monopoly to Measurement
As Finland opens its gambling market, regulators are weighing how much data is enough in a society built on instant verification.
Finland’s reform marks the end of a long era of monopoly provision and the start of a tightly regulated, licence-based market. Much of the discussion has turned on how regulators will supervise the market. Other European states have already experimented, then implemented with near-continuous reporting; Finland is now designing a model in the knowledge that its citizens expect instant verification and that vendors will have to supply robust audit trails.
Finns using strong electronic identification
01. Platform Provider
Brian Forth, (pictured above), Commercial Director, Finnplay
Compliance by Design: A Cross-Border Test
Finland’s imminent licence window raises an industry debate: how to reconcile regulators’ desire for reliable evidence with the engineering and commercial realities of running multi-market platforms.
Jaakko Soininen is not interested in speed for its own sake. With Finland due to open gambling licence applications in six weeks time on March 1st, the Finnplay Managing Director argues that the central challenge for multi-market operators is not how quickly regulators can access data, but how systems and contracts are designed so a single regulatory change does not fracture several live products at once.
Soininen says the solution is simple and practical: build compliance in from the start. “Compliance by design is a critical part of product and technology development in iGaming,” he says. That, he adds, means planning with reuse in mind. “When planning any development we must ensure that existing live solutions are not disrupted. Unnecessary duplication is avoided; features built for one jurisdiction can often be adapted for others with minimal changes.”
His experience across nearly ten jurisdictions gives the argument weight. Regulators frequently issue subtly different technical expectations; the cumulative effect for suppliers and operators is bespoke engineering, repeated work and fragile integrations. The alternative, Jaakko argues, is modularity: agree common schemas, settle delivery cadences and build components that can be repurposed rather than rewritten.
- Real-time reporting is often unnecessary; hourly or daily batches usually suffice -
That stance raises a debate over “real-time” reporting. Rather than quarrel over literal streaming of every event, the Finnplay MD focuses on outcomes. “Unified data supports evidence-based decision-making,” he says, “but in practice hourly or daily batch reporting meets regulatory needs in almost all cases while sharply reducing operational complexity.” He recommends pairing such batches with rapid, secure forensic exports and tested incident playbooks so regulators can reconstruct events when necessary — without imposing constant streams on every vendor.
Two technical preconditions follow: visibility into the supply chain and contractual clarity. Certificates such as ISO 27001 are useful, he says, “but they are only the foundation. Providers and operators must fully understand the entire supply chain — down to the last component.” Equally, who carries liability for delivering reports must be specified in contracts; commercial arrangements cannot be left ambiguous.
His final counsel to newcomers is terse and commercial: “Avoid shortcuts. Investing in thorough planning and robust solutions upfront is far cheaper than fixing issues later.” If cross-border markets are to scale without breaking, compliance must be treated as an engineering discipline as much as a legal box-tick.
Genuine Thought Leader: Jaakko Soininen, (pictured), is Managing Director at Finnplay, now one of the world’s most trusted fully integrated casino and sportsbook platforms.
01 Fraud Prevention Annual Global Rankings
[2026 - 3rd Edition]
Sumsub
The Power of One Verification Platform
INNOVATIONS IN ANTI-FRAUD & DIGITAL IDENTITY
GamblingIQ talks to the operators and Benchmarks the Leading fraud prevention and digital identity providers, ranked on innovation, effectiveness & real-world impact.
Sumsub has gone from startup scrapper to swaggering vendor, and the iGaming industry has noticed. In 2025, the respected analyst firm Gartner once again placed the company in the Leaders’ Quadrant for Identity Verification. Sumsub was also recognised as a leader by Forrester and IDC, citing its strong execution and growing market traction.
Run by the Sever brothers (Andrew, Jacob and Peter) and their friend Vyacheslav Zholudev, who is company’s CTO, Sumsub now sells the sort of reassurance executives really crave: a modular stack that stitches KYC, KYB, AML, transaction monitoring and fraud orchestration into a single workflow — with reusable identity primitives and ease of use for the players touted as its USP.
Crucially for iGaming, Sumsub has been landing headline clients and partnerships through 2025 — from specialist operators to platform plays — as it pushes gaming-focused SDKs and Fraud Prevention tooling. That commercial momentum looks real. The sales pitch isn’t idle marketing:
Sumsub claims industry-leading conversion (roughly 91–96% across the US, UK and Brazil) and sub-20second average verifications; metrics that directly shave abandonment and compliance cost. Those are the numbers operators care about most.
Regulators and boards should also take note: Sumsub maps controls to FATF and major regimes (FCA, CySEC, MAS, BaFin, FINMA) and positions itself as compliance-as-a-service, complete with advisory capability and payments / exchange integrations. In short: fast onboarding, enterprise controls, customizable flows, case management and a product roadmap pitched at the fraud wave coming from deepfakes and AI-assisted attacks, exactly why many iGaming firms put Sumsub on their shortlists in 2025.
By the numbers, Sumsub now serves 4,000+ clients across 220+ countries, supports over 14,000 document types, and can verify users in as little as 4.5 seconds using its Non-Doc solution. Its reusable ID suite can halve onboarding time and lift conversions by 30%. Impressively, the company analysed 3M+ fraud attempts in its 2025 iGaming research. Overall, it has outstanding iGaming-facing staff and the company’s attention to detail is second to none.
TransUnion Information for Good®
TransUnion began in 1968 as the parent holding company for Union Tank Car Company and soon moved into credit information. Today it is a global information and insights business based in Chicago, operating in more than 30 countries with offices across 110 locations. The firm employs roughly 13,400 people (latest public count). Full-year 2024 revenue was $4.184bn; trailing-12-month revenue through Q3 2025 is about $4.44bn, indicating continued organic growth. In January 2025 TransUnion increased its stake in Trans Union de México to 94% via a MXN11.5bn ($560m) deal aimed at expanding its Latin American footprint and adding an estimated $145m of local revenue. Evolving from credit reporting, TransUnion now sells data, analytics and decision-ingestion platforms across credit, fraud, marketing and risk, with substantial regulatedgambling partnerships. Its Information For Good® mission underpins commercial products that claim to boost financial access and consumer empowerment. Major gaming partners include Flutter, Entain, BetVictor and William Hill; integrations with operators and service providers help secure and verify transactions, manage fraud and meet compliance requirements across regulated markets. It serves millions of consumers and businesses worldwide and operates extensive reseller and channel partnerships. Leadership highlights continued investment in analytics and platform engineering strategically.
Data-Driven Defence Risk Intelligence at Scale
Visit: TransUnion.com
GeoComply
Over 2.5 Billion Checks Every Month
Innovations
GeoComply provides fraud prevention and digital identity solutions designed to stop location spoofing and sophisticated online fraud, while enabling fast, reliable verification of legitimate users. Founded by David Briggs and Anna Sainsbury, the Vancouverbased company combines high-integrity location intelligence with device signals, behavioural analysis and identity data. Its technology is installed on more than 200 million devices worldwide.
Built in some of the world’s most demanding regulatory environments, GeoComply brings more than 14 years of experience across compliance, fraud and identity. In 2025, the company appointed former FanDuel President Kip Levin to accelerate global commercial growth. That regulatory heritage, combined with the scale of its global device network, strengthens GeoComply’s AI and machine-learning models across industries including financial services, fintech, media and entertainment, iGaming and beyond.
By positioning “where” as a core source of truth through its where-based trust engine, the company helps organisations prevent spoofing, account abuse and regulatory breaches while strengthening compliance outcomes at scale.
Visit: GeoComply.com
Jumio
The Future of Identity
Jumio remains a leading fraud prevention and identity verification platform, now estimated to generate $250m annual revenue with current staffing at around 1,500, reflecting a mixed picture after restructuring and regional hires. Jumio emphasises reusable biometrics, continuous risk signals and an identity graph of 30M+ identities, and continues to expand iGaming and travel offerings globally. Recent commercial wins include a high-profile integration with Alaska Airlines (mobile app biometric check-in) as Jumio pushes into travel while maintaining strong gaming relationships. It has fast, enterprise-grade verification (sub-50s avg), expanded fraud signals and regulatory readiness (eID/eIDAS, AI Act) — targeted at operators needing conversion, compliance and hardened transaction rails. Its commitment to innovation is evident in its continuous development of advanced biometric technologies, such as selfiebased authentication and 3D liveness detection, to combat increasingly sophisticated fraud tactics. The company maintains strong partnerships with industry leaders, including Playtech and continues to provide services to online casinos and sportsbooks like Novibet, Casumo, Stanleybet, while Lottoland has been a Jumio customer since 2017.
Win players Worldwide
GBG Go helps operators match and protect players and minors, accelerating player acquisition while meeting global gaming market regulations, so you’re always ahead of the game.
Connected Intelligence
Verify player age, improve sign-up rates and beat cybercriminals with easy eKYC and AML.
Visit: Jumio.com
Complete Player Onboarding
With around 1,125 people worldwide and headquarters in Chester, UK, GB Group (GBG) retains a stellar gaming client book including Betfair, Betway, Ladbrokes and William Hill (under the 888 group). The firm continues to field an experienced identity management and fraud team, led in the gambling sector by the highly respected Rebekah Jackson, supporting operators on compliance and regulatory requirements.
The Group delivered a solid first-half performance in FY2025/26, reporting £135.5m revenue (1H FY26), up 1.8% on a constant-currency basis. Growth was driven by the Identity and Location segments, which rose approximately 3.1% and 6.2% respectively; the Fraud segment saw a decline (c. 4.0%), largely due to timing of licence renewals.
Adjusted operating profit was £29.5m, with an operating margin around 21.2%. Net debt at 30 September 2025 stood at roughly £66.6m, with net-debt-to-EBITDA near 1.0x, underpinning a stable balance-sheet as GBG presses its platform and iGaming go-to-market strategy into 2026.
A true global player, LexisNexis® ThreatMetrix® is its flagship product. This delivers advanced fraud detection by analysing millions of global transactions to uncover high-risk behaviours and patterns. This is especially vital in combating account takeovers, bonus abuse, and other fraud types common in the gaming industry. The company operates as a subsidiary of RELX, a leading provider of data and analytics for risk management across the iGaming sector. As of November 2023, RELX reported an annual revenue of approximately £9 billion.
experian
Helps Gaming companies to stop leaving value on the table
Headquartered in Dublin and listed on the London Stock Exchange, Experian connects with the gambling sector through its CrossCore® digital identity and fraud platform. Over the last five years, it has prevented more than £10 billion in fraudulent applications. FY2026 revenues reached £6.8 billion, driven by digital and data services. Within gambling, Experian provides KYC, age verification, and fraud prevention, ensuring regulatory compliance worldwide. Major stakeholders include Vanguard, BlackRock, and Invesco.
Socure
Almost 3 billion Identity Checks reported in 2025
Founded in 2012, Socure applies machine learning, graph analytics, AI and vast data linkages to spot synthetic identities, accounttakeover attempts and other fraud at scale. The firm raised a $450m Series E, ($4.5bn valuation) and has made strategic buys such as Effectiv to move beyond consumer KYC into business identity and payments. Socure now verifies billions of identity requests annually, the company reported 2.7 billion ID checks in 2024. It serves thousands of enterprise customers, including marquee names like DraftKings.
SEON
Eliminating iGaming threats without sacrificing experience
SEON is a fraud-prevention platform founded by Tamas Kadar and Bence Jendruszak. After an $80 million Series C led by Sixth Street, its total funding stands at $187 million. SEON combines device intelligence, graph analysis and machine learning to detect bonus abuse, account takeover and synthetic accounts. Proven with gambling clients like LeoVegas, its real-time scoring and rich data integrations make it strong for regulated iGaming operators.
Yoti
Advanced age and identity verification solutions
The Robin Tombs and Noel Hayden founded company has strong gambling and age-assurance credentials. Its total funding to date remains over £166 million, and reported annualised revenues of about £26 million in March 2025, reaching its first EBITDA-profitable month. Its privacy-focused products, identity verification, age verification, facial age estimation, eSigning and anti-spoofing AI, continue to serve clients across iGaming.
Part of the RedCore group, Frogo is an AI-driven fraud-prevention platform tailored for iGaming operators. It combines device fingerprinting, behavioural analytics, graphbased forensics and real-time scoring to stop bonus abuse, multi-accounting, synthetic identities and more. Frogo’s modular engine integrates with operator workflows to protect revenue while preserving conversion. Selected as the GamblingIQ rising star for 2026.
Rising Star 2026
Frogo
“Reusable Identity and the case for a shared, legally defensible KYC layer
Operators and identity providers can form a regulated trust framework with common APIs, standardised consent artifacts and shared revocation lists; akin to open banking payments rails, but for identity
The gambling industry’s regulatory reckoning has a technical answer: legally defensible reusable identity. The argument advanced by Robert Prigge, chief executive and co-founder of Jumio, is not merely about convenience. It is about re-engineering how proof of identity is captured, consented to and reused across a fragmented set of operators, and in doing so materially reducing the kinds of identity and anti-money-laundering (AML) failures that attract the largest fines.
“If you’re an identity provider without biometrics and reusable identity, you probably won’t exist in a few years,” Prigge warns. His blunt assessment sits alongside a catalogue of enforcement actions in 2024–25 that have shown regulators will punish systemic verification failures. The link is straightforward: weak, episodic KYC processes create gaps — duplicate or synthetic accounts, poor source-of-funds checks and inconsistent audit trails — that inspectors identify and penalise. A legally robust, reusable identity regime can close those gaps.
At the centre of the proposal is a rigorous legal foundation. Prigge draws a line between two very different practices. “Here’s where most of them cheat,” he says. “They store fraud data under ‘legitimate interest’ provisions and call it reusable identity. Fraud data is evidence stored to check for future fraud. Reusable identity means having valid permission from real people to store and reuse their verified identity. That legal distinction matters.” In regulatory terms this distinction is pivotal: biometrics and other sensitive identifiers are treated as high-risk data under EU and UK privacy rules and therefore demand explicit, informed and revocable consent if they are to be reused.
How would such a system work in practice? Technically, a legally defensible reusable identity platform combines strong biometric enrolment with cryptographic tokenisation, consent management and standardised interfaces between identity providers and operators. A prototypical flow begins at enrolment: a customer completes a biometric-anchored verification (document scan + liveness check). The identity provider issues a tamper-evident digital credential — for example a signed, time-limited verifiable credential or JSON Web Token (JWT) — that represents the verified attributes (name, dob, verification date) without exposing raw images. Crucially, the credential records the consent scope: which attributes may be reused, for which purposes and for how long.
From a coding perspective the architecture leans on existing open standards. Verifiable credentials (W3C), decentralized identifiers (DID), FIDO2/WebAuthn for device-bound authentication and OAuth/OIDC for consented token exchange form the backbone. Implementations typically adopt secure enclaves or hardware security modules (HSMs) to hold private keys; the operator never receives raw biometric templates — instead they validate a signed proof presented by the customer or the identity provider. For developers this means adding layers: an API gateway that checks signatures and consent scopes, a revocation-check endpoint for tokens, and client-side code to store user keys in platform secure storage rather than on servers.
Legally defensible reusable identity requires more than cryptography. It needs governance. Operators must understand who is the data controller and who is the processor; contracts must allocate responsibility for consent capture, data breaches and regulatory reporting. Consent records must be auditable and revocable; data-protection impact assessments (DPIAs) and retention policies must be explicit. In cross-border settings, where an operator may accept players from multiple jurisdictions, the consent model must account for varying privacy regimes and, where necessary, default to the strictest applicable standard.
Operationally, the advantages are tangible and tied directly to enforcement risk. Reusable identity reduces onboarding friction, which cuts abandonment and the incentive to game registration flows. It reduces human review - the source of many errors — by providing machine-verifiable provenance. It hardens audit trails: when a regulator asks, an operator can show a signed credential bearing the identity provider’s cryptographic seal, the user’s explicit consent and the exact scope of reuse. That traceability short-circuits the ambiguity that often produces heavy fines.
But the system is not risk-free. Centralised repositories of reusable credentials could become high-value targets. Vendors that claim “reusable identity” without demonstrable consent and strong key-management practices could create new liabilities.
The practical route for gambling operators likely lies in a consortium model. Operators and identity providers can form a regulated trust framework with common APIs, standardised consent artifacts and shared revocation lists; akin to open banking payment rails but for identity. Such a framework spreads operational cost, concentrates auditing and makes it harder for bad actors to exploit one weak link. For compliance officers, a consortium certificate and catalogue of signed credentials is a more persuasive defensive narrative to regulators than ad hoc screenshots or siloed KYC logs.
Robert Prigge, CEO & Co-Founder, Jumio
Record Fines Trigger Race for Reusable Identity
Solutions >>
In 2024, just over $184 million in regulatory penalties were assessed globally. In 2025, large, widely publicised sanctions, like Spain’s aggregated €77.4m action and the multimillion-dollar Nevada cases, were designed not only to punish, but to force structural changes to AML systems, customer-safeguarding processes and licence governance. Smaller, targeted fines reinforce that the net now reaches across jurisdictions and across business models, from land-based casinos to cross-jurisdictional online platforms. For readers and industry watchers, two implications matter. First, compliance budgets must reflect enforcement risk: senior management and boards can no longer treat AML and safergambling as checklist items. Second, cross-border operators face an increasingly fragmented enforcement landscape where one regulator’s action can prompt parallel investigations elsewhere.
Spain (DGOJ) — €77.4 million
Spain’s regulator imposed one of the year’s largest single enforcement packages after identifying 14 operators offering services without licences; fines ranged up to €10m apiece.
Platinum Gaming / Unibet (UK) — £10 million (~$13.3m)
The UK Gambling Commission penalised the operator behind the Unibet brand for serious AML and safer-gambling failures — a headline-making punishment intended as a market signal.
Resorts World Las Vegas (Nevada, US) — $10.5 million
Nevada regulators approved a $10.5m stipulated fine in a money-laundering enforcement tied to illegal bookmaker activity — the second-largest fine in the state’s modern history.
Gammix Limited / Dutch regulator — €19.7 million
The Dutch regulator’s large fine for operating without permission and other breaches featured among Europe’s heaviest single penalties in 2025.
MGM Resorts (Nevada, US) — $8.5 million
Nevada’s action against a major land-based operator for permitting illegal bookmaker activity resulted in an $8.5m sanction.
Caesars Entertainment (Nevada, US) — $7.8 million
Regulators approved a multi-million dollar fine for failures tied to a convicted illegal bookmaker who gambled repeatedly at company properties.
Netherlands / Betcity (Entain brand) — €2.65 million
Dutch enforcement continued apace with a seven-figure penalty against a major operator for local regulatory breaches.
Sweden — SEK19 million (≈€1.7m total across operators)
The Swedish Gambling Authority issued sanctions and warnings, delivering SEK19m in fines across several licensed operators for AML failings.
ProgressPlay (UK) — £1 million
The UK regulator fined the platform operator for deficiencies in AML and safer-gambling controls.
Admiral Casino / Greentube — £1 million
A notable £1m fine recorded in U.K. enforcement roundups for customer-protection and AML shortcomings.
Videoslots (UK) — £650,000
The Gambling Commission issued a £650k settlement for AML and social-responsibility failures.
NetBet (UK) — £650,000
A similar-sized penalty addressed multiple AML and safer-gambling failings at the operator’s UK arm.
DraftKings (Massachusetts, US) — $450,000
State enforcement in Massachusetts produced a significant penalty for acceptance of credit-card wagers in contravention of local rules.
+ There were also regional seven-figure and high six-figure fines across Europe, the UK and US jurisdictions in 2025. For example, there were municipal and national fines in Scandinavia (Betsson, TSG, Snabbare), multiple mid-sized UKGC penalties issued during a sharp enforcement cycle, New Jersey licensing fines, and targeted sanctions against operators that failed to demonstrate adequate KYC, source-of-funds checks, or safer gambling interventions.
iGaming Fraud Types 2026
Fraud’s Cold Calculus: New Research shows First-Party Deception is the biggest Profit Leak; there are fewer headline breaches, but smarter attackers. Here’s what the numbers mean for gambling operators and what to do next.
The latest Sumsub Identity Fraud Report should be read by every boardroom that makes money from customer activity. The striking headline is almost paradoxical: the reported identity-fraud rate eased from 2.6% in 2024 to 2.2% in 2025, yet the vendor also documents a 180% year-on-year rise in “sophisticated fraud” and finds 75% of surveyed fraud professionals agreeing that attacks are becoming more AI-driven. In short: fraudsters are trading volume for stealth and lifetime yield. That change matters, and it will cost operators who remain complacent.
Sumsub’s study analyses more than four million flagged attempts and combines telemetry with survey responses from 300+ fraud teams and 1,200+ consumers. That is scale enough to show structural shifts, not random noise. The report’s breakdown of first-party fraud, the attacks where the “customer” is complicit, reads like an operator’s worst accounting spreadsheet: “Others” 27%, synthetic identities 21%, chargeback abuse 16%, application fraud 14%, deepfakes 11%, money muling 11%.
Those percentages translate directly into lost stakes, reversed settlements, higher acquiring fees and regulatory headaches, and they are not evenly distributed across accounts.
Why first-party fraud is different
First-party fraud mimics legitimate behaviour: the applicant submits plausible documents, completes onboarding flows, wagers and withdraws in ways that often look ‘normal’ to simple rule-based systems. Synthetic identities are particularly corrosive. Built from fragments of real data and falsified elements, they can pass single-source checks repeatedly, accumulate welcome offers and cash out before detection. Chargeback abuse compounds the damage: fraudulent deposits followed by disputes leave operators not only out of pocket but facing processing penalties and higher interchange costs.
At the same time, third-party attacks remain a large, industrialised threat: identity theft (28%), account takeover (19%), card testing (17%), phishing/social engineering (16%), and bot-based automation (12%). The danger is the intersection: synthetic or mule accounts established via first-party routes are reusable assets for third-party rings, turning a single fraudulent persona into a laundering hub or high-volume cash-out node.
New vectors, payments & deepfakes
Two practical shifts are worth flagging. First, Sumsub identifies a pivot toward pay-
Comment
Identity Fraud
(Trend from 2021 to 2025): 1.1%, 1.7%, 2.0%, 2.6%, 2.2% (drop in 2025 masks composition change).
First Party Fraud
Synthetic identities 21%
Chargeback abuse 16%
Application fraud 14%
Deepfakes 11%
Money mulling 11%
Others 27%
Third Party Fraud
Identity theft 28%
Account takeover 19%
Card testing 17%
Phishing 16%
Bots 12% / Other 8%.
Customer Impact
52% of end users report being victims of identity fraud; 40% of companies report direct impact.
ment-method fraud outpacing document spoofing in certain pockets, with payment abuse metrics reaching about 6.6% in higher-risk cohorts. Criminals are monetising faster, they validate and cash out via transactions rather than building identities for long games when it suits them. Second, deepfakes have exploded: Sumsub reports enormous percentage increases in synthetic-biometric attacks year-on-year. Attackers combine synthetic video or altered selfies with telemetry tampering, altering device or browser signals to hide injection attacks to trick liveness checks and automated biometric classifiers.
What that means operationally
The blunt truth is that one-off KYC checks — a passport scan here, a selfie there — are no longer sufficient. The gambling industry must move from episodic identity checks to continuous assurance. That requires changes across measurement, technology, organisation and governance.
Operators: measure what matters
Make fraud economics a board metric. Track median time-to-detect, average fraudulent cash-out, chargeback cost per incident, lifetime fraudulent revenue per account, and false-accept / false-reject rates by vendor and assurance tier. These numbers move debate from anecdotes to investment-grade business cases. Reducing detection latency collapses lifetime fraudulent yield; measure it and you can prioritise what delivers real ROI.
Technical architecture: layered, explainable and low-latency
Operators must demand low-latency, interoperable signals: device fingerprinting, phone-number and SIM checks, transactional micro-pattern telemetry, passive browser attestation and behavioural biometrics. Ensemble detection, document forensics coupled with graph analytics and behaviour scoring, reduces reliance on any single supplier or biometric signal. Crucially, insist on explainability from vendors: models that return scored reasons and signal provenance allow rapid adjudication and regulatory evidence packages.
Network detection not thresholds
Per-account thresholds miss networks. Graph analytics that cluster shared devices, beneficiary wallets, IPs and withdrawal destinations reveal mule rings far faster than isolated rules. Detecting clusters reduces replication: if one operator spots a mule network and shares anonymised indicators, copycat attempts at other sites fail faster.
Organisational and process fixes
Centralise fraud responsibility in a cross-functional Fraud Operations unit that includes data science, payments, legal/compliance, product and human review. Run adversarial red teams quarterly that simulate synthetic-identity campaigns, deepfake-enabled onboarding and telemetry injection. Upskill human reviewers to recognise hybrid attacks: look for inconsistent metadata, improbable device switching, rapid changes in wagering patterns and suspicious payment rails.
Instrument payments
Because payment-method abuse is rising, instrument payment rails for micro-patterns: small-value deposits followed by immediate large withdrawals, unusual card bin patterns, and new payee identifiers should trigger adaptive checks. Build fast chargeback analytics so acquiring teams can present evidence and contest illegitimate disputes early.
GamblingIQ's roll call of the leaders keeping play safe Security Index 2026
THE SECURITY
GamblingIQ celebrates the defenders who protect the security and integrity of the gambling industry. Their expertise ensures that systems are resilient, operations are secure, and that games are fair. While product launches and market growth often dominate the headlines, it is the unseen architects of security; those who build networks, certify platforms, and prevent fraud, who keep the industry running safely. Our index recognises the individuals whose work has made regulated gambling more robust and accountable.
At the forefront sits Michael Tobin and Continent 8, a combination synonymous with dependability. Tobin’s insistence that infrastructure and protection be treated as primary products reshaped operator expectations. Continent 8’s global private network and early investment in DDoS mitigation set a new standard: resilience scaled to match a multinational customer base, not merely reactive defence. That mentality reduced downtime, preserved revenues and, crucially, protected players’ trust across jurisdictions.
James Maida is another figure whose technical authority and regulatory fluency have been pivotal. His work translates complex compliance demands into operational reality, ensuring that testing and standards are not abstract ideals but everyday processes. Laboratories such as Gaming Laboratories International, (GLI), provide the evidential backbone for the industry’s integrity. Through rigorous testing, certification and a global presence, GLI turns regulatory requirements into actionable milestones for operators.
GeoComply’s founders, Anna Sainsbury and David Briggs, deserve special note. Their geolocation technology solved a puzzle that many thought insoluble: how to allow regulated gambling across a federated patchwork of US states without compromising on legal certainty. GeoComply’s solutions enabled pay-to-play markets to open while keeping operators on the right side of local laws. In doing so, Sainsbury and Briggs not only created commercial opportunity; they preserved the principle that regulated markets must be compliant if they are to earn public trust.
Security in gambling can sometimes be framed as a cost centre. The Security 10 asserts the opposite: that security is strategic. Leaders on this list have shown that investment in protection and verification is also an investment in growth, trust and longevity. For operators, regulators and players, their work has changed the parameters of the game and resilience.
This index is a recognition that the industry’s ability to scale responsibly rests on solid foundations. The Security 10 applauds those who build those foundations; quietly, insistently and without fanfare, because without them modern gambling would be smaller, riskier and far less sustainable.
Taken together, the names on this list reflect a common trait: an unwillingness to accept compromise when it comes to security. Their innovations are not merely technical feats; they are commercial enablers.
https://www.gamblingiq.co.uk/news
Michael
Continent 8 Tobin 01
Michael Tobin founded Continent 8 in 1998 after spotting demand for data-centre services while working as a chartered accountant. Early contracts with gaming pioneers prompted a strategic pivot to iGaming and accelerated international expansion. Continent 8 launched DDoS mitigation in 2004 and established operations in the Isle of Man in 2006; a New Jersey data centre followed in 2019 to serve US sports betting. The firm’s private network now spans more than a hundred jurisdictions and hosts major operators, suppliers and anyone connected to the industry. Tobin has long argued that infrastructure and security must be core products: under his watch Continent 8 created C8 Secure and Threat Exchange to integrate protection, detection, response. He emphasises resilience and sustainability; the group holds ISO 50001 certification for energy management. Celebrated in industry circles, he was inducted into the SBC Sports Betting Hall of Fame in 2024. In the future, he sees AI as both test and opportunity, but insists that “trust will remain stubbornly human.”
IQ Comment
Michael Tobin is one of gambling’s rare figures who combines respect with genuine popularity; a feat almost impossible in an industry as volatile and scrutinised as ours. His reputation isn’t built on flash or hype, but on steady, practical leadership, curiosity about technology, and an ability to make complex challenges seem manageable. Operators, regulators, suppliers and colleagues value his clarity, his evidence-backed thinking, and his long-term approach to partnerships. After nearly 30 years, his standing signals more than success: it reflects consistency of character, reliability and a human touch in a sector that often forgets both.
James Maida, Founder & CEO, Gaming Laboritories International, (GLI)
JAMES MAIDA GAMING LABORATORIES INTERNATIONAL,
On June 23, 1989, James Maida joined forces with Paul Magno to create GLI with world headquarters located in Toms River, New Jersey, USA. Now the world’s dominant gaming testing lab, GLI operates more than 30 offices and 1,600+ staff, offering certification, standards and cybersecurity across land based, online and sports betting markets. Maida & co-founder Magno’s pitch has not changed: speed without compromise. GLI promises to get products to market on time and on budget, provided they meet rigorous regulatory standards. That dual emphasis on timeliness and integrity has made GLI indispensable to operators and regulators alike. Under his stewardship GLI has expanded its remit as the industry has evolved, buying specialist firms, adding security divisions and drafting standards such as the Gaming Security Framework. It runs regulator roundtables, trains officials and travels to nascent markets to translate technical requirements into workable policy. That combination of technical muscle and regulatory diplomacy gives GLI unusual leverage: it helps shape standards and then enforce them.
IQ Comment
A law graduate from Rutgers State University in New Jersey, and another Hall of Famer, industry legend, James Maida is a true Defender of Trust. His challenge now is institutionalising that expertise for a wider field: codifying standards for emerging technologies, recruiting specialised testers and scaling security offerings while retaining quality. GLI’s heft gives it sway, but sustaining credibility depends on evidence, independence and the judgement to lead regulators rather than chase them. Maida remains hands on, steering strategy through steady expansion. Globally. And he has matched GLI’s scale with operational muscle: a recent global hiring surge and a dedicated innovation team aim to cut turnaround times and embed specialist skills for AI and cybersecurity. He has been vocal on the need for industry standards around AI and data integrity, pushing for modular, auditable controls.
03
DAVID BRIGGS
GEOCOMPLY
Englishman David Briggs co-founded GeoComply and helped build the technical foundations that enabled regulated online gaming to scale globally. Working alongside wife and co-founder Anna Sainsbury, he was instrumental in developing the infrastructure that allowed digital platforms to verify legitimate users in real time — a prerequisite for the growth of modern online betting and other high-risk digital markets. Much of today’s regulated industry would not exist in its current form without the systems Briggs helped put in place.
Scale and audience matter. GeoComply now processes more than 2.5 billion checks every month, operating at a level that makes its technology a critical layer for fraud prevention and identity verification across gaming, financial services, fintech, media and entertainment. That scale supports real-time fraud prevention and identity verification across highly dynamic, high-volume digital environments.
IQ Comment
Briggs entered the online gaming industry in the late 1990s, joining British gambling company Ladbrokes in 1999 to launch its online division, and later serving as Managing Director. That early experience — building digital products before regulatory frameworks and industry norms were fully established — shaped his long-term approach to product design: systems built to adapt as markets, rules and user behaviour evolve. Today, as GeoComply’s Co-Founder & Chief Product and Technology Officer, he remains focused on platform architecture, resilience and scale. Beyond GeoComply, Briggs also made a lasting contribution through the Challenger Series, a founder-led initiative designed to pass on hard-earned lessons from earlier waves of growth. By helping new companies avoid repeating past mistakes, the series supported healthier competition and contributed to an industry better positioned to grow and thrive. The final edition, held at G2E in October, marked the close of a programme that influenced the direction of the wider gaming ecosystem.
David Briggs, Co-Founder & Chief Product and Technology Officer
GeoComply
Johnny Ayers has built Socure into a leading provider of digital identity and fraud-risk tools for regulated industries. Founded in 2012, the company is now valued at around $4.5bn valuation and reported verifying allmost 3 billion identity requests in 2024, covering some 370 million unique identities, and now serves 3,000 organisations and 4 billion end-users across banking, fintech, government, telecoms and gambling. Under Ayers’s leadership the firm has broadened its platform: it purchased Effectiv to add real-time risk decisioning, integrated those capabilities into its RiskOS workflow engine, and launched Signals to provide granular fraud telemetry. Recognition has followed. Socure has been named to CNBC’s list of the world’s top fintech companies and has received Datos Impact awards for digital identity verification and first-party fraud solutions. Ayers, an Ernst & Young Entrepreneur of the Year winner, sells a straightforward proposition: higher automated approvals, fewer false positives and faster onboarding. The company supplies identity services to major operators, including DraftKings, anxsd is pushing further into payments and public-sector identity programmes. Ayers has led as a data-driven gatekeeper, turning identity and behavioural signals into measurable, auditable decisions for institutions keen to grow while keeping regulators onside.
Johnny Ayers, Founder & CEO Socure
04 Ayers Johnny IQ Comment SOCURE
Socure’s move into iGaming was signalled by a high-profile tie-up with DraftKings, which Ayers called “a privilege” and “a significant milestone for us as we continue to expand our presence in the online gaming industry.” He added that it was “an exciting time… the industry is growing at such a tremendous pace,” and framed Socure’s role plainly: help operators meet compliance while allowing “continued, unimpeded responsible growth.”
This is not puff. Ayers, an Ernst & Young Entrepreneur of the Year, sells a simple proposition — faster sign-ups, higher auto-approval rates, fewer false positives. The man is also oddly charismatic: a former college athlete whose bungled punt taught him resilience — his coach’s offhand “it can’t get any worse than that” became an operational mantra — Ayers prizes controlled experimentation and a culture that tolerates failure.
Named by Goldman Sachs as one of the Top 100 Entrepreneurs of 2021, 2022, 2023 and 2024. Outside of Socure, he is an investor/advisor to Acorns, Astra, Bask, BillGo, Chipper Cash, Coast, Covered, HMBradley, Lemon Perfect, Moov, Public, Rillet, and Treasury Prime.
Bruce Lowthers is CEO of Paysafe and has led a strategic turnaround focused on strengthening regulated payments, advancing secure transaction technology and accelerating product innovation. Lowthers prioritises scalable, compliant solutions for the gambling industry — from instant bank payouts to tokenisation and fraud prevention — positioning Paysafe as a trusted backbone for operators. A fintech leader with over two decades’ experience in payments, Lowthers joined Paysafe from FIS where he held senior roles including President. Under his stewardship the company has tightened governance, reduced leverage and deepened operator partnerships across North America and Europe. Combining operational discipline with payments engineering expertise, Lowthers aims to make safe, reliable payments infrastructure a competitive advantage for both operators and players and to protect player funds globally.
Bruce Lowthers, CEO & Executive Director Paysafe
Bruce Lowthers
PAYSAFE
IQ Comment
He has emphasised payments technology as the foundation of trust in gambling and has delivered on that promise. His leadership has pivoted Paysafe from financial restructuring to investing in secure, scalable infrastructure: instant bank transfers, tokenisation, real-time fraud detection and robust reconciliation systems. These capabilities are not optional features but the backbone that enables regulated operators to offer safe player experiences while meeting AML and KYC obligations. Lowthers’s background at FIS gives him the institutional knowledge to oversee complex integrations with sportsbooks, lottery platforms and white-label operators, reducing friction and risk. Public statements and appearances show a pragmatic focus on engineering discipline, data-driven risk controls and partnerships with banks and fintechs to expand regulated rails in North America and Canada.
Execution challenges remain — rolling out instant payouts at scale, harmonising compliance across jurisdictions and converting product investments into margin recovery. Yet the strategic emphasis on payments safety positions Paysafe as a custodian of player funds and trusted middleware for operators. For Defenders of Trust readers, the takeaway is simple: in modern iGaming the resilience and transparency of payments systems determine brand reputation as much as product design. Lowthers knows this, and his bets on technology has defined Paysafe’s credibility industry-wide.
The Sever Brothers
Sumsub AND Vyacheslav Zholudev
(Pictured from left), Vyacheslav Zholudev, and brothers Peter, Andrew and Jacob Sever. They founded Sumsub after recognising that traditional verification systems were often inaccurate and created friction by slowing onboarding & compliance processes
Peter, Andrew and Jacob Sever co-founded Sumsub in 2015, along with Vyacheslav Zholudev, noting that existing identity-verification tools struggled to stop sophisticated document and image fraud, which slowed onboarding and compliance. Andrew (Andrey) Sever, a physicist by training, serves as CEO and leads global strategy and expansion, while Peter is Chief Strategy Officer focusing on product-market fit and growth, and Jacob drives engineering and anti-fraud R&D as Chief Innovation Officer. Starting from a small team with roots in image-forgery detection, the brothers married computer-vision expertise to commercial rigour to build a full-cycle verification platform that unites KYC, KYB, transaction monitoring and fraud prevention. Under their stewardship Sumsub has scaled rapidly, serving thousands of clients with hundreds of employees across multiple offices and target verticals including fintech, crypto and iGaming. The Severs emphasise reusable, privacy-aware verification, high pass-rates and faster onboarding; a message reinforced in interviews and press coverage that positions Sumsub as a partner for compliance teams worldwide. Their family-led founding story, technical pedigree and relentless product iteration explain how a project born from anti-photo-editing research became a global regtech vendor trusted for verification and fraud prevention; today the brothers continue to speak widely on fraud trends, AI risks and compliance best practice for regulated sectors and beyond.
Charles
Mizzi
MALTA GAMING AUTHORITY, (MGA)
Charles Mizzi is Chief Executive Officer of the Malta Gaming Authority, steering the regulator with a clear mandate: strengthen trust through tougher, more tech-literate supervision. He has prioritised modernising the Authority’s toolkit; bolstering compliance capacity, sharpening enforcement and embedding data-driven oversight across AML, safer-gambling and integrity work. Under his leadership the MGA has published its 2024 annual report highlighting enhanced regulatory activity and stronger governance, and overseen new cross-border cooperation agreements to improve intelligence sharing. Mizzi also championed the Authority’s ESG agenda and the roll-out of ESG Code approval seals for licensees, signalling an expectation that sustainability and governance practices are central to industry legitimacy. His approach balances market competitiveness with an insistence that robust regulation is the foundation of consumer and investor confidence
IQ Comment
He has reframed regulation as the active defence of trust. Rather than treating oversight as a passive checklist, he has pushed the MGA to act as a proactive, technically fluent supervisor, one that understands payments rails, real-time monitoring and the data signals that reveal money-laundering or harm. That shift is visible in three concrete moves: strengthening the Authority’s resourcing and people capability to keep pace with fast-moving product innovation; formalising cross-jurisdictional co-operation (notably with the UKGC) to speed intelligence sharing and joint responses; and embedding non-financial standards through the voluntary ESG Code and the first issuance of ESG approval seals to licensees. These are not cosmetic changes — they recalibrate the risk calculus for operators by linking licence privilege to demonstrable governance, player protection and transparency.
Charles Mizzi CEO, MGA
Robin Tombs Co-Founder, CEO, Yoti
IQ Comment
Robin Tombs treats identity tech as infrastructure for trust. He has focused Yoti on two linked goals: build privacy-preserving verification that regulators can rely on, and make that capability interoperable with formal trust frameworks so operators can adopt it at scale. That strategy is visible in Yoti’s public engagement and delivery: sustained R&D into non-identifying facial age estimation and verified credentials, plus recent moves to secure formal certification under the UK Digital Identity & Attributes Trust Framework (DIATF). These steps reduce ambiguity for firms needing compliant age checks and identity proofing while signalling to regulators that Yoti aims to meet auditable standards. Tombs is also active in the policy conversation, pushing back on inaccurate reporting, explaining error rates, and arguing that pragmatic, transparent deployment of age assurance is preferable to unmanaged, inconsistent approaches.
Robin Tombs
YOTI
Co-founder and Chief Executive Officer of Yoti, the UK digital identity and age-assurance company he helped establish to put privacy-preserving ID on people’s phones. He combines serial-entrepreneur experience as a co-founder of Gamesys with a long focus on trustworthy identity systems, leading product, engineering and policy strategy as Yoti scales into regulated markets. Tombs has steered Yoti toward certification and interoperability with formal trust frameworks, and has emphasised privacy-first approaches to facial age estimation, verified credentials and attribute services for platform partners. Under his leadership Yoti has grown commercial relationships across major tech platforms while publicly engaging on the policy implications of age assurance and reusable digital ID. Tombs positions Yoti as a technical and ethical partner for operators and regulators seeking dependable, privacy-aware identity rails.
Rasmus
Kjaergaard
MINDWAY
As CEO, Rasmus Kjaergaard has grown Mindway AI from a small startup to the fastgrowing software company it is today. Rasmus’ focus is on the commercial and strategic development of Mindway AI through product innovation, partnerships, and market expansions. Rasmus is deeply invested in the safer gambling agenda and a firm believer in the power of partnerships and collaboration in the pursuit of better player protection. Rasmus has +20 years of experience in leadership and B2B sales of complex tech solutions and services in both to private and public sectors.
Mindway.ai
Mike Dreitzer
NEVADA GAMING CONTROL BOARD
Mike Dreitzer is Chairman of the Nevada Gaming Control Board (NGCB), appointed by Governor Joe Lombardo in June 2025. He brings over 25 years of experience in gaming regulation, law and industry leadership, including service as a Nevada Deputy Attorney General and senior roles at Gaming Arts, Ainsworth Game Technology and BMM Americas. As chairman, Dreitzer leads regulatory oversight of Nevada’s gaming industry, focusing on modernisation, transparency and efficient enforcement while upholding public confidence. He holds degrees from Cornell University and Emory University School of Law and has lived in Nevada for decades.