NHS Stroke-Recovery App Site Hijacked, Now Pushes Casino Ads

A website built by the NHS to help stroke and brain-injury patients choose safe rehabilitation apps has been hijacked and now promotes unlicensed offshore casinos, Gambling.com has confirmed.
My-Therappy.co.uk, launched in 2013 by the Neuro-Rehabilitation Team at Northern Devon Healthcare NHS Trust, currently displays content titled “Non UK Casinos 2026 – Best Foreign Casino Sites” in place of its original app review resource.
The trust merged into Royal Devon University Healthcare NHS Foundation Trust in 2022, and the stroke-app site had continued to operate as a clinical resource for therapists and patients until the takeover.
What The Hijacked Page Now Shows
Gambling.com independently accessed my-therappy.co.uk and confirmed the domain now serves online casinos content, including sections promoting “Non UK Casinos” and “Betting Sites Not on GamStop,” the term for operators outside Britain’s licensing regime that let customers sidestep the UK’s national self-exclusion scheme entirely.
The page carries a byline for a “Daniel Reeves,” described in an author bio as “a seasoned writer and analyst specialising in online casinos, sports betting and iGaming trends for UK audiences,” alongside copy encouraging readers to move away from GamStop-registered operators.
NHS Trust Confirms It Is Investigating
Royal Devon University Healthcare NHS Foundation Trust confirmed the breach after being approached by Digital Health News, the specialist healthcare-IT publication that first identified the compromised domain.
A trust spokesperson said the matter had been escalated internally.
“We have raised this with our digital and cyber security teams for investigation,” the spokesperson said.
“We are currently establishing the status of the website domain and will provide a further update once we have completed our enquiries. We take matters relating to online safety and security seriously and are looking into this as a priority.”
Part Of Wider Pattern Of Hijacked Public Sites
The incident is the latest in a run of UK public-sector web domains being repurposed to push gambling content once their original owners stop maintaining them.
In August, Gambling.com reported that 16 links on the Scottish Borders Council’s own directory had been hijacked to redirect residents to offshore casino sites, with most of the affected pages traced back to a defunct local directory service that had gone unmaintained for years.
Legacy, unmonitored web addresses tied to public bodies appear to be a recurring target.
Why This Matters For Players
For players, the case is a reminder that a page with an NHS domain history or design does not guarantee who currently controls it.
Sites operating outside the UK Gambling Commission’s licensing regime, including ones explicitly marketed as bypassing GamStop, are not subject to the same player-protection, complaints and responsible-gambling requirements as licensed operators, and consumers have far less recourse if something goes wrong.
Anyone directed to an unfamiliar casino site from an old NHS or council link should treat it with the same caution as an unsolicited email or text.



