Eastern Cape Gambling Board was hacked The most dangerous gambling company for cooperation Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Eastern Cape Gambling Board was hacked The most dangerous gambling company for cooperation Listed by alphv Ransomware Group (reported April 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target public-sector and regulatory bodies, treating administrative networks as sources of internal documents that can be stolen and leveraged for pressure. Listings on criminal leak sites have become a routine part of that landscape, even when independent confirmation of what was taken remains thin.
On 21 April 2023, the Eastern Cape Gambling Board was named in connection with a ransomware incident attributed to the group alphv. Public reporting states that internal files were exfiltrated. The number of people affected is unknown, and wider technical detail has not been disclosed. For an organisation that oversees gambling and betting in a South African province, any confirmed loss of internal material raises practical questions for staff, licensees, and anyone whose details may sit in regulatory files.
What happened
According to available public reporting, the Eastern Cape Gambling Board was listed by the alphv ransomware group in connection with a ransomware attack in which internal files were exfiltrated. The incident was reported on 21 April 2023. The headline associated with the listing described the organisation in aggressive terms and framed it as a target for cooperation pressure, which is consistent with how such groups present victims on their leak sites.
No public figure has been given for the number of people affected. The precise method of initial access, the duration of any intrusion, the volume of data taken, and whether systems were encrypted in addition to theft have not been disclosed in the material provided. What is stated is that internal files were removed as part of a ransomware attack and that alphv publicly listed the organisation. That listing should be treated as a claim by the group unless and until independently verified.
The group behind it: alphv
alphv, also widely known in public reporting as BlackCat, is a ransomware operation that has functioned on a ransomware-as-a-service model. Affiliates gain access to victim environments, deploy the group's encryptor, and exfiltrate data before or alongside encryption. The group has been associated with double-extortion tactics: threatening to publish stolen material on a dedicated leak site if a ransom is not paid, and using public listings to increase pressure on the victim and its partners.
Public documentation of alphv activity over recent years describes use of custom ransomware written in modern languages, negotiation portals, and repeated targeting of organisations across government, healthcare, manufacturing, and professional services. The group has claimed numerous victims globally. In this case, the facts establish only that alphv listed the Eastern Cape Gambling Board and that internal files were described as exfiltrated; no further specific claims by the group about this victim are set out in the provided record, and the listing itself remains an unverified assertion from the threat actor.
Who is Eastern Cape Gambling Board?
The Eastern Cape Gambling Board is a provincial regulatory body in South Africa. Public directory information places its headquarters at Quenera Park, Quenera Drive, East London, 5201, with a listed phone number of +27 437028300 and a website at www.ecgb.org.za. It also maintains public profiles on professional and social platforms under names linked to the Eastern Cape gambling and betting board.
Bodies of this type typically license and supervise casinos, betting operators, and related gambling activities within their province. They handle applications, compliance records, inspection findings, correspondence with operators, and internal administrative files. They may also hold personal and financial information about licence holders, employees, and sometimes members of the public who interact with the regulator. A breach affecting such an organisation is consequential because regulatory files can contain commercially sensitive material, identity data, and records that third parties rely on for lawful operation. Disruption or exposure can affect oversight continuity and trust in the licensing system even when the full scope of theft is not yet public.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of specific categories such as identity documents, financial accounts, or licensee databases have been provided. The number of people affected is unknown.
Organisations in this sector commonly hold, among other things:
- Internal administrative and policy documents
- Licensing and compliance correspondence with operators
- Staff and HR-related records
- Contact and application data tied to regulated entities
- Operational notes from inspections or enforcement work
Whether any of those categories were among the files taken in this incident is unconfirmed. Exact contents remain undisclosed, and no assumption should be made that particular personal or commercial data sets were included solely because they are typical for the sector.
Why it matters
When internal files leave a regulator, the immediate risks are practical rather than abstract. Staff and contractors may face phishing or social-engineering attempts that reuse genuine internal detail. Licence holders and applicants could see commercially sensitive correspondence or compliance material appear in criminal channels, creating leverage or reputational harm. If personal data was present in the exfiltrated set—something not established here—affected individuals could encounter identity misuse or unwanted contact over time.
For the organisation, a public ransomware listing can complicate day-to-day oversight, require forensic and legal response, and force careful communication with supervised entities and provincial authorities. Because the scale and precise content of the theft are unknown, the prudent stance is to treat the incident as a serious but incompletely documented event: real enough to warrant attention, not yet quantified enough to support firm claims about every possible impact.
Were you affected?
If you work for the Eastern Cape Gambling Board, hold or have applied for a gambling-related licence in the province, or have otherwise supplied personal or company information to the board, treat the incident as potentially relevant until more detail emerges. Practical first steps include watching for unexpected emails or calls that reference internal board matters, reviewing financial and account statements for unusual activity, and using unique passwords with multi-factor authentication on important accounts. Do not assume you are unaffected solely because no public headcount has been released; equally, do not assume your data was taken when the contents of the exfiltrated files remain undisclosed.
Readers who want a concrete check can run a free exposure scan of their email address against known breach data sets. That will not confirm or deny involvement in this specific incident, but it can show whether the same address has already appeared in other publicly circulated breach collections and help prioritise further precautions.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
First Judicial Circuit - Florida Court Listed by alphv Ransomware GroupErbilbil Bilgisayar (You have 72 hours) Listed by alphv Ransomware GroupNej Inc was hacked Listed by alphv Ransomware GroupFIRST 5 Santa Clara County Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.