Casino Check ZASouth Africa’s licence and complaint evidence desk · Latest publication 12 August 2026

CLONE WARNING · DOMAIN CHECK

How to spot a cloned betting website in South Africa

A clone can copy colours, a logo, terms and even a licence number. Identity comes from the exact domain and independent records, not from visual familiarity.

Latest publication:

Casino Check ZA evidence desk
Records first, narrow conclusions, private personal data.

MATERIAL OBSERVATIONS · 11 AUGUST 2026

Practical answer

Stop before logging in or paying. Copy the hostname, preserve the message or advert that led there, and compare the legal entity, licence, province and domain with current NGB and provincial records. Contact the genuine operator through a separately verified route. If credentials or money were exposed, contact the bank immediately.

SignalWhy it mattersVerification stepDo not do
Lookalike hostnameOne character can route to another ownerCompare the full hostname with primary recordsDo not trust the logo
Copied licence badgeImages can be reusedMatch number, entity, province and domainDo not search the number only
Message-only supportImpersonators control the conversationReach support from the typed official domainDo not share PINs
New beneficiaryMoney may leave the expected routeCheck recipient in the banking app and termsDo not send a test amount
Urgent unlock feePressure suppresses verificationConfirm against authenticated terms and bank guidanceDo not pay another transfer

Freeze the route before it disappears

Copy the full URL, including subdomain and path, and note the source that delivered it. Preserve the advert, SMS, WhatsApp message, email headers or social profile. Do not continue clicking around merely to collect more screenshots; every login or download can increase exposure. A browser capture should show date and address where possible, while sensitive fields remain hidden.

Use another device or clean browser session to type the known brand address and locate legal terms. Compare company names, licence wording and contact details. A clone may reproduce every visible word, so independent records and a separately reached support channel carry more weight than design.

Match identity through official records

The NGB verified-operator portal rechecked on 11 August 2026 is the national starting point. Search the trading and legal names, then compare the exact hostname and province. The NGB FAQs, accessed 9 August 2026, explain the provincial licensing structure, so the issuing board should resolve any uncertain domain or licence reference.

A missing match is a reason to pause, not proof of fraud. A conflicting entity or copied number is an observation to report. Preserve both the suspect claim and the official record used for comparison, including their access dates.

Recognise the payment and support pattern

The FSCA payment-scam warning, accessed 9 August 2026, describes advance-fee and bank-transfer scam patterns. An unsolicited contact demanding another payment before winnings or a withdrawal can be released should trigger a stop and independent verification.

Nedbank’s deposit and refund scam guidance, inspected 11 August 2026, adds context around fake proof of payment and refund pressure. Do not rely on an image of a banking confirmation; verify movement in the actual account.

Respond according to the harm

If credentials were entered, change the password from the genuine service and anywhere it was reused. If bank credentials, card details or an OTP were exposed, call the bank’s verified fraud channel. If money moved, give the bank the beneficiary, reference, amount and timestamp immediately. Do not delay bank action while waiting for an operator reply.

Report the suspect route factually to the genuine operator and appropriate authority. State the exact URL, how it arrived, what it displayed and what was sent. Avoid publishing identity documents or claiming a named person committed fraud without an official finding. A careful incident record is more actionable than a broad accusation.

If exposure occurredFirst recipientEvidence to keepPrivacy rule
Password enteredGenuine operator and reused-password servicesHostname, time and security alertsNever forward the password
Bank credentials enteredBank fraud channelSession time, URL and transaction alertsKeep PIN and OTP secret
Transfer sentBank immediatelyBeneficiary, reference, amount and confirmationShare redacted copies publicly
Identity document uploadedOperator, bank and relevant reporting routeDocument type, upload address and timeWatch for later impersonation
Clone still liveOperator and appropriate authorityURL, advert source and dated captureState observations, not accusations

Close a clone incident without destroying evidence

Create a read-only copy of the original chat, email or advert and record the suspect hostname as plain text. Note which device was used, what information was entered and whether the browser downloaded anything. Do not circulate a live phishing link to friends for confirmation. A redacted image or safely written hostname is enough for most initial reports.

Track every containment action: password changed, sessions ended, bank called, card blocked, operator notified and authority report submitted. Record reference numbers and advice received. If no money moved, say so. If the genuine operator confirms that the route is not theirs, preserve that response as an operator statement and still let the competent authority decide any formal finding.

A clone report should never expose the victim twice. Remove identity numbers, full bank details, passwords, one-time PINs and unrelated messages from working copies. Keep originals private for the bank or investigator. Update the record if the domain disappears or an authority publishes a notice, but retain the first dated observation.

Recheck the suspect address only through safe institutional processes; a punter does not need to revisit it to prove that it once existed. If an archive or authority later preserves the domain, record that source and date separately. Disappearance may follow many causes and is not, on its own, proof that a scam finding was made.

Review method and evidence limits

The clone checklist combines NGB primary records, NGB jurisdiction guidance, an FSCA official warning and first-party bank fraud guidance recorded between 9 and 11 August 2026. It describes observable patterns and response actions without identifying any unproven perpetrator.

Source discipline: official records support regulatory or scam-pattern statements; provider guidance explains its own service; operator statements speak only for the operator; user posts remain unverified. An incomplete record is reported as unresolved, never upgraded into an accusation.

Questions South African punters ask

Can a fake betting site use a real licence number?

It can display copied text or an image. Verify the number together with the entity, exact domain, province and product scope.

Is HTTPS proof that a betting site is genuine?

No. Encryption protects a connection to a hostname; it does not establish who operates that hostname.

What should I do after entering my bank login?

Contact the bank through a verified channel immediately, change exposed credentials and keep the suspect URL and timestamps.

Should I pay a small fee to test a withdrawal?

No. Stop and verify any extra payment demand against authenticated terms and official scam guidance.

Does a domain mismatch prove fraud?

Not by itself. It is a serious hold point that requires operator and regulator confirmation.

Source docket

  • ZA-S01 · National Gambling Board: recorded source. Primary portal; rechecked 11 August 2026.
  • ZA-S02 · National Gambling Board: recorded source. Primary jurisdiction guidance; accessed 9 August 2026.
  • ZA-S08 · Financial Sector Conduct Authority: recorded source. Official scam warning; accessed 9 August 2026.
  • ZA-S25 · Nedbank: recorded source. First-party bank fraud guidance; inspected 11 August 2026.

Continue with the scam-warning hub, the fake-support response guide or the full review method.