
The Gambling Regulatory Authority (GRA) has confirmed that it is investigating allegations against several licensed betting operators following claims that they unlawfully benefited from subscriber data allegedly obtained through a major data breach.
In an email to a citizen who has lodged a formal complaint, the regulator confirmed that investigations are ongoing into allegations raised against the licensees.
"Kindly be informed that the Authority is still actively handling the matter. We are conducting investigations into the allegations raised against the licensees to establish the facts and determine the appropriate action," the Authority in communication with the complainant identified as complainant Benedict Kabugi.
"We appreciate your patience and assure you that you will be informed of the outcome once the investigations are concluded," it added.
The confirmation marks the first public indication that the regulator is examining the allegations following the formal complaint lodged by the citizen with both the Director of Criminal Investigations (DCI) and the Director General of the Gambling Regulatory Authority.
In his complaint dated May 19, 2026, Kabugi asked the two agencies to investigate three licensed betting firms over alleged unlawful acquisition and use of subscriber data.
He also sought the suspension of their operating licences pending investigations.
The complainant alleged that the subscriber information had been harvested by former employees of one of the telco companies and shared with the betting firms in violation of the law.
He claimed the companies unlawfully obtained subscriber data that had allegedly been accessed by former employees of the telecommunications company and shared for financial gain.
According to the complaint, the alleged sharing of the data enabled the betting firms to improve customer acquisition, increase sales and enhance their profits through targeted marketing.
The complainant further argued that findings contained in DCI forensic investigations indicated that the alleged breach was not an isolated incident but occurred over an extended period and involved substantial volumes of subscriber information.
He also questioned why no regulatory action had been taken against the alleged recipients of the data despite ongoing criminal and civil proceedings involving former employees accused of illegally accessing subscriber information.
In the complaint, the citizen cited the High Court judgment in Constitutional Petition E095 of 2026, delivered on May 13, 2026, arguing that the court had found there was "a sustained and systematic compromise of subscriber data."
He further alleged that the compromised information was systematically shared with betting companies and other third parties, who allegedly used it for targeted marketing and behavioural profiling of subscribers engaged in gambling activities.
Sources familiar with the investigations said the DCI has formally requested extensive records from the Gambling Regulatory Authority as part of the ongoing inquiry.
The investigators requested all records held by the regulator relating to the licence holders, including licensing information, past complaints, due diligence records and statutory returns covering the period from 2018.
The investigations come months after the High Court found that the constitutional rights of 11 subscribers of one of the telcos had been violated following the unlawful disclosure of their personal data.
Justice Bahati Mwamuye awarded each of the 11 petitioners Sh900,000 in general damages after finding that their rights to privacy, dignity and consumer protection had been infringed.
According to the judgment, the petitioners alleged that between 2018 and 2019, former employees unlawfully accessed and transmitted sensitive subscriber information to third parties, including betting companies, without consent or lawful authority.
The court said the information allegedly shared included financial transaction data, betting activity, device identifiers and geolocation information.
The petitioners argued that the breach was facilitated by weaknesses in internal controls that allegedly allowed employees unrestricted access to subscriber databases.
They further relied on forensic material and internal communications, alleging that subscriber data was repeatedly shared through platforms including WhatsApp, Google Drive and email for commercial purposes.
The telco opposed the petition and denied liability.
The company argued that the alleged breach resulted from criminal acts by former employees acting outside the scope of their employment for personal gain.
It also maintained that there was no proof that the petitioners' individual data had been accessed or compromised and disputed claims that millions of subscribers had been affected.
In its judgment, however, the High Court held that the evidence presented was sufficiently corroborated by independent records, including internal communications and material produced by the telco.
The court found there was sufficient evidence of a systemic compromise of subscriber data during the period under review and held that the petitioners' constitutional rights had been violated.
The judgment awarded the 11 petitioners a total of Sh9.9 million in damages, in addition to costs and interest.