The General Directorate for the Regulation of Gambling (DGOJ), based in Madrid and under the Ministry of Social Rights, Consumer Affairs and the 2030 Agenda, has once again focused on a problem that is growing as fast as the sector itself: identity theft on online betting platforms. What seemed like an isolated phenomenon a few years ago has become one of the regulatory priorities of the agency, to the extent of coordinating actions with the AEAT, the Security Forces and Corps, and the health sector of the City of Madrid.
The figure that best summarises the magnitude of the problem was provided by the Ministry itself: in the last closed fiscal year, there were nearly 8,000 reports from individuals claiming to have been victims of identity theft to bet in their name. Almost 5% of those who made profits exceeding 100 euros on licensed platforms reported that those operations were not theirs. This is an uncomfortable figure, especially considering that the bulk of the fraud is concentrated in sports betting (91% of the total) and that most impersonators are family members or acquaintances of the victim.
To assist those affected, the sector has also seen a parallel culture of transparency grow, with portals that compare operators, conditions, and regulated promotions, such as the bonus 20 Euros free casino for signing up, one of the reference pages for understanding which casinos offer trial balances before depositing real money and under what legal conditions. They are not operators, but editorial comparators that analyse licenses, betting requirements, and identity verification policies, precisely the points where the DGOJ is tightening the screws.
What is the PACS protocol and why does it matter
The regulator's flagship instrument is called PACS (Protocol for Action for Impersonated Taxpayers) and was created for a situation as Kafkaesque as it is real: citizens who receive in their tax draft winnings from online gambling that they never obtained, because someone used their ID to open an account at a betting house. The first reaction is usually one of panic and disbelief, especially when the tax office comes knocking for explanations.
The protocol establishes a clear route for the affected individual: request a PACS reference via email to the DGOJ, report the case to the National Police, ask the operators for the activity certificate and the closure of the fraudulent account, and finally, transfer all documentation to the Tax Agency. If the operator does not cooperate, the citizen can download a transaction report from the regulator's electronic headquarters, which serves as proof before the tax office.
Another complementary tool is Phishing Alert, a free service that any citizen can sign up for to receive an email alert when someone attempts to register on a state gaming platform using their personal data. It functions as a kind of voluntary anti-fraud bureau and, according to the Ministry itself, has tripled its registrations since PACS was activated.
Who impersonates whom
The DGOJ has identified four recurring patterns that help to understand the phenomenon with less hyperbole and more data. The first is that of interdicts: more than 7,600 people registered in the General Register of Access Prohibitions to Gambling (self-excluded) would have played using third-party data, almost always from their family environment. The second affects minors: it is estimated that at least 8% of minors who attempt to register and are rejected end up accessing gambling with someone else's identity, usually that of parents or older siblings.
The third pattern is automation, with bots opening accounts in chains to operate intensively until blocked, at which point the cycle starts again with another stolen identity. The fourth, more sophisticated, is welcome bonus fraud: networks that open new accounts solely to capture registration promotions and then disappear. This is precisely why specialised comparators have gained traction, as resources like the guide on 50€ free no deposit help legitimate users understand which offers are real, what betting requirements they have, and why DGOJ licensed platforms tighten KYC verification before releasing any euros.
The role of the City of Madrid and public health
The latest development in the file is that the regulator has brought an unexpected actor into the conversation: the General Subdirectorate for Addictions of Madrid Health and the medical services of the City of Madrid. The idea is that identity theft should not only be tackled from the tax side but also from health prevention, especially among young people and self-excluded individuals. Official data on the complete plan can be consulted in the informative note from the Ministry of Social Rights, Consumer Affairs and the 2030 Agenda, which details the steps and the designated channels for reporting.
This cooperation between state, regional, and municipal administrations is not common in gambling matters, and reveals something deeper: the DGOJ has acknowledged that digital impersonation is primarily a public health and data protection issue, not just a matter of revenue collection. Hence the interest in extending prevention to educational centres and health professionals, who until now rarely connected screens with gambling.
What citizens can do today
The practical part is probably what interests anyone reading this with a raised eyebrow thinking it won't happen to me. The reality is that a poorly stored photocopy of an ID is enough to end up caught in this mess. The official recommendation is to register for Phishing Alert, periodically review tax data with the AEAT, not share documentation with third parties, and in case of detecting any anomalies, activate PACS without waiting for a tax notification to arrive. The quicker the report is made, the less paperwork later.
For those who want to delve into good digital protection practices applied to daily life in Madrid, the security section of Digital Madrid offers specific content on online fraud, phishing, and prevention. Because in the end, just as we have become accustomed to not leaving the keys in the car, we must get used to treating personal data with the same healthy distrust.





