A Hacker Says She Watched Curaçao's Regulator for Nine Months and Will Publish Every Owner
By Antonina Tupikova · Founder, iGaming Times2 min read
Lilith Wittmann has claimed responsibility for the breach the Curaçao Gaming Authority disclosed this morning, says she has had access since December 2025, and has begun releasing material with broadcasters in five countries. She says the full list of ultimate beneficial owners is still to come.
- The German activist Lilith Wittmann has revealed she is behind the breach at the Curaçao Gaming Authority and says she will release the full list of ultimate beneficial owners, NEXT.io reports
- She announced this morning that she has had access to the CGA's systems since December 2025, and claims to hold information on the owners, the finances and the regulating processes behind casinos licensed on the island
- In a coordinated campaign across publications in five countries she has released details about licensees including entities allegedly associated with 1Xbet, Stake.com, SoftSwiss and Platinum Casino
- Wittmann says it took her less than eight hours, after logging into the regulator's web portal under a false identity, to exploit what she describes as an easily identifiable security vulnerability and gain full access to the authority's servers and its licence management portal
- She admitted responsibility for a similar breach at the Malta Gaming Authority earlier this year; the MGA, represented by Bird & Bird LLP, has since reportedly served her a 1,300 page preliminary injunction preventing her from making certain statements about the regulator
Nine Months Inside the Portal, and the Owners' List Still to Come
The unauthorised access that Curaçao's gambling regulator disclosed this morning has a name attached to it. The German activist Lilith Wittmann said on Tuesday that she is responsible, that she has had access to the Curaçao Gaming Authority's systems since December 2025, and that she intends to publish the full list of ultimate beneficial owners behind the island's licensees.
"For nine months, I watched the Curaçao gambling authority at work in real time, without the staff knowing," Wittmann wrote in a LinkedIn post reported by NEXT.io. "I could see who owned illegal online casinos, who was financing them, and what the authority knew about their operations. Today, in collaboration with NDR, NRK, SVT, and FTM, I am publishing the #casinosecrets."
Her account of how she got in is brief. Writing on her own website, she described logging into the regulator's web portal for the first time under a false identity, using an email address that could be traced back to her but under a different name. "From then on, it took less than eight hours for me to exploit an easily identifiable security vulnerability and gain full access to the gambling regulator's servers," she wrote. "This also gave me access to the web portal used for licence management. From then on, I could read every application and every document submitted to the authority."

The first tranche, released with broadcasters and outlets in five countries, covers licensees including entities allegedly associated with 1Xbet, Stake.com, SoftSwiss and Platinum Casino. The ownership list is held back. A CGA spokesperson told NEXT.io that the authority "is committed to staying transparent and we will be releasing a statement presently."
Nine Months of Undetected Read Access Is a Supervisory Failure, Not Only a Security One
A vulnerability that takes eight hours to find is a technical problem with a technical fix. An intruder reading every application and every filing for nine months without anyone noticing is a different category of failure, because detection, not prevention, is what a supervisor is supposed to be good at. The CGA's own notice said it had found no compromise of core infrastructure and had not yet established what information was reached. Those two statements are hard to hold alongside a claim of full server access dating to December, and the regulator now has to reconcile them in public.
Publishing the UBO List Would Do the Reform's Work Without the Reform's Consent
Collecting ultimate beneficial ownership was the point of Curaçao's licensing overhaul. The island moved from master licences and sublicences to direct regulatory relationships precisely so that somebody official would know who was behind each operator. If that register reaches the public through a hacker rather than through the regulator, Curaçao loses the argument it has been making for three years, that it is now a jurisdiction where ownership is known and checked. It would also expose people who filed under an expectation of confidentiality, some of whom will have done nothing more than apply for a licence, which is why the disclosure is contested rather than simply useful.
The Malta Injunction Is the Template Other Regulators Will Reach For
Wittmann has been here before. After the Malta Gaming Authority breach, the MGA's lawyers reportedly answered with a 1,300 page preliminary injunction restraining what she may say. That is the instinctive institutional response, and it does nothing about the vulnerability, the nine months, or the ownership data now sitting outside the building. A regulator whose credibility rests on knowing who owns its licensees cannot litigate its way back to that position. Curaçao's statement, when it arrives, will show which lesson it took from Malta's.
Curaçao spent three years arguing that it had become a real regulator. The test of that claim is no longer the licensing reform but what the authority says about the nine months it did not notice.


