Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Regulatory

Hacker Says Berlin Court Let Her Keep Using the MGA Documents She Took

Antonina TupikovaBy Antonina Tupikova · Founder, iGaming Times2 min read
Courtroom interior

The Malta Gaming Authority and its chief executive sought an injunction in Germany against Lilith Wittmann. She says the Berlin judgment bars her from hacking the regulator again but lets her use its documents. The court has not published its reasoning.

  • Lilith Wittmann, the Berlin security researcher who claimed the Malta Gaming Authority (MGA) breach in March, posted the first page of a judgment from the Berlin Regional Court II on 25 September
  • The page names the MGA and its chief executive Charles Mizzi, personally, as applicants in preliminary injunction proceedings, represented by Bird & Bird, with Wittmann as respondent, according to European Gaming
  • Wittmann says the judgment lets her use the documents she obtained and describe the MGA in the terms she has used, but bars her from accessing its systems again; the reasoning has not been published and her account cannot yet be checked
  • She has called the case a SLAPP; the MGA said in March that allegations made in the context of unauthorised access were "unsubstantiated"
  • The ruling comes days after Wittmann and media partners began publishing from a separate leak of the Curaçao regulator's files

A Regulator Sues Its Own Hacker in Germany

The Malta Gaming Authority disclosed a breach of one of its systems on 17 March 2026, saying it appeared to be attributable to someone presenting themselves as a security researcher. Lilith Wittmann, a Berlin-based researcher, publicly claimed responsibility, and on 20 March the MGA said allegations made "in the context of unauthorised system access are unsubstantiated and do not undermine the MGA's role as a regulator committed to transparency, due process and the rule of law", as we reported at the time.

The regulator then went to court in Germany. On 25 September Wittmann posted on X the first page of a judgment ("Urteil") from the Landgericht Berlin II, the Berlin Regional Court II, in preliminary injunction proceedings under reference 7 O 254/26 eV, according to European Gaming. The page lists the MGA, represented by its chief executive Charles Mizzi, as first applicant and Mizzi in a personal capacity as second, with the Frankfurt office of Bird & Bird acting for both.

Wittmann's own summary is the only public account of the outcome. She wrote that the judgment allows her to use the documents she obtained and to keep describing the MGA as an "organized crime enablement scheme", a characterisation the regulator rejects, but that she is not allowed to hack it again. The court's reasoning has not been published, and it is not known whether either side will appeal. The MGA had not commented publicly on the judgment at the time of writing.

iGaming glossary: 430+ terms explained.

In an interview with the German tech site heise online in July, which heise decided not to run over legal concerns and which she later published herself, Wittmann said the MGA had earlier obtained a preliminary injunction under German press law barring her from entering its systems and from repeating a statement about it. She described the case as "a completely classic SLAPP", a strategic lawsuit against public participation, and said she had created an account on a portal the MGA uses to receive data from licensees and downloaded more than 3,000 documents about a subset of companies, according to European Gaming.

If Her Account Is Right, the Injunction Protected the Systems, Not the Reputation

Preliminary injunction proceedings in Germany can be decided on a mix of claims, and the outcome she describes is a split: the court accepted the regulator's interest in not being hacked again but, on her account, declined to stop her using what she has or characterising the regulator as she does. For a public authority that is a meaningful distinction. German courts give wide latitude to opinion on matters of public interest, and a regulator suing a critic over speech invites the SLAPP label she has already attached. Until the judgment is published, the scope of what she may say, and on what factual basis, is unknown, and her summary of a partial page is not a substitute for the court's reasoning.

The MGA's Problem Is the Documents, Not the Judgment

Whatever the court decided about words, the practical exposure for Malta is the 3,000 documents Wittmann says she took from its licensee portal, and the model her Curaçao work has now established: data released with broadcasters and investigative outlets rather than dumped. The Curaçao leak has already produced reporting on the ownership of licensees. For Maltese licensees, the question is whether their compliance filings are among the documents she says she took, and the MGA has not publicly said what was accessed.

The only public account of the Berlin judgment comes from the hacker it was brought against. Until the court publishes its reasoning, the MGA's legal position, and Malta licensees' exposure, remain unclear.

Sources

Citations and primary documents this article references. Captured at the time of writing.

Comments

Be the first to comment.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.