Key Points
- Wittmann claims she exploited a security flaw within eight hours of accessing the CGA portal and monitored casino ownership data for nine months undetected.
- Dutch investigators from Follow the Money verified 897 UBO records across 646 Curaçao gambling entities, with a further 24 Americans identified among connected individuals.
- The breach follows Wittmann’s earlier MGA hack in March 2026, making her the only known individual to have breached two major gaming regulators within the same year.
Lilith Wittmann did not rush. From December 2025, the German activist says she watched the Curaçao Gaming Authority manage its licensees in real time, reading every application filed and every document submitted to the regulator’s portal, for nine months, while its staff remained unaware. When she finally spoke, she did so across publications in five countries simultaneously, and announced that the full list of ultimate beneficial owners behind hundreds of offshore casino licences is still to come.
In a LinkedIn post on 22 September, Wittmann wrote: “For nine months, I watched the Curaçao gambling authority at work in real time, without the staff knowing. I could see who owned illegal online casinos, who was financing them, and what the authority knew about their operations. Today, in collaboration with NDR, NRK, SVT, and FTM, I am publishing the #casinosecrets.”
How Wittmann Claims She Got Inside the CGA?
In her own telling, Wittmann accessed the CGA’s online portal using a fake identity and, within eight hours, discovered a flaw in security which allowed her to gain access to the regulators’ servers and licence-management systems.
The CGA had issued a statement about the breach on 18 September, four days before Wittmann came out with her identity. In the statement, the CGA revealed that it was aware of an unauthorised access to its system, that it had activated its incident response protocols immediately, and that a forensic investigation was underway. CGA said that it had not yet found any breach of its core technical infrastructure but added that it was still assessing the situation. Following Wittmann’s disclosure, a CGA spokesperson told NEXT.io: “The CGA is committed to being transparent, and we’ll be putting out a statement shortly.”
What the Leaked Files Actually Show?
The first wave of material published in coordination with investigative journalists already carries considerable weight. Dutch outlet Follow the Money verified 897 UBO records representing 767 individuals across 646 Curaçao gambling entities. Separately, GamblingHarm’s reporting on FTM’s analysis identified 24 Americans among people connected to Curaçao gambling companies as current or former ultimate beneficial owners.
Named entities in the coordinated publications include businesses allegedly linked to 1xBet, SoftSwiss, and Platinum Casino. Stake, publicly promoted by rapper Drake and connected to Ed Craven and Bijan Tehrani, appears in the leaked files registered under a different corporate name, leaving unresolved questions about its formal ownership structure. One Dutch owner of Blaze.com declared assets of €800 million in the leaked filings, while his American co-owner reportedly declared €500 million.
According to iGamingToday’s reporting on the leaked documents, licences were sometimes continued despite the transfer of 350 casino domains without player notification, which auditors described in the files as “unfair.” The same reporting flagged criticism of the use of AskGamblers as an arbitration board in one case, on grounds of its business ties to the applicant. The CGA told iGamingToday the industry was in a transition period under the new law, and that the security gap allowing Wittmann’s access had since been closed.
Wittmann has stated she intends to publish the complete UBO list, which would expose the individuals behind a significantly larger set of offshore operations than what the initial release covers.
The Second Gaming Regulator Wittmann Has Breached This Year
The CGA is not the first major gaming regulator to find itself in this position. In March 2026, Wittmann claimed responsibility for breaching the Malta Gaming Authority, writing directly to the regulator in a LinkedIn post: “Yes, I hacked you, and the data obtained has been shared with media partners, authorities.” The MGA condemned any unauthorised access to its systems and described her allegations as “unsubstantiated.”
The MGA’s legal response was pointed. Represented by Bird & Bird LLP, the authority served Wittmann with a 1,300-page preliminary injunction restricting her from making certain statements about the MGA and further access to its systems. A legal instrument of that scale in response to a single individual is unusual; Wittmann, who is affiliated with the Chaos Computer Club, which describes itself as Europe’s largest association of hackers, did not change course.
Prior to the regulatory breaches, Wittmann had compromised data of about 800,000 gamer accounts in Germany by abusing an open API belonging to Merkur Gaming in early 2025. Her attacks have progressively become bigger, and her approach has shifted from targeting weaknesses in operators to targeting the regulators.
The Regulator That Was Rebuilding Its Reputation When the Breach Happened
There is a certain sharpness to the timing. The launching of the CGA’s online licensing service itself was the outcome of Curaçao’s recent regulatory revamp. The National Ordinance on Games of Chance (LOK) came into force on 24 December 2024, thus finally replacing the existing master licence regime that facilitated the operation of numerous offshore companies without much control. One of the key features of the LOK was that the final beneficial owner would be subject to a background check, and the CGA would issue licences directly to the operator.
Wittmann says she first accessed the CGA’s portal in December 2025, a full year after that law took effect. The portal built to support the new framework contained a vulnerability she found within a working day. Separately, the CFATF’s 2025 mutual evaluation of Curaçao, endorsed by FATF, found that the supervisory framework for online gaming operators was not yet fully operational at the time of its June 2024 on-site visit, and that only limited inspections had been conducted. Wittmann’s access period overlapped directly with the transition the CGA was midway through.
Expert Analysis
We have covered offshore gaming regulation long enough to recognise what is actually being exposed here, and it is not just a cybersecurity story.
Two major gaming regulators have now been breached by the same individual within one year. The MGA responded with a 1,300-page injunction. The CGA responded with forensic investigators and a commitment to transparency. Neither authority caught Wittmann during her access periods; in the CGA’s case, she says that period lasted nine months. What changed in both instances was Wittmann’s own decision to come forward.
The harder question sitting inside the leaked files is not who got hacked. The leaked documents reportedly show licences continuing despite unresolved ownership questions, domains moved without player warning, and ownership structures deliberately kept opaque, all within a system that was, on paper, being reformed. The LOK was sold to Curaçao’s parliament and its international partners as the answer to exactly these problems.
We are not suggesting the CGA acted in bad faith. Reform processes are slow and transition periods are messy, and the CFATF’s own evaluation notes the framework was mid-implementation. What we are suggesting is that the gap between what Curaçao’s new regulatory law promised and what Wittmann actually found inside the portal is large enough to be a story in its own right, separate from the breach itself. The injunction served on Wittmann by the MGA may slow what she says publicly. It has not, so far, slowed what she publishes.