Lustich.de does not operate for profit. Surpluses go into charitable projects, for example building schools and wells in Benin (West Africa). Learn more
All Casino News in English
Regulation

Curaçao Data Breach: Hacker Lilith Wittmann Threatens to Expose Casino UBOs

22 September 20266 Min.by Lisa Lustich
Editorially reviewed by Lisa LustichLast review:
Curaçao-Datenleck: Hackerin Lilith Wittmann droht mit Enthüllung der Casino-HintermännerAI-GENERATED

A massive data breach at the Curaçao gaming regulator threatens to expose the ultimate beneficial owners of all licensed operators after a nine-month infiltration.

The offshore gambling world is reeling from a digital earthquake. For years, the Caribbean island of Curaçao served as a fortress of anonymity for global gaming operators, but that era may be coming to an end. Lilith Wittmann, a German IT activist known for exposing governmental security flaws, has announced a successful breach of the Curaçao Gaming Authority (CGA). This is not a minor leak but a comprehensive exposure of the regulatory system's inner workings, threatening to pull back the curtain on the multi-billion dollar offshore industry.

Wittmann claims she gained entry to the CGA's servers in December 2025 and spent nine months observing the regulator's operations in real-time. Crucially, she asserts that she now holds information regarding the Ultimate Beneficial Owners (UBO) of licensed entities. In a coordinated release across media outlets in five countries, she has already highlighted details concerning major operators such as 1Xbet, Stake.com, SoftSwiss, and Platinum Casino. The implications are dire for individuals who have long relied on Curaçao's lack of transparency to hide their identities.

Numbers and facts

The scale of the vulnerability is staggering. Wittmann noted that it took her less than eight hours to identify and exploit a security flaw to gain full administrative access. This allowed her to view every license application, financial document, and internal process submitted to the authority. Additional context is provided by other recent failures in the region, such as the MyStake Casino breach where a PDF containing 540 user credentials was leaked in May 2025. Forensic investigators found that even eight months after the leak, no meaningful action—like forced password resets—had been taken by the operator, Santeda International B.V.

"For nine months, I watched the Curaçao gambling authority at work in real time—without the staff knowing. I could see who owned illegal online casinos, who was financing them, and what the authority knew about their operations. Today... I am publishing the #casinosecrets." - Lilith Wittmann, IT Activist and Hacker

A spokesperson for the CGA told media that the organization remains committed to transparency and will issue a statement soon. However, trust in the jurisdiction is at an all-time low. This breach follows a similar incident at the Malta Gaming Authority (MGA) earlier in the year, which led to a 1,300-page preliminary injunction against Wittmann by law firm Bird & Bird LLP. It appears the defenses in Curaçao were even easier to bypass than those in Malta.

Background

Curaçao has long been a favored hub for operators seeking to avoid the rigorous standards of European mainland regulations. The island's licenses are inexpensive, and the corporate structures often obscure the true owners. However, the Dutch government has been applying pressure for reform, demanding tighter licensing conditions. This hack arrives at a critical moment for the CGA, which is attempting to modernize its image. The exposure of sensitive data, reminiscent of a previous case where an ElasticSearch server left 100 million gambling transactions unprotected, highlights the systemic failures of offshore search engine security.

Why it matters for German players

For players in Germany, this news serves as a stark warning about the dangers of the grey market. Deposits made at Curaçao-licensed casinos are managed by entities with clearly insufficient IT protocols. The German Interstate Treaty on Gambling 2021 (GlüStV 2021) was established to prevent exactly this kind of data exposure. Casinos licensed by the Gemeinsame Glücksspielbehörde der Länder (GGL) must adhere to strict cybersecurity and data protection laws.

German residents should always check the official GGL whitelist. Only these providers offer mandatory player protections, such as the 1,000 Euro monthly deposit limit through LUGAS and the 1 Euro per spin limit on slots. The MyStake leak shows that offshore operators often ignore data breaches for months, leaving players vulnerable to identity theft and phishing. When a Curaçao casino fails, there is virtually no legal recourse for a German citizen to protect their personal information.

What it means for GGL-licensed casinos

Legal German operators can view this scandal as an opportunity to demonstrate the value of regulation. While offshore regulators like the CGA are exposed as insecure, the German regulatory framework provides a safe haven for consumer data. The anonymity that is currently being stripped away in Curaçao does not exist for GGL-licensed firms, where ownership must be fully transparent before a license is granted. This transparency builds the trust that offshore entities are rapidly losing. German operators should emphasize their superior security standards to attract players back into the legal, regulated market.

Frequently asked questions

Who is Lilith Wittmann and what did she do?

Lilith Wittmann is a German IT activist who exploited a vulnerability in the Curaçao Gaming Authority's portal. She claims to have had full access to their servers, financial records, and owner identities since December 2025.

Which online casinos are affected by this breach?

Documents released so far mention major brands like 1Xbet, Stake.com, SoftSwiss, and Platinum Casino. Additionally, MyStake Casino suffered a separate breach involving 540 user accounts.

What kind of data was exposed in these leaks?

The data includes Ultimate Beneficial Owner (UBO) lists, financial statements, and internal regulatory documents. In past leaks, names, addresses, and transaction histories of millions of players were also exposed.

How has the Curaçao Gaming Authority responded?

The CGA has stated they intend to remain transparent and will release a formal statement presently, though no technical remediation plan has been confirmed yet.

Is my data safer in a GGL-licensed German casino?

Yes, casinos with a GGL license must follow strict German data protection laws and IT security standards. These providers are monitored to prevent the systemic security failures seen in offshore jurisdictions like Curaçao.

Share

About the author

Lisa Lustich

Lisa Lustich

Editor-in-chief & casino tester

Lisa Lustich has been testing German-language online casinos since 1997 and runs the Lustich.de newsroom. More than 400 published reviews, certified player-protection advisor (BZgA training, 2019).

All articles by Lisa Lustich

Sources & further reading

Gambling can be addictive. Please play responsibly. Help and counselling at 0800 1 372 700 (BZgA, free & anonymous).

Related topics

Further Reading