Casino Secrets methods raise serious hacking and privacy concerns

Casino Secrets methods raise serious hacking and privacy concerns

Hacking regulators and calling it journalism: I have a serious problem with Lilith Wittmann's methods!

I have followed Ms Wittmann's work for quite some time and I have used parts of it myself. Her earlier gambling research was useful when Malta Media examined Lottoland, and our own reporting has since looked at both the German licensing questions around Lottoland and the limits of German gambling enforcement. I have no problem referring to another journalist's work when I can understand where the information came from, verify what matters and put it into the proper context. If gambling companies hide ownership, mislead regulators, avoid tax or operate unlawfully, they should be investigated, irrespective of whether they know us, advertise with us or dislike what we publish.

That is why my problem with Casino Secrets is not that its investigations concern companies such as SoftSwiss, PlatinCasino or Lottoland. Ms Wittmann's current series includes detailed pieces on the CuraƧao Gaming Authority, the SoftSwiss network and PlatinCasino, and some of the resulting corporate questions are worth examining. Malta Media has spent years going into company structures and regulatory failures, and we will continue doing so. The fact that an investigation is uncomfortable for a gambling company is not a reason to attack the investigation.

My problem is the method used to obtain the underlying regulatory material and the way private information has subsequently been handled. We should not sanitise the provenance by describing this simply as a conventional leak when Ms Wittmann herself publicly said, in relation to the MGA incident, “Yes, I hacked you”, while her own CuraƧao account says that access to the CGA environment continued for approximately nine months.

There is a fundamental difference between a whistleblower giving documents to a newsroom and a journalist personally obtaining prolonged access to a regulator's system. Whether every element of that conduct ultimately satisfies a criminal offence is for prosecutors and courts, but the underlying conduct is serious enough to deserve the same scrutiny journalists routinely apply to everyone else.

There is also a second issue which, for me, has become even more important than the corporate stories produced from the archive. A regulator's files contain much more than the identities of casino owners. They contain passports, dates of birth, residential addresses, source-of-funds material, employment records, proof-of-address documents and information belonging to compliance staff, AML professionals, consultants and employees who may never have been accused of anything.

Public interest can justify exposing ownership or wrongdoing, but it does not automatically justify exposing every private field sitting beside that evidence.

The MGA hack should have set alarm bells ringing

The MGA case should have forced a much wider discussion about that distinction. On 17 March 2026, the Malta Gaming Authority confirmed a breach in one of its systems, and three days later it issued a second statement explicitly condemning unauthorised access and the extraction, handling or dissemination of information obtained through it. Ms Wittmann had already claimed responsibility publicly and said material had been shared with media partners and authorities.

To my knowledge, those authorities have still not been identified publicly in a way that answers the obvious questions about who received the material, when they received it and what they knew about its provenance.

The MGA has now responded directly to Malta Media after receiving this article in advance. It told us that unauthorised access to public systems, impersonation of authorised users and the extraction, handling or dissemination of confidential information are not, in its view, responsible disclosure or legitimate engagement with a public institution.

The Authority also says its proceedings against Ms Wittmann were intended to prevent further unauthorised use and dissemination rather than to silence legitimate journalism, and that it sought no damages or compensation for its own benefit. That is the regulator's position, and it deserves to be recorded accurately even when Malta Media disagrees with the MGA on other questions.

The MGA also challenged broader descriptions of all cross-border activity by MGA-licensed operators as simply “illegal gambling”. Its position is that gambling remains non-harmonised at EU level and that regulated operators licensed within the EU or EEA should not automatically be placed in the same category as businesses operating outside recognised regulatory frameworks.

That debate is larger than this article, and Malta Media has published its own critical reporting on how national enforcement works in practice, including cases where illegal domains remain accessible despite years of regulatory action. Giving the MGA space to state its position does not require us to adopt it.

Serious allegations still require serious evidence

Ms Wittmann has made grave allegations about organised crime, regulatory failures and the gambling businesses operating around Malta and CuraƧao. If documents show bribery, concealed ownership, manipulated decisions, tax avoidance or other unlawful conduct, those documents should be authenticated and reported responsibly. Malta Media would publish such evidence irrespective of whom it embarrassed, and criticism of Ms Wittmann's methods does not amount to a defence of any company named in her investigations.

The same standard, however, has to work in both directions. An unpublished or partly published archive cannot become a substitute for proving every allegation attached to it, and the importance of a story does not retrospectively settle whether every step used to obtain the material was justified. That is why the distinction between acquisition, verification, publication and the treatment of unrelated personal data matters so much here.

CuraƧao makes the scale much harder to ignore

The Casino Secrets account of the CGA investigation already described access to the CuraƧao regulator's licensing environment over many months. Before publication Malta Media sent the CGA our draft and invited factual corrections, and the Authority provided a detailed response based on its forensic work. One correction was important: the affected environment was the online licensing portal managed by an external service provider, not unrestricted access to every CGA server, workstation, email account or internal corporate system. We have changed the article accordingly because accuracy matters, particularly when criticising somebody else's standards of evidence.

The wider forensic picture is nevertheless considerably more serious than the wording dispute about “the regulator's servers”. According to the CGA, an account using the name “Flip Humme” and an email address on the lilithwittmann.de domain was approved as an administrator for its own organisation, a customer-side role rather than a CGA employee account. The regulator says database access followed within hours. The access then remained available over a period of approximately nine months, which is a very different situation from demonstrating a vulnerability and immediately ending the intrusion.

The volume is the most striking part of the CGA response. Its forensic records identified 14,054 requests returning data and approximately 373.78 GB of transferred information, with 369.84 GB originating from document folders associated with 1,355 organisations. Because some folders were retrieved repeatedly, the regulator estimates the unique amount of information, including the database, at approximately 123 GB. Whatever view one ultimately takes of the legal arguments, this was not the retrieval of a few documents needed to demonstrate a security weakness.

The CGA has acknowledged to Malta Media that the unauthorised access should never have occurred and says it regrets the concern and uncertainty created by the incident. The regulator therefore has serious questions of its own to answer about security, detection, notification and why an environment containing this level of regulatory information remained vulnerable. Poor security by a regulator, however, does not answer the separate question of what somebody outside the regulator was entitled to do with the material once access had been obtained. Both issues can be serious at the same time.

The files concern far more than UBOs

A gambling licensing portal does not contain information only about wealthy casino owners. The CGA's own application requirements show that personal-history material can be required for UBOs, directors, trustees, lenders and key persons such as chief executives and compliance officers. In practice, regulatory files also involve consultants, AML professionals and other employees who are simply doing their jobs. Their presence in a regulator's database does not transform them into public figures.

I have spoken to people in the industry in Lisbon who are familiar with compliance work around the CuraƧao process, and this distinction is not theoretical. Some individuals appearing in these files are not UBOs, not shareholders and not people accused of wrongdoing. They may have provided a passport, proof of address or employment information because a regulatory process required it.

The idea that this private material can then become publicly downloadable because somebody else in the same database is interesting to journalists is, in my view, indefensible.

Even where the person is a UBO or director, relevance still has limits. If someone owns 47 per cent of a casino company, publish the ownership if it matters. If several supposedly independent businesses are secretly connected, prove and publish the connection. None of that requires giving the public the person's complete passport number, exact home address or unrelated proof-of-address documentation.

Publishing raw documents is a separate editorial decision

Malta Media has independently reviewed examples from the public Casino Secrets archive and found documents exposing full passport identifiers, dates of birth, precise residential addresses and other information capable of identifying and locating natural persons. We prepared our own evidence dossier without reproducing those values, because documenting that somebody else has exposed private information does not require us to expose the same information again. That is a normal editorial decision, not an attempt to protect casino companies from scrutiny.

The distinction is especially important in gambling because the industry combines large amounts of money, cryptocurrency, fraud, extortion attempts and, at times, organised criminal activity. Publishing a person's exact residential address beside information suggesting that they control a valuable gambling business can create a very different risk from merely identifying that person's corporate role. The same concern applies even more strongly to a compliance consultant, employee or AML professional who may have no ownership interest at all.

A serious newsroom routinely possesses information that never appears in the resulting article. A shareholder register can prove ownership while the passport numbers and private addresses on the same page are redacted. A regulator's identity document can help verify that a person is who the file says they are without turning the entire passport into a public download. Public-interest reporting is about publishing what is necessary to explain the story, not publishing everything that happened to be available.

That distinction now also has fresh European legal relevance. In Case C-199/24, Legal Newsdesk Sweden, the Court of Justice dealt directly with the relationship between online databases, personal data and the concept of processing for journalistic purposes under Article 85 GDPR. The facts were different, and the judgment does not decide the Casino Secrets situation, but it reinforces why a searchable public database cannot simply avoid scrutiny by attaching the word journalism to the operation. The legal assessment depends on what is being processed, why it is being published and how the competing rights are balanced.

The legal questions deserve a proper test

The acquisition side raises a different set of questions from publication. Section 202a of the German Criminal Code criminalises obtaining unauthorised access to data not intended for the person where specially protected access is overcome. Whether the precise CGA or MGA technical facts satisfy every element of that offence cannot be decided from a newspaper article, and Malta Media is not declaring that a German court has already convicted Ms Wittmann of it. The point is that the conduct described publicly, and now partly documented by the regulators, is serious enough for prosecutors to examine rather than for journalists to decide for themselves that the legal question is closed.

The publication of personal information raises further questions. Section 126a StGB addresses dangerous dissemination of another person's personal data where the statutory circumstances are capable of exposing that person or somebody close to them to serious unlawful acts. It is not enough merely to show that an address was published, because the provision contains additional requirements, but the combination of precise residential addresses with wealth, ownership and gambling-industry information is an obvious reason for the competent authorities to assess whether the provision is relevant.

Another provision that may warrant examination is Section 42 of the Federal Data Protection Act, which contains criminal provisions for certain knowing unauthorised disclosures or processing of non-public personal data where additional commercial, payment or intent requirements are satisfied. Again, Malta Media is not claiming those additional elements have already been proved. We are saying the legal framework contains more than a general debate about press freedom, and somebody other than the publisher should now test the facts against it.

GDPR, journalistic privilege and proportionality

The data-protection position is equally important and equally incapable of being reduced to a slogan. Under the General Data Protection Regulation, Article 5 includes principles such as lawfulness, purpose limitation and data minimisation, while Article 6 deals with lawful bases for processing.

At the same time, Article 85 requires Member States to reconcile data protection with freedom of expression and journalism, which means it would be wrong to pretend that the ordinary GDPR rules automatically apply in the same way to every journalistic activity. The real question is where the journalistic protection ends when a project operates a searchable repository of raw documents containing data unrelated to the public-interest allegation.

The Court of Justice has also emphasised proportionality when personal information is made freely accessible online. In Case C-474/24, NADA Austria and Others, the Court dealt with online publication of personal data and the need to balance the purpose of disclosure against its consequences and accessibility. The factual context was different, but the principle is directly relevant to the decision to publish an exact home address or complete passport identifier to an unlimited audience when the underlying journalistic point could be made without it.

This is why Malta Media is not asking a journalist to accept our legal conclusion. We are asking the competent data-protection authorities, media regulators and prosecutors to make their own assessment. Press freedom is important precisely because it protects difficult reporting, but it cannot mean that the person publishing the material is also the final authority on whether every privacy and criminal-law boundary has been respected.

Malta Media is taking the issue beyond this article

We have prepared evidence concerning the public availability of passport information, dates of birth, residential addresses and other personal data, and we are contacting the relevant authorities in Germany, Malta and CuraƧao. That includes the Berlin data-protection authority, the competent authority in North Rhine-Westphalia, Malta's Information and Data Protection Commissioner and the CuraƧao data-protection authority.

We are also approaching the General Prosecutor's Office in Berlin to establish whether German authorities were already informed about the MGA or CGA incidents, whether anyone knew while the CuraƧao access remained active and whether the acquisition or subsequent dissemination of the information is already being assessed.

The infrastructure around the public archive also matters. Malta Media is using the appropriate abuse procedures with the registrar and other service providers, including the INWX illegal-content reporting channel and Cloudflare's abuse-reporting process where those services are involved.

The objective is to have providers and authorities examine whether unredacted passports, precise residential addresses and comparable private material should remain publicly downloadable when the underlying corporate evidence can be preserved with those fields removed.

If a regulator or service provider concludes that documents can remain online only after redaction, that is a proportionate outcome. If an authority concludes that the structure of the archive itself breaches applicable law, it should use whatever powers the law gives it. Malta Media is not trying to substitute itself for those authorities; we are putting the evidence in front of them and asking them to do the job that journalists, companies and regulators cannot credibly do for themselves.

If your private data are in the archive

Anyone who discovers their own passport information, exact residential address, date of birth, proof of address, source-of-funds material or comparable private information in the archive should preserve evidence of what was publicly accessible. Keep the exact URL, filename and date, and retain a screenshot or other record without redistributing the unredacted document more widely than necessary. Affected people should consider complaints to the competent data-protection authority and targeted abuse reports to the registrar, hosting provider, CDN or other relevant infrastructure provider.

I also believe affected individuals should seriously consider obtaining legal advice and filing a criminal complaint with the competent German authorities where the facts justify it. Filing a complaint is not a conviction and it does not require the person concerned to decide which criminal offence has been committed. It is a request for prosecutors to examine how the information was obtained, how it was processed and whether the publication of that person's private data crossed a criminal-law boundary.

For people outside Germany, the language and jurisdictional questions can make that process unnecessarily difficult. Malta Media is prepared to help affected individuals free of charge, on a case-by-case basis, organise the factual material and prepare an initial German-language submission for the relevant authority or service provider. We are not offering legal representation and we will not manufacture allegations for anybody, but people who want that assistance can contact us privately at ms@malta-media.com and we will take it from there individually.

Editorial note – right of reply: Before publication Malta Media sent the draft of this article to Ms Wittmann, the Malta Gaming Authority and the CuraƧao Gaming Authority and invited factual corrections, supporting documentation and comments. The MGA and CGA both responded, and relevant factual clarifications have been incorporated into this version. Lottoland, PlatinCasino and SoftSwiss were also sent the draft because they are referenced in the article. At the time this version was prepared, no response had been received from Ms Wittmann, PlatinCasino, Lottoland or SoftSwiss; any substantive later response will be considered on its merits.

Journalism does not exempt journalists from scrutiny

I do not have a problem with aggressive investigative journalism. Some of the best reporting exists because journalists were prepared to challenge companies, regulators and wealthy individuals who would have preferred uncomfortable information to remain hidden. Malta Media intends to remain that kind of publication as well, which means going into ownership structures, regulatory decisions and corporate relationships even when the people involved would rather, we did not.

Independence also means applying the same standard when a journalist becomes part of the story. If a gambling company obtained around 123 GB of regulatory information through unauthorised database access and maintained access over many months, Malta Media would investigate it aggressively. If the same company, then placed raw documents containing passport numbers and home addresses online, I would expect data-protection authorities, infrastructure providers and prosecutors to examine what it had done. Changing the person doing those things from a gambling executive to a journalist does not make the underlying questions disappear.

There may ultimately be legal arguments protecting some or much of Ms Wittmann's use of the material, particularly where documents are analysed and published to establish matters of genuine public interest. There may also be important legal differences between acquiring the data, possessing it, sharing selected information with other journalists and putting raw unredacted documents on a public website.

The filing cabinet remains the simplest test

If a gambling regulator left a physical filing cabinet containing licensing files unlocked, I would immediately ask how a public authority entrusted with passports, financial information and residential details could be so careless. If somebody found that weakness and demonstrated it, there could be a legitimate public-interest story about the regulator's failure. I would still struggle to accept somebody returning repeatedly for approximately nine months, watching new files arrive, copying large quantities of material and later placing documents containing unrelated people's passport numbers and home addresses into a public archive.

The fact that the filing cabinet is digital does not create a different moral standard. Weak security does not remove the privacy interests of the people whose information was stored behind it, and journalistic relevance in one part of a document does not make every other field in the same document relevant. The regulator can have failed badly and Ms Wittmann can still have serious questions to answer about the way the resulting material was obtained, retained and published.

I want Malta Media to remain a publication that publishes uncomfortable facts about gambling companies, owners and regulators when those facts are supportable. I also want us to know where the line is, because independence is not only about whom we are prepared to criticise; it is also about the standards we keep when we possess information that would be easy to publish but serves no necessary public-interest purpose. Passport numbers, exact home addresses and an employee's proof-of-address document do not explain a corporate structure, and they should have been redacted before the underlying files were made public. That is the line I believe Casino Secrets crossed, and it is now time for the relevant authorities to decide whether legal boundaries were crossed as well.

FAQs

What is Casino Secrets?
Casino Secrets is an investigative project associated with journalist Lilith Wittmann that examines gambling companies, regulatory systems and corporate structures using material obtained from gambling regulatory environments.

Why is Malta Media criticising the Casino Secrets investigation?
Malta Media's criticism focuses primarily on how regulatory information was obtained and how private personal information was subsequently handled and published, rather than on the fact that gambling companies were investigated.

What happened with the Malta Gaming Authority system breach?
The Malta Gaming Authority confirmed a breach in one of its systems in March 2026 and later condemned unauthorised access and the extraction, handling or dissemination of information obtained through such access.

What happened with the CuraƧao Gaming Authority portal?
The CuraƧao Gaming Authority said unauthorised access affected its online licensing portal. According to its forensic findings, access remained available for approximately nine months and involved substantial amounts of regulatory information.

How much data was reportedly accessed from the CuraƧao Gaming Authority environment?
The CuraƧao Gaming Authority reported approximately 373.78 GB of transferred information during the incident, while estimating that the unique amount of information involved was around 123 GB.

Why is the publication of personal data a concern?
Regulatory files can contain passports, dates of birth, residential addresses, proof-of-address documents, employment information and financial records belonging to people who may not be accused of wrongdoing.

Does journalistic public interest automatically justify publishing complete documents?
No. Public-interest reporting may justify publishing information that establishes ownership, wrongdoing or regulatory failures, but that does not necessarily make unrelated personal information journalistically necessary.

What role does GDPR play in the Casino Secrets debate?
GDPR establishes principles including lawfulness, purpose limitation and data minimisation while also requiring Member States to balance data protection rights with freedom of expression and journalistic activity.

Could German criminal law apply to unauthorised access to regulatory data?
German criminal law contains provisions dealing with unauthorised access to specially protected data. Whether those provisions apply to particular conduct depends on the technical facts and would ultimately be assessed by prosecutors and courts.

What should someone do if their private data appear in the Casino Secrets archive?
Affected individuals should preserve evidence of what was publicly accessible, record relevant URLs and dates and consider contacting the appropriate data-protection authority, service provider or qualified legal adviser.

Share

Michael Schmitt is the founder of TRIDER.UK and Editor of Malta Media. He writes about iGaming, gambling regulation, corporate structures, financial services and market integrity, combining investigative journalism with nearly three decades of experience in corporate services and international business.