German hacker-activist Lilith Wittmann says she has had access to Curaçao Gaming Authority systems since December and plans to publish a full list of licensee beneficial owners.
Wittmann gained access to CGA servers in under eight hours through a web portal vulnerability. She could then read all licence applications, operator documents, ownership data and casino funding records. "For nine months I watched the regulator work in real time — staff had no idea," she wrote on LinkedIn.
The breach was published in coordination with NDR, NRK, SVT and Follow the Money across five countries. Wittmann disclosed information on several licensees, including structures allegedly linked to offshore operators. A full UBO list would pierce the opacity that has long shielded the dot-com gambling industry.
This is the second regulatory hack Wittmann has claimed publicly. She previously breached Malta Gaming Authority systems. MGA responded through Bird & Bird with a preliminary injunction running to 1,300 pages, restricting what she could say about the regulator.
A CGA representative told NEXT.io the regulator intends to remain transparent and will issue an official statement soon.