
Curaçao Gaming Authority Hit by Security Breach
The Curaçao Gaming Authority disclosed a significant cyberattack that has raised alarm bells across the offshore iGaming sector. The breach, carried out by Berlin-based security researcher Lilith Wittmann, 30, has the potential to expose detailed ownership and operational information for hundreds of online casinos licensed in the jurisdiction.
Wittmann, who previously penetrated the Malta Gaming Authority's systems, claims to be acting as a white hat hacker motivated by transparency concerns. However, the potential release of confidential regulatory files—including licensing applications, ownership documentation, and compliance records—could have severe ramifications for operators across the industry.
What's at Stake
Curaçao has long served as a convenient jurisdiction for operators seeking gaming licenses with relatively minimal regulatory burden. The jurisdiction hosts licensing for hundreds of online casinos, many of which operate globally but maintain deliberately opaque ownership structures. Access to the CGA's internal databases could reveal the true beneficial owners behind seemingly independent brands—information that operators have long kept carefully compartmentalized from public view.
The potential disclosure of this data raises uncomfortable questions about the legitimacy of certain operators and their compliance with anti-money laundering requirements. It also threatens to expose relationships between operators that are officially presented as distinct competitors but are actually controlled by the same parent entities.
Regulatory Implications
The breach highlights a critical vulnerability in how gaming authorities maintain sensitive data. If a single researcher can penetrate these systems, state-level regulators in major jurisdictions like the United States, the United Kingdom, and Europe have justification to demand stronger cybersecurity standards from licensing authorities—or to question whether offshore jurisdictions should be permitted to license operators serving their regulated markets.
Operators licensed in Curaçao may face increased scrutiny from primary regulators if the hack results in public disclosure of ownership structures. Compliance teams across the industry are likely reviewing how their corporate structures might appear if exposed and whether their current arrangements could withstand regulatory examination.
The incident underscores that offshore gaming regulation operates on an implicit assumption of confidentiality that is increasingly fragile in an era of sophisticated cybersecurity attacks. Whether intentionally or not, Wittmann's actions may force the entire industry toward greater transparency.
Source: Casino.org
Marcus De Luca
Regulation Correspondent
Member of the iGaming Pulse editorial team. Covering industry news, analysis, and B2B developments across the global iGaming sector.


