Hacker Reveals Documents on the Owners of 1xBet, Stake, and Blaze Following the MGA Breach
A 30-year-old German cybersecurity researcher, Lilith Wittmann, who describes herself as a “hacker influencer,” breached the Malta Gaming Authority’s (MGA) systems and leaked a database containing information on the owners of major online casinos.

The breach has sparked controversy after Lilith Wittmann, a member of a Berlin-based cybersecurity outfit Zerforschung, which specialises in identifying vulnerabilities in government and corporate IT systems, publicly claimed responsibility for the attack. She also accused the Malta Gaming Authority of unlawful business conduct.
Wittmann, known in Germany as an advocate of “ethical hacking,” despite methods that have at times pushed legal boundaries, says her MGA breach has nothing to do with ransom. Instead, she claims she wanted to gather evidence of alleged links between the regulator and illicit activities.
Leaked Files Reveal Concerns Over Casino Licence Applicants
Wittmann registered on the CGA portal in December using the name of a manager at a Dutch trust office known to the regulator, but provided her own Gmail address. She reportedly gained access within days. Wittmann then uploaded software that gave her control of the portal, allowing her to download the stored documents.
Applications reviewed by the investigators show that CGA assessors repeatedly identified serious issues involving licence applicants. So far, Wittmann has published documents linked to the owners of 1xBet, Stake, and Blaze.
CGA Says “Licence Holders Were Given Time to Meet New Regulatory Requirements”
The CGA did not dispute the findings, but said the iGaming sector is in a transitional period following the adoption of a new law in 2024. Companies were given time to meet the new requirements gradually, rather than having their licences revoked immediately upon raising concerns.
Lilith Wittmann is now using the archive she obtained as leverage, threatening to release the full dataset if Malta seeks her extradition.
Lilith Wittmann’s Track Record of High-Profile Hacks
She had previously hacked German operator Merkur, exposing data linked to thousands of players. Unlike the current dispute with the MGA, Merkur officially recognised her actions as “ethical hacking”.
Before targeting the Maltese gambling regulator, Wittmann obtained tens of thousands of documents from Curaçao’s CGA licensing system in December 2025, which later formed the basis of the “Casino Secrets” investigation by several media outlets.
In 2021, she also uncovered vulnerabilities in an app used by Angela Merkel’s political party, prompting authorities to pursue legal action before backing down following protests from Europe’s largest hacker organisation.
In the meantime, this isn’t the only data leak concerning Stake. Another group of hackers had previously gained access to its players’ personal data, leading to numerous occasions of spam and phishing attacks.
More news
Neymar, Vini Jr. and Galvão Bueno are among several Brazilian celebrities who have received official notices over gambling advertising. The action by Espírito Santo authorities comes as Brazil tightens oversight of the iGaming sector.
Sep 16, 2026

Sep 10, 2026
Aug 21, 2026
Aug 03, 2026

