WILLEMSTAD – The Curaçao Gaming Authority (CGA) is considering legal action against German IT security researcher Lilith Wittmann after tens of thousands of documents obtained from the regulator’s online licensing portal were made public. The CGA is also trying to prevent further distribution of the leaked material online as a forensic investigation into the security breach continues.
The regulator disclosed its possible legal response while announcing that it would not participate in the SBC Summit in Lisbon. According to the CGA, personnel and resources that would otherwise have been involved in the conference are currently needed to deal with the unauthorized access to its online portal.
The CGA said the unauthorized access has been blocked and the account involved has been secured. It is working with authorities and independent cybersecurity specialists to determine the full scope of the incident and its consequences.
For the first time, the regulator has also provided more details about steps it is considering against those involved in obtaining and distributing the information.
The CGA said reports have been filed with authorities in Curaçao and abroad concerning information it considers to have been unlawfully obtained. Legal proceedings against Wittmann are among the options being considered.
At the same time, the regulator is monitoring where the leaked documents are being published online and is seeking ways to have the material removed.
The data breach has become a major issue for Curaçao’s recently reformed online gambling sector because the licensing portal contains highly sensitive information submitted by applicants. The leaked material reportedly includes corporate information, ownership structures, details about ultimate beneficial owners and identification documents.
The CGA's contemplated legal action comes as Wittmann has scored a significant victory in a separate dispute involving another gambling regulator.
A German court recently ruled in preliminary proceedings involving the Malta Gaming Authority (MGA) and its chief executive, Charles Mizzi, that Wittmann may continue using documents she previously obtained from the Maltese regulator for journalistic reporting.
According to Wittmann, the Berlin Regional Court II also allowed her to continue publicly describing the MGA as an “organized crime enablement scheme.”
The German court did not definitively decide whether Wittmann's access to the Maltese system legally constituted hacking. In the preliminary proceedings, the court reportedly considered it sufficiently plausible that her actions could be characterized that way.
However, the decision indicates that documents potentially obtained unlawfully cannot necessarily be barred from subsequent use for journalistic purposes.
The complete German ruling has not yet been made public, meaning important details concerning the court's reasoning remain unavailable. Information about the judgment has so far come primarily from Wittmann herself, while technology publication NEXT has cautioned that the full legal implications cannot yet be determined.
The German ruling does not concern the Curaçao Gaming Authority and has no direct legal effect on the Curaçao data breach. Any proceedings brought by the CGA against Wittmann would therefore have to be assessed separately and on their own legal grounds.
Nevertheless, the timing creates an unusual situation for the Curaçao regulator. Just as the CGA confirms that it is considering legal proceedings against Wittmann and attempting to limit further publication of the leaked information, another gambling regulator has failed in Germany to obtain a preliminary prohibition preventing her from using documents obtained from its systems in her reporting.
The CGA has not yet announced whether it will formally proceed with a lawsuit or in which jurisdiction such a case could be brought.
For now, its priority remains the forensic investigation. The regulator says additional information will be released as the investigation progresses and more becomes known about the scale and impact of the breach.