German hacker claims MGA breach, alleges criminal activity

In a post on X published on Friday afternoon, Wittmann gave a cryptic account of the hack.
Share on
MGA hacked Lilith Wittmann
  • German ethical hacker Lilith Wittmann has claimed responsibility for a data breach at the Malta Gaming Authority (MGA), disclosed by the regulator on 18 March 2026.
  • Wittmann alleges the MGA has facilitated organised crime through its licensing regime, threatening to release a wider archive of iGaming data if Malta seeks her extradition.
  • The MGA has confirmed the breach and activated containment protocols, but has not addressed the organised crime allegations.

German ethical hacker Lilith Wittmann has publicly claimed responsibility for a cyberattack on the Malta Gaming Authority, issuing explosive allegations against the regulator in a post on X published on 20 March 2026.

The MGA had earlier confirmed a “breach within one of its systems,” stating that initial indications suggested the incident was perpetrated by an individual presenting themselves as a security researcher.

The regulator said it had activated its internal response protocols and dedicated technical resources to a full investigation. iGaming Republic reported on the initial breach earlier today.

Hacker goes public

In a post on X published on Friday afternoon, Wittmann gave a blistering and cryptic account of the hack, confirming she had shared the data obtained with media partners and authorities.

Writing directly to the regulator, Wittmann said:

“Dear Malta Gaming Authority, Yes, I hacked you, and the data obtained has been shared with media partners, authorities… And yes, we will expose the organised crime enablement schemes you created while presenting yourselves as a ‘legitimate public service’.”

Wittmann also warned that any attempt to extradite her to Malta would trigger the immediate release of her entire archive of iGaming-related data. Under Maltese law, hacking a public service carries a sentence of up to ten years’ imprisonment.

“I hope the German authorities are, for once, smart and do not extradite me to Malta, where I would face up to 10 years imprisonment for hacking a public service. Any police action from Malta would also trigger the immediate release of my entire archive of iGaming-related data.”

Wittmann stated she believes the data is sufficiently significant to the public interest that the breach will ultimately be seen as justified.

he added no further details on upcoming releases relating to what she described as “organised crime networks supported by countries like Malta,” and asked not to be contacted for the time being.

“PS. Hacking the mga was a easy as hacking the CDU.”

MGA hack X post

MGA response

The MGA said earlier this week it had implemented all necessary containment and mitigation measures upon identifying the breach, and confirmed that investigations remain ongoing to establish the full facts and ensure all appropriate safeguards are in place.

The Authority said it is treating the matter with the utmost seriousness and is working closely with its technical teams and relevant authorities to assess the situation comprehensively.

The MGA added that further updates to impacted entities will be provided in due course. The regulator did not comment directly on Wittmann’s organised crime allegations as of the time of this article.

Not her first rodeo

This is not the first time Wittmann has targeted the iGaming sector. In February 2025, she discovered a critical vulnerability in Merkur Group’s online casino platforms, exposing data belonging to a large number of players. She reported the issue to Germany’s gambling regulator, the GGL, the same day, before publishing a detailed blog post two weeks later.

Following that investigation into legal and illegal online casinos, Wittmann claimed that software provider The Mill Adventure subsequently cut off access to unregulated operators, resulting in the closure of several unlicensed platforms operating in Germany.

The pattern of escalating targets, from a licensed operator to a national regulator, marks a significant shift in scope. Wittmann has not confirmed whether her MGA activities were co-ordinated with any law enforcement body, as was the case in the Merkur disclosure.

What comes next

The breach comes at a sensitive moment for Malta’s gambling industry. The sector is home to firms such as Kindred Group, Betsson and LeoVegas, with 304 companies currently licensed by the MGA, collectively holding 312 gaming licences.

The industry generates an estimated €714.4m in gross value added and employs over 14,000 people, representing 4.9% of Malta’s workforce.

The investigation leaves the MGA in a difficult position. The authority has previously faced scrutiny over its licensees’ connections to organised crime.

In early 2024, Italian police seized €400m in assets from a figure linked to the ‘Ndrangheta mafia, with the individual alleged to have been involved in providing online gaming services through Malta-registered companies. The MGA clarified at the time that the individual had no connection to any Malta-licensed iGaming company.

The scope and content of the breach, including which systems were accessed and what data was exfiltrated, has not been disclosed by either party.

The MGA had recently published its supervisory priorities for 2026, outlining a risk-based, evidence-led approach structured around compliance, player protection and sports betting integrity. Cybersecurity was not listed as a primary theme.

Wittmann has stated further releases are forthcoming. The MGA says it will provide updates to affected entities in due course.


Keep reading:


Submit story

Do you have a story worth sharing?
Send it over to our editors!

Send story
Advertise with us