News / § Scam watch

Casino Secrets: 40,000 leaked regulator files put the owners of Curaçao-licensed casinos on a searchable map

Scam watch By Ihor Makushinsky

On 23 September 2026 the Casino Secrets archive went live: more than 40,000 documents relating to casinos licensed by the Curaçao Gaming Authority (CGA), searchable by company and by domain. It accompanies an investigation published a day earlier by Follow the Money with NDR, NRK, SVT and Jetzt, based on material that Berlin-based security researcher Lilith Wittmann obtained from inside the regulator’s licensing portal over nine months.

How the files were obtained

Wittmann has described the method openly: in December 2025 she registered on the CGA portal under the name of a trust-office manager already known to the regulator, using her own Gmail address and a fictitious applicant. Within days she had portal access, then escalated to the licensing system itself.

The CGA’s account, published on 22 September, is consistent on the mechanics and unambiguous on the legal characterisation: access came through the customer-facing part of the licensing portal using an account registered under a false identity — “a variant of the name of a real person combined with an existing company in the Curaçao Chamber of Commerce registry” — and continued from December 2025 until it was identified and ended in September 2026. The regulator calls this “a serious breach under Curaçao law”, says it will report the matter to the relevant authorities, and adds that the full extent of the material taken has not been established: “The CGA will not repeat figures it cannot verify.”

What the reporting says the files show

Follow the Money says the cache — licence applications, regulatory assessments, ownership declarations, passports, tax returns, financial information — allowed the consortium to identify roughly 800 owners behind nearly 650 licensed companies operating thousands of gambling sites. Its central finding is procedural: that licences were granted in cases where the regulator’s own assessors had flagged unresolved questions about who actually controlled the applicant.

The CGA’s answer is that this reads individual documents out of context. It says it has followed robust due diligence since the 2024 reform, that pending items with licensed operators were followed up, and that “it does not find it prudent to draw conclusions on its licensing process by looking at separate documents and not considering the whole context of the particular applications”. It has also said publicly that it refused around 28% of applications since 2023.

Where the two sides diverge most sharply is the network question. Asked about roughly 1,000 domains reporters attributed to one software-platform ecosystem, the CGA said it keeps no such classification, that a shared technology platform “is commonplace across the online gambling industry and does not convert separate licenced entities into a single regulatory network”, and — directly addressing the blocking-evasion claim — that registering additional domains “is not permission to target any country in which an operator is not legally entitled to operate”, and that a Curaçao licence “does not authorize an operator to conduct activities in Germany”.

This is a dataset produced by unauthorised access, published on a public-interest justification. That is not a technicality. The Malta Gaming Authority, whose systems the same researcher accessed earlier this year, has obtained a preliminary injunction against her in a German court. Anyone using the archive is handling contested material about identified private individuals, including passport and tax data that no rightsholder has any business republishing.

What this means for you

For brand owners in iGaming the significance is attribution. The recurring wall in clone and impersonation enforcement is not finding the fake site — it is proving who runs it, and demonstrating that the “licensed” operator behind a network of mirrors is the same actor your notices keep hitting. Ownership opacity is the product being sold by offshore licensing, and this archive is the first large-scale crack in it. It sits alongside Infoblox’s finding that four actors run 99.5% of 1.7 million illegal casino domains: both point at the same conclusion — the durable unit is the operator, not the domain.

The operative caution is equally clear. A name in a leaked file is a lead, not a finding. Before it appears in a legal demand it needs corroboration from sources you can stand behind in front of a court or a registrar: corporate registries, WHOIS and DNS history, payment rails, platform disclosures, the CGA’s own public licence and enforcement registers. The archive’s own disclaimer — that inclusion does not imply illegal or improper conduct — is the right standard to apply to yourself.

And one structural note for operators: “licensed in Curaçao” has never meant “beneficial ownership verified”. If your compliance or partnership screening treats an offshore licence as a substitute for knowing your counterparty, this week is the argument for changing that.

Counsel’s note. The temptation with a leak like this is to search your brand name, find the entity behind a clone network, and put it straight into a cease-and-desist. Resist it: a demand built on unauthorised material invites a fight about your evidence instead of their infringement, and can taint an otherwise clean case. The working method is to use the archive only as a hypothesis generator, then rebuild the same chain from sources you can cite — registry filings, DNS and hosting records, payment processors, platform responses — so that the case you file stands entirely on its own record. We broke that attribution sequence down in our guide to taking down casino clone websites.

Ihor Makushinsky, senior counsel at Lawyerd
Ihor Makushinsky

Senior counsel · in IP and compliance practice since 2014. The counsel's note in every item is his own.

Full counsel profile →