Wittmann publishes 40,000-document Curaçao casino ownership archive
Lilith Wittmann launched a public, searchable Casino Secrets database on September 24 containing over 40,000 documents from Curaçao’s gambling regulator, and revealed she actually had unauthorized access to the portal for roughly nine months.
From investigation to searchable archive
Lilith Wittmann took the Casino Secrets story a step past journalism and turned it into a public tool. The German security researcher behind the original Curaçao Gaming Authority breach launched a searchable website on September 24 containing more than 40,000 documents pulled from the regulator’s licensing system, letting anyone look up ownership records for Curaçao-licensed operators directly instead of relying on reporters to surface individual names. Wittmann said this is only a portion of what she actually obtained, with more material still to come.
The access itself turns out to have run far longer than a single breach implies. Wittmann logged into CGA’s portal under a false identity starting in December 2025 and kept that access for roughly nine months before the regulator detected and shut it down on September 17, the same breach CGA disclosed publicly at the time. That timeline reframes the original incident: what CGA described as a contained intrusion was, on Wittmann’s account, closer to nine months of someone reading the regulator’s own files without anyone there knowing it was happening.
The industry pushes back
What’s sitting in the archive is the same category of material the earlier reporting drew from: license applications, ownership declarations, passports, tax records, and financial documents for the roughly 650 companies and 800 individual owners already named in the Follow the Money investigation. The site carries an explicit disclaimer that appearing in the database doesn’t imply illegal or improper conduct, an acknowledgment that a raw document dump searchable by anyone carries real risk of guilt-by-association for names that show up in paperwork without wrongdoing behind them.
Pushback from the industry started before the public database even went live. Softswiss, the technology group the reporting positioned as central to several of the operations involved, sent a lawyer’s letter dated September 9 denying it runs any online casinos itself or provides gambling services directly to users, comparing its role to a software vendor like Microsoft or Apple rather than an operator. It acknowledged supplying individual software components to Platincasino specifically but denied operational involvement. Founder Ivan Montik’s lawyer confirmed he once held full ownership of Dama N.V. and Topchik N.V. before selling both, while denying any current role running them. CGA itself pushed back too, telling reporters the “network” framing used to connect these companies doesn’t exist in its own regulatory records and arguing that operators sharing the same technology platform is ordinary practice, not evidence the entities should be treated as one.
None of that pushback undoes what’s now publicly searchable. Wittmann built a tool that puts the underlying documents in front of anyone willing to look, rather than leaving the story dependent on which names reporters chose to spotlight.
“CGA called the intrusion contained. Wittmann calls it nine months of reading the regulator’s own files without anyone noticing — those two descriptions of the same breach aren’t close to the same story.”
Share
SUBSCRIBE TO OUR PRIVATE CASES AND USEFUL TIPS
Subscribe to our newsletter, get only exclusive content and weekly digests, no any spam!
By providing my email, I accept the Privacy Policy.