September 22, 2026By TozettaHackersCybercrime

Hack Curaçao Gaming Authority, journalist or hacker?

Where is the line between cybersecurity research and hacking? The CGA hack raises questions about ethical hacking, responsible disclosure, and privacy.

When does cybersecurity research end and hacking begin? This question arises after the recent reports from Follow the Money and Curaçao.nu regarding the Curaçao Gaming Authority (CGA). The German cybersecurity researcher Lilith Wittmann managed to gain access to the licensing portal of the regulator and subsequently obtained tens of thousands of confidential documents. This data now forms the basis for international journalistic research into the Curaçao gambling sector. This raises an uncomfortable but important question: does the end justify the means?

First, a step back. Curaçao has played a significant role in the international online gambling sector for decades. You can debate the desirability of this, but that is not the focus of this incident. According to Curaçao.nu and Follow the Money, Wittmann registered on the CGA portal in December 2025 under the name of a manager from a Curaçao trust office known to the regulator. She used her own Gmail address and provided a fictitious company for which she allegedly wanted to apply for a gambling license. A few days later, the account was approved by the CGA.

From that moment on, it becomes truly interesting from a cybersecurity perspective. According to FTM, Wittmann uploaded software after gaining access that allowed her to take over the management of the licensing portal. This gave her access to highly sensitive information, including passports, tax returns, financial data, license applications, and internal assessments. Ultimately, tens of thousands of confidential documents came into her possession. That the initial identity verification by the CGA apparently fell short is undoubtedly a serious security issue. However, a weak front door does not automatically mean that anyone who walks through it has free rein.

And this is precisely where the interesting discussion lies for us at Tozetta. Responsible disclosure and ethical security research exist precisely by virtue of boundaries: what do you do when you discover a vulnerability, how far do you go to demonstrate it, and what do you do with the data you gain access to? Journalistic interest, societal interest, and cybersecurity can reinforce each other, but they are not an automatic license for every technical action. The CGA must be accountable for the security of a system in which extraordinarily sensitive personal data was stored. At the same time, the method by which that data was obtained also deserves critical attention. Journalist, cybersecurity researcher, or hacker? What do you think?

Related articles