Berlin-based security researcher and activist Lilith Wittmann has claimed a significant development in her ongoing legal dispute with the Malta Gaming Authority, six months after taking responsibility for unauthorised access to the regulator’s systems.

Writing on LinkedIn on Friday (today), Ms Wittmann said she had received the decision in appeal proceedings concerning interim legal protection sought by the MGA.

“The good news is that I can call the MGA an ‘organized crime enablement scheme’,” she wrote. “And I am allowed to use the documents that I extracted from the MGA for my reporting.”

The ruling itself does not appear to have been made publicly available at the time of writing. As a result, the precise reasoning, scope and conditions attached to the German court’s decision cannot yet be independently assessed.

Importantly, the reported ruling should not be interpreted as a court finding that the MGA facilitates organised crime. Previous reporting on the proceedings indicates that the relevant description was treated as a permissible expression of opinion rather than an established factual allegation.

According to Ms Wittmann, the court also declined to examine in detail at this interim stage whether her access to the MGA’s systems legally constituted “hacking”, considering it sufficiently credible for the purposes of the proceedings that hacking may have occurred.

“After six months, this leaves us with around 2,000 pages of court files, costs of about €15,000 to €20,000 for me – and a bailiff who illegally passed on my address to Malta,” she claimed.

She again described the proceedings as a SLAPP – a strategic lawsuit against public participation – writing: “A pretty SLAPP to hang on the wall.”

The MGA has previously rejected the suggestion that its legal measures were intended to silence or intimidate Ms Wittmann, maintaining that its actions were aimed at preventing further unauthorised access and protecting confidential information.

Ms Wittmann has already started releasing information on companies like SoftSwiss and others in curacao on her blog.

Dispute stretches back to March

The dispute began in March, when Ms Wittmann publicly claimed responsibility for gaining unauthorised access to an MGA system.

On 17th March, the MGA confirmed that it had identified a breach within one of its systems and activated its internal response protocols.

The regulator said containment and mitigation measures were implemented immediately, while technical and operational resources were deployed to investigate the incident. At the time, the MGA said initial indications suggested the activity could be attributable to an individual presenting themselves as a security researcher.

Three days later, following Ms Wittmann’s public statements, the regulator issued a stronger response condemning unauthorised access to its systems and the extraction, handling or dissemination of information obtained through such activity.

The MGA also rejected allegations made in connection with the breach as “unsubstantiated”, saying it operates within established legal and governance frameworks and carries out its statutory functions with “integrity, independence and accountability”.

Ms Wittmann, meanwhile, claimed she had maintained access to the regulator's system for months and said information obtained through the breach had been shared with journalists and authorities.

MGA sought injunction in Germany

The dispute subsequently moved into the German courts.

In July, Ms Wittmann said she had been served with a lengthy preliminary injunction sought by the MGA, represented by international law firm Bird & Bird.

The injunction concerned, among other matters, statements connecting the regulator to organised crime as well as further unauthorised access to its IT infrastructure.

At the time, Ms Wittmann characterised the proceedings as a SLAPP and argued that her research and subsequent reporting were matters of public interest.

The MGA strongly rejected that interpretation.

In a right of reply issued in connection with reporting on the dispute in July, the regulator maintained that unauthorised access to public systems, impersonation of authorised users and the extraction or dissemination of confidential information could not be considered responsible disclosure.

It said the measures it pursued were intended to prevent further unauthorised access, protect confidential information and safeguard data entrusted to it as part of its regulatory functions.

The MGA also stressed that the measures were “protective, not punitive”, and said it had not sought damages, compensation or any other monetary remedy from Ms Wittmann.





Continue Reading

Carmel Said joins Celsius Casino as Senior Affiliate Manager

25 September 2026
by Julia Falzon

He has been working freelance in online gambling and affiliate management for the past 11 years


New tax rules set to reshape Malta’s gaming framework come into effect this October

25 September 2026
by Julia Falzon

MGA and MTCA said that the change will allow operators to recover eligible input VAT associated with taxable supplies

Avanti Studios opens office in Malta

23 September 2026
by Julia Falzon

‘Our presence there will help to expand our commercial function’, says Avanti Studios Commercial Director

Malta-based RiskCherry continues global expansion with new jurisdictional approvals

23 September 2026
by Julia Falzon

RiskCherry can currently service clients in 24 regulated markets

The Mill Adventure secures Danish platform certification

23 September 2026
by Julia Falzon

'Securing our Danish platform certification marks another important step in our long-term strategy’, says Chief Commercial Officer at The Mill Adventure

See more