An investigation dubbed "Casino Secrets"—conducted by German cybersecurity researcher Lilith Wittmann alongside investigative outlets including Follow the Money (FTM), NDR, SVT, and NRK—has published leaked internal records from the Curaçao Gaming Authority (CGA).
The breach exposes around 800 beneficial owners across roughly 650 licensed gambling operators, shedding light on nominee owners, complex corporate shells, and hundreds of millions in untracked funds.
What Was Exposed: The Key Revelations
Stake (Medium Rare N.V.):
The sole official beneficial owner submitted to the regulator is Serbian national Mladen Vuković, who declared personal assets exceeding $1 billion.
Publicly known founders Ed Craven and Bijan Tehrani were not listed on the official license application.
Internal CGA compliance notes revealed that regulators identified hundreds of millions of dollars in loans and transfers moving directly between Medium Rare and entities tied to Craven and Tehrani. Despite flagging the discrepancy, the regulator approved the license.
1xBet (Caecus N.V.):
The declared owner and CEO is Ukrainian national Ihor Hniedash (declaring an annual income under €10 million).
The widely reported Russian founders (Roman Semiokhin, Dmitry Kazorin, and the late Sergey Karshkov) do not appear in the official ownership documentation.
Internal assessor notes show regulators suspected 1xBet possessed "multiple hidden owners" and requested clarification, yet issued the license in 2024 before receiving conclusive proof.
Blaze (Prolific Trade N.V.):
The prominent Brazilian-facing operator is registered to 30-year-old Dutch citizen Nick van Gorsel (€800M in declared assets) and American Nicholas Bugg (€500M).
Qbet (Novatech Solutions N.V.):
Beneficial ownership is registered to Manila-based corporate manager Joanna Tinaco Arenas. Novatech was recently hit with a near-€25M penalty by the Dutch Gaming Authority (KSA) for unlicensed operations in the Netherlands.
How the Hack Happened: A Total Verification Failure
The breach did not require a sophisticated zero-day exploit. Wittmann obtained access to the regulator's portal via basic social engineering:
She registered an account on the official CGA portal using the name of an existing director at a reputable Dutch trust office, paired with a generic u/ gmail com address and a fictitious foundation (DreamCatcher Private Foundation).
The CGA portal administrators approved and verified the account within days without basic KYC checks, phone verification, or corporate domain validation.
Once logged in as a verified trust agent, she leveraged systemic vulnerabilities in the portal to deploy scripts, establish administrative control, and extract over 84,000 internal documents and 2 TB of data over an extended surveillance period.
The Regulator’s Defense. When questioned about approving operators despite severe internal compliance red flags, the CGA stated that the jurisdiction is currently navigating a transition phase under the new LOK (Landsverordening op de Kansspelen) regulatory framework. According to the regulator, companies were afforded leniency and a grace period to progressively achieve compliance rather than facing immediate operational bans.
For years, offshore jurisdictions have pledged transparency and tighter anti-money laundering controls. This leak reveals that even when internal compliance teams explicitly document hidden ownership and unaccounted capital transfers, licenses continue to be rubber-stamped.
Will this leak force international payment processors and tier-1 banking rails to cut ties with Curaçao-licensed entities, or will operators simply relocate to emerging offshore hubs like Anjouan and Costa Rica?
https://www.reddit.com/gallery/1wp7p29
Source: r/anticasino · by /u/Available-Bottle709
