AlphaFin wrote on 14.03.2025 at 17:51: I just noticed that the hacktivist Lilith Wittmann has confessed to this, I just read on her X, she will reveal more details about this in a moment... At least it doesn't seem to be anything malicious, I hope we take more care of our data after this anyway.
Awesome. If she's really using this as a warning, respect and a great achievement.
Since she has admitted it herself, the chances of the data from this hack being misused are extremely low.
AlphaFin wrote on 14.03.2025 at 17:51: I just noticed that the hacktivist Lilith Wittmann has confessed to this, I just read on her X, she will reveal more details about this in a moment... At least it doesn't seem to be anything malicious, I hope we take more care of our data after this anyway.
And how are you supposed to look after your data if you have to verify yourself with casinos/bookmakers? It's up to them to protect it. Sure, you shouldn't register or play in some Curaçao crap shop, but there's nothing you can do about it anyway except create a new identity or use someone else's accounts
AlphaFin wrote on 14.03.2025 at 17:51: I just noticed that the hacktivist Lilith Wittmann has confessed to this, I just read on her X, she will reveal more details about this in a moment... After all, it doesn't seem to be anything malicious, I hope we take more care of our data after this anyway.
It is important to note that the data was freely accessible with (appropriate IT knowledge) and it is unclear whether other, unknown persons may have accessed it. It's a real shame and I'm sure that the licensed casinos concerned will not receive a fair punishment for their unlawful data protection compliance. As described in the article, data protection and Player protection are probably the lowest priority for them, the main thing is that the money comes in
Sick! What bunglers! Or ignoramuses, even worse... 😡
"But since the data was de facto public and Merkur only closed the gaps when they were reported by me or the GGL, it is unclear whether anyone else found the data."
Does this mean that they were de facto publicly accessible during/after the hack? Or in general, because of the poor security?
Anyway, tomorrow I'll close the accounts there, hopefully they won't "accidentally" give me an Oasis ban for it... 😆
Stromberg wrote on 14.03.2025 at 20:04:
Sick! What bunglers! Or ignoramuses, even worse... 😡
"But since the data was de facto public and Merkur only closed the gaps when they were reported by me or the GGL, it is unclear whether anyone else found the data."
Does this mean that they were de facto publicly accessible during/after the hack? Or in general, because of the poor security?
Anyway, tomorrow I'll close the accounts there, hopefully they won't "accidentally" give me an Oasis ban for it... 😆
As I understand it, this data was always publicly accessible, even before she found out. She could therefore not rule out the possibility that someone else had known about and exploited this vulnerability before her.
There is now also a WIKI e-entry about the case. So the data was publicly accessible the whole time. She discovered this, informed the GGL and the gap was then closed. It is not known whether anyone discovered the gap before her. But I would assume that if the vulnerability had been discovered by an evil villain, he would have exploited it immediately or sold it as quickly as possible. After all, it is clear that this loophole will become worthless sooner or later. So if no damage has been done so far, nothing will happen to you in the future either.
Even if I no longer gamble, I will still send a letter to all these shops (deletion in accordance with Art. 17 GDPR) and never want to have anything to do with them again in this life! If they don't respond, I'll follow it up with a nice complaint to the data protection supervisory authority.
Interesting. Has anyone had any experience with Protectra in the past? Would you then have a claim against all 3 (Merkur Bets, Slotmagie and Crazy Buzzer) or do you just join a class action?
No, I am not familiar with Protectra so far.
Incidentally, GGL has issued a public warning to the companies behind it . The background to this are various breaches of the GlüStV. Among other things, the required pentests were apparently not carried out.
Hacker attack on Merkur Bets
Nobody has liked this post so far
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
Awesome. If she's really using this as a warning, respect and a great achievement.
Since she has admitted it herself, the chances of the data from this hack being misused are extremely low.
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
And how are you supposed to look after your data if you have to verify yourself with casinos/bookmakers? It's up to them to protect it. Sure, you shouldn't register or play in some Curaçao crap shop, but there's nothing you can do about it anyway except create a new identity or use someone else's accounts
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
You can find the relevant article here:
https://lilithwittmann.medium.com/casinonutzer-der-merkur-gruppe-verlieren-nicht-nur-ihr-geld-sondern-auch-ihre-daten-ef6710184f7c
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
Sick! What bunglers! Or ignoramuses, even worse... 😡
"But since the data was de facto public and Merkur only closed the gaps when they were reported by me or the GGL, it is unclear whether anyone else found the data."
Does this mean that they were de facto publicly accessible during/after the hack? Or in general, because of the poor security?
Anyway, tomorrow I'll close the accounts there, hopefully they won't "accidentally" give me an Oasis ban for it... 😆
This post has been translated automatically
Hacker attack on Merkur Bets
Liked this post:
Stromberg
Awesome woman. I read through her wiki:
"By her own account, Wittmann dropped out of school at the age of 16 and then completed vocational training..."
You can see how bad our school system is if you can't support and challenge people like that.
I think she didn't take advantage of it because she knows that this action can achieve a lot for her career.
She is well known. At least this wasn't the first time she's done something like this
Gap in CDU app: party embarrasses itself with complaint against IT expert
As I understand it, this data was always publicly accessible, even before she found out. She could therefore not rule out the possibility that someone else had known about and exploited this vulnerability before her.
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
Even if I no longer gamble, I will still send a letter to all these shops (deletion in accordance with Art. 17 GDPR) and never want to have anything to do with them again in this life! If they don't respond, I'll follow it up with a nice complaint to the data protection supervisory authority.
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
No, I am not familiar with Protectra so far.
Incidentally, GGL has issued a public warning to the companies behind it . The background to this are various breaches of the GlüStV. Among other things, the required pentests were apparently not carried out.
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
Do you have a link to the entry? I couldn't find it right away. Thank you
This post has been translated automatically
Hacker attack on Merkur Bets
Nobody has liked this post so far
I think that's a bold thesis.
This post has been translated automatically