
A security breach at Merkur, one of Germany’s largest gambling companies, has sparked major concerns over data protection and system stability.
The breach may have exposed the personal data of a significant number of players, affecting several of Merkur’s gambling platforms, including Slotmagie, Crazybuzzer, and Merkurbets.
The incident came to light after security researcher Lilith Wittmann published a blog post on Medium on Friday evening (14 March).
Wittmann alleged that an unsecured API had left extensive personal data, including full names, account details, gaming histories, and transaction records, potentially accessible to unauthorised users.
Merkur had previously notified players of a security vulnerability and related data exposure on Thursday evening.
According to Wittmann, the issue stemmed from an improperly secured GraphQL interface, which, due to a lack of proper authorisation controls, may have allowed unauthorised access to sensitive data.
The data at risk reportedly included documents used for identity verification, such as copies of ID cards and letters from employment agencies.
Wittmann said she reported her findings to Germany’s gambling regulator, the GGL, to facilitate evidence collection.
She further stated that over 70,000 ID card copies and data from more than 800,000 individuals may have been affected, though these figures have not been independently verified.
Software security concerns
Merkur Group’s affected platforms reportedly utilise portal software from The Mill Adventure, a company based in Malta.
Wittmann suggested that The Mill Adventure’s software contained security flaws. She also highlighted that some online casinos operating with this software were not on the GGL’s whitelist.
Merkur has informed customers via its website and email about a “current data protection case” and advised vigilance against potential fraudulent activity.
The company said: “Despite extensive security measures, the IT system of one of our service providers was the target of a cyberattack.
“The official and internal investigation of security vulnerabilities revealed that incorrectly configured interfaces on the merkurbets.de website made it possible for a registered customer to view other customers’ data.
“However, to the best of our knowledge, these activists have no intention of sharing or misusing the information obtained.”
Merkur stated that it became aware of the breach on 28 February when the GGL notified the company.
The operator added that its specialists resolved the security vulnerability on the same day and have since taken additional measures, including conducting security audits, notifying data protection authorities, and enhancing internal security protocols.
External IT security experts were engaged to close identified security gaps, optimise systems, and improve employee training.
Not a data thief
A spokesperson from Merkur also responded to NEXT.io after being contacted, stating: “A cyberattack is always a serious incident – especially when sensitive personal data is affected. This makes it all the more important for us to respond quickly and transparently.
“According to current knowledge, Lilith Wittmann is not a ‘data thief,’ but a so-called ‘ethical hacker’ who is concerned with uncovering security vulnerabilities rather than using the data she has stolen without authorisation.
“We are also reassured that she has not misused the data acquired through the hacking. For the benefit of our customers, we hope and expect her to return the data in full or delete it to prevent any misuse.”
Meanwhile, a spokesperson for The Mill Adventure said: “This was an unprecedented event for our systems and we took immediate action to address the issue.
“Thanks to our team’s swift response and collaboration with top cybersecurity experts, we are further hardening our defences to ensure even greater protection for the players.
“Moving forward, we remain fully committed to maintaining the highest security standards so that all player data stays safe and private, as it should.”
System outages
On Saturday (15 March), several of Merkur’s gambling platforms experienced unexpected outages, leaving players unable to access games.
Merkur attributed the outages to issues with LUGAS, Germany’s national gambling monitoring system, and suggested that they were unrelated to the cyberattack.
In a statement to heise online, the company said: “We were also forced to temporarily take our systems offline for this reason. This measure is not related to the cyberattack on our service provider.”
Meanwhile, the GGL confirmed a technical malfunction in the LUGAS system, which temporarily blocked new registrations and deposits at online casinos on Saturday.
However, the regulator noted that existing players with balances could still continue playing despite the malfunction.
Player reactions
The security concerns have led to frustration among some Merkur users.
In online forums, players expressed concerns about the potential misuse of their personal data.
One user questioned why certain data, such as video verification images, were retained, while another criticised Merkur’s handling of the situation: “It’s a scandal, and Merkur is playing the whole thing down as if it were a minor matter.”
NEXT.io has contacted the GGL for further comments and clarifications.