
Merkur, one of Germany’s largest gambling companies, said a white hat hacker inadvertently exposed the personal and payment information of more than 1 million customers through a misconfiguration.
The incident came to light after security researcher Lilith Wittmann wrote in a blog post that the gambling company left an Application Programming Interface (API) exposed on the cloud. The API repository contained extensive personal data, including full names, account details, gaming histories, and transaction records of over a million players and could have been easily accessed by unauthorised users.
“All of this data could be queried via GraphQL — with a very, very large query,” Wittmann wrote. “You didn’t even have to be logged in to do this. Instead, you could simply retrieve the data using queries named "users," "sessions," and "paymentOptionsV2." The system was therefore completely publicly accessible.”
She said the exposed data records included game sessions with all moves, user agent details, IP addresses and payment data from multiple payment service providers, including Trustly, Paylado, PayPal, Skrill, Payment_IQ, and PaySafeCard.
Wittmann added that more than 70,000 ID card copies and data associated with over 800,000 individuals may have been exposed by the gambling company.
Soon after the data exposure became public, Merkur said that one of its service providers suffered a data security incident due to the work of a “so-called white hat hacker.”
“White hat hackers operate without malicious intent and regularly report system vulnerabilities in order to improve IT security. The official and internal investigation of security vulnerabilities revealed that incorrectly configured interfaces on the merkurbets.de website theoretically allowed a registered customer to view other customers’ data,” the company said.
“However, the data was not readily accessible; it required a particularly high level of expertise and the circumvention of various security measures.”
Merkur added that the data exposure was reported to the company on 28 February by GGL and an investigation was launched immediately to determine the scope of the incident.
“The investigation revealed that “no other unauthorised third parties besides the white hat hacker were able to access the data.” In fact, “the white hat hacker has expressed no intention of sharing or misusing the information obtained,” Merkur added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543