The Malta Gaming Authority confirmed on 17 March 2026 that it had identified a breach within one of its systems and immediately activated its internal response protocols.
In a statement published on its official website, the MGA said all necessary containment and mitigation measures had been implemented as a precaution, with technical and operational resources directed toward a thorough investigation. Early indications, the Authority noted, suggest the activity may be attributable to an individual presenting themselves as a security researcher. Investigations remain ongoing.
What the MGA Said
The Authority is treating this matter with the utmost seriousness and continues to work closely with its technical teams and the relevant authorities to assess the situation comprehensively.
The MGA confirmed it would provide further updates to affected entities in due course. No details have been disclosed about which specific system was breached, the volume or nature of any data accessed, or the identity of the individual involved.
Sector Exposure
The MGA is one of Europe’s most significant gaming regulators. Malta’s gaming sector contributed gross value added of €714.4m in the first half of 2025, according to MGA figures, and employs more than 14,000 people — representing 4.9% of the national workforce. The island is home to licensees including Kindred Group, Betsson, and LeoVegas, among hundreds of other B2C and B2B authorised operators and suppliers.
A breach of MGA systems carries potential exposure for licensee data, compliance records, and internal regulatory correspondence — the precise nature of which depends on which system was affected, information the Authority has not yet disclosed.
Regulatory Context
The breach disclosure comes shortly after the MGA published its Supervisory Engagement Efforts for 2026, outlining a risk-based oversight approach structured around compliance, player protection, and sports betting integrity. The Authority had also recently completed a thematic review using mystery shoppers across licensed operators, which identified gaps in self-exclusion implementation at several platforms.
The MGA’s systems hold sensitive regulatory and compliance data for its licensee base. Whether the breach intersects with any of those datasets has not been confirmed. The Authority’s investigation is active and further disclosures are expected.
Source: Malta Gaming Authority









