Curaçao Gaming Authority Says Licensing Portal Was Accessed for Nine Months Using False Identity
The Curaçao Gaming Authority (CGA) has confirmed that its online gaming licensing portal was accessed without authorisation for approximately nine months through an account registered using a false identity. The regulator said the unauthorised access began in December 2025 and continued until it was identified and terminated in September 2026.

The access was obtained through the customer-facing section of the CGA's licensing portal. According to the regulator, the account was created in December 2025 using a variation of the name of a real individual together with an existing company registered with the Curaçao Chamber of Commerce. The CGA subsequently identified the account and ended the unauthorised access in September.
The disclosure follows an initial announcement by the CGA on September 17, when it confirmed that unauthorised access to the online gaming portal had been detected. At that stage, the regulator said the access had been contained, its source had been identified and its service provider had begun a forensic investigation. The CGA also said that its investigation had not identified a compromise of its core technical infrastructure.
The regulator subsequently issued a further statement after international reports concerning information allegedly obtained from its systems. The CGA said that claims made by a German security researcher regarding access to the portal and the extraction of information concerning Curaçao-licensed operators and internal regulatory documents were consistent with the findings of its own investigation. It described the incident as a serious breach under Curaçao law and said the matter would be reported to the relevant authorities.
The full extent of the information accessed has not yet been established. The CGA has stated that it will not publish figures or other details that it cannot verify and will identify the material obtained once the investigation provides sufficient evidence. The authority has also indicated that individuals, applicants, licensees or other stakeholders whose information may have been affected will be notified in accordance with applicable legal and regulatory requirements.
The licensing portal is central to Curaçao's current online gambling regulatory system. Under the National Ordinance on Games of Chance (LOK), which entered into force on December 24, 2024, applications for online gaming licences and supplier licences must be submitted through the CGA's online portal. Licensees also use the system for periodic, incident and change reports.
The portal therefore contains information submitted as part of the licensing and ongoing regulatory process. The CGA's portal documentation states that corporate account holders use the system for applications and licence management, while qualified and key individuals, including ultimate beneficial owners, may have personal accounts associated with corporate applications. The required application documentation includes online gaming application forms, business and corporate information, personal history declarations and related supporting documents.
The licensing framework itself places significant emphasis on the identification and verification of persons connected with applicants. The CGA states that an application may be refused where the identity, existence or involvement of ultimate beneficial owners, persons with qualified participation or policymakers cannot be verified. Other grounds for refusal include an inability to verify the source of funds, certain relevant criminal convictions involving key individuals and failure to register with the goAML reporting system where required.
The incident has consequently raised questions about access to information held within the licensing system, although the CGA has not yet confirmed precisely which records were obtained or whether all information allegedly reported as compromised was actually accessed. The regulator has specifically cautioned against drawing conclusions from individual documents without considering the complete context of the relevant licensing applications.
The CGA has also addressed its licensing procedures following the incident. It said that since the implementation of the online gaming reforms in 2024 it has maintained procedures for conducting due diligence on applicants, assessing submitted documentation and following up on outstanding questions before forming an opinion on whether a licence should be granted. The authority acknowledged that some licensed operators could still have had outstanding matters, but said these were subject to follow-up procedures.
Reports concerning the breach have included references to confidential licensing, ownership and financial documentation relating to Curaçao gaming companies. However, the CGA has not confirmed the full body of information allegedly obtained and has stated that further details will only be released once they are supported by the ongoing investigation.
Following detection of the incident, the CGA said it strengthened security measures covering both its back-office systems and the customer-facing portion of the portal. Software security upgrades were also implemented. Licensed operators were informed of changes affecting their side of the system and were instructed to implement the necessary measures.
The incident occurred while Curaçao's online gambling sector was operating under a substantially revised regulatory framework. The LOK replaced the previous licensing arrangements and established the CGA as the regulator responsible for licensing and supervising online gaming activities. The current system requires applications to be submitted through the central portal and provides for a two-phase licensing process covering the integrity and financial stability of applicants followed by additional regulatory and LOK requirements.
The CGA's investigation remains ongoing. The authority has said it will provide additional information as further facts are established and has indicated that the relevant parties will be notified where the investigation determines that their information may have been affected. Until the investigation is completed, the regulator has not established the full scope of the information accessed or the complete consequences of the unauthorised access.
By fLEXI tEAM





Comments