Curaçao gambling regulator confirms hack of licensee portal
The Curaçao Gaming Authority disclosed on September 17 that its online licensing portal was accessed without authorization, with the source contained but the full scope of exposed information still unknown.
Contained, but the scope is still unclear
Curaçao’s gambling regulator disclosed on September 17 that its online licensing portal was accessed without authorization. The Curaçao Gaming Authority says the intrusion has been contained and its source identified, but the full scope isn’t established yet, and the CGA is still working out exactly what information was touched and what the consequences might be. Investigators found no sign that the regulator’s core technical infrastructure was compromised, and extra monitoring and security measures went in immediately, though the authority itself cautioned that it’s too early to draw conclusions about the overall impact.
What sits inside that portal is what makes the caveat worth taking seriously. The CGA’s public register lists 616 licenses, 523 held by operators taking bets from players and 93 by suppliers, and every application carries corporate records plus a personal history form naming the individuals behind each company. If any of that was accessed, it wouldn’t be abstract regulatory paperwork, it would be identity and ownership data on people running licensed gambling businesses. The CGA says that if individuals, applicants, or licensees turn out to be affected, it will notify them directly under applicable legal requirements.
A regulator breached under its own cybersecurity rules
The timing carries an awkward edge. In April, the CGA put out its own mandatory cybersecurity framework for licensed operators, requiring the Center for Internet Security’s IG1 controls as a baseline, multi-factor authentication on internet-facing services, monthly vulnerability scans, and a strict 24-hour window to report any incident affecting player data or system availability. Operators who don’t comply risk warnings, financial sanctions, or suspension of their licenses. The regulator now finds itself dealing with exactly the kind of incident it was asking everyone else to prepare for.
Curaçao’s licensing regime has been under scrutiny for years, and it has become a common jurisdiction for offshore operators, alongside others like Anjouan where licensing credibility has already been questioned. A breach at the regulator itself doesn’t answer the bigger question about how carefully those licenses are held, but it does raise the stakes on whoever’s data ended up exposed, and on how quickly the CGA can say what was actually taken.
“A regulator that just wrote a 24-hour incident reporting rule for everyone else is now the one racing to explain what was taken from its own portal.”
Share
SUBSCRIBE TO OUR PRIVATE CASES AND USEFUL TIPS
Subscribe to our newsletter, get only exclusive content and weekly digests, no any spam!
By providing my email, I accept the Privacy Policy.