Key Points
- The Curaçao Gaming Authority has officially reported the incident of the hack of its online gaming portal on 17 September 2026.
- The portal processes identity and integrity data on applicants, UBOs, licensees and key persons; whether any of it was accessed remains under forensic investigation.
- This is coming at a time when the CGA itself is facing issues of credibility, including the fact that its entire Supervisory Board resigned in September 2025 and its ministerial oversight was shifted to the Ministry of Justice.
The Curaçao Gaming Authority confirmed on 17 September 2026 that hackers gained unauthorised access to its online gaming portal. The breach has been contained, and the source of the access has been identified. What remains entirely open is what, if anything, was taken.
Forensic investigation is underway, with the CGA stating: “While the unauthorised access has been contained, the investigation remains ongoing and has not yet established the full scope of the incident. The CGA is currently assessing whether and which information was accessed, as well as the potential consequences arising from such access.”
The regulator confirmed no compromise of its core technical infrastructure. Even so, it explicitly cautioned that the nature of the information it holds makes it premature to draw conclusions about the incident’s overall impact. That caveat is what the industry should read carefully, because the data this portal collects is not generic.
What the Portal Actually Processes?
The CGA’s online gaming portal is the gateway through which operators apply for licences, submit compliance documentation, and register their key persons. Per the CGA’s own privacy statement, the portal processes personal data connected to licence applications, including the names and details of statutory directors, compliance officers, ultimate beneficial owners, and holders of qualifying interests, as part of the integrity assessment the CGA carries out on every applicant.
The regulator assesses the integrity of applicants, their UBOs, holders of a qualifying interest, statutory directors, and other key persons engaged in critical activities. Those are not abstract compliance categories. They are identity documents, background records, and financial disclosures tied to real people running real businesses.
Whether the portal breach reached any of that material is precisely what the forensic investigation has not yet determined. The CGA has said it will notify affected individuals, applicants, licensees, or stakeholders directly once the facts are established. That notification, if it arrives, will be the clearest signal yet of the breach’s true scale.
The Crypto Casino Angle the Industry Is Watching
The CGA’s portal holds operator data across a large base of licensees, many of them crypto-facing operators who have historically used Curaçao’s offshore framework to operate internationally. Users on X have already raised the question of whether KYC files and UBO records for crypto casino operators could be among the material that was accessed, noting that such records could expose previously private ownership details.
The concern is not invented. Under the LOK framework that came into force on 24 December 2024, the CGA now issues all licences directly and conducts its own UBO investigations, collecting more detailed applicant data than the previous system required. In June 2026, the CGA also published dedicated crypto policy guidelines requiring wallet screening, risk-scoring, and transaction monitoring, while prohibiting personal or UBO-linked wallets outright.
None of that confirms what was accessed in this breach. However, it does clarify what kind of data environment the hackers were operating in when they reached the portal.
Six Months After the Malta Gaming Authority Was Hacked
The CGA breach arrives roughly six months after the Malta Gaming Authority confirmed in March 2026 that its systems had been accessed without authorisation. German ethical hacker Lilith Wittmann claimed responsibility for that incident, alleging in a LinkedIn post that was subsequently removed by the platform that the MGA had enabled “organised crime schemes.”
Wittmann stated she had shared the data with media partners and authorities, and warned that any extradition attempt to Malta would trigger a full release of her “entire archive of iGaming-related data.” The MGA rejected the allegations as unsubstantiated and said it condemns any unauthorised access to its systems.
Two major iGaming regulators experiencing portal breaches within six months of each other is a fact the industry should sit with. What connects them, if anything beyond timing, remains unknown.
A Regulator Already Under Institutional Strain
The breach is harder to absorb given the CGA’s recent institutional history. The whole CGA supervisory board resigned in mid-September 2025. It is confirmed by the official statement onthe Curaçao government website on 14 October 2025 that the political administrative authority of the CGA was moved from the Ministry of Finance to the Ministry of Justice on 19 August 2025.
This came after some time when Finance Minister Javier Silvania had faced immense pressure. In November 2024, forensic expert Dr Luigi Faneyte lodged a criminal complaint against the finance minister, accusing him of committing the crimes of fraud, embezzlement and money laundering through the issuance of provisional gambling licenses by the CGA during the LOK implementation process. CGA claimed innocence and lodged a criminal counter-complaint. There were reports of an ongoing criminal investigation into the CGA in November 2025; however, a corrected response was provided on 3 December 2025 by the Curaçao Financial Supervision Board which eliminated the report.
The picture emerging is that of a regulator which was busy managing the departure of regulatory officials and the change of minister in 2025 along with the allegations of irregularities. The regulator had simultaneously been working on creating a stringent compliance structure in the wake of the implementation of the LOK framework. In April 2026, new guidelines for operator T&Cs were provided by the regulator increasing the responsibilities for KYC and AML. This breach has come as a setback to this process.
Expert Analysis
We think the CGA’s statement is carefully constructed, and intentionally so. Confirming that “core technical infrastructure” was not compromised is a specific technical claim that leaves the portal’s application layer, where operator and UBO data is submitted and stored, an open question. That distinction is not reassurance. It is precision about what has been ruled out, not about what remains at risk.
The more uncomfortable read is structural. The CGA spent 2024 and 2025 building a significantly more data-intensive compliance framework under LOK, requiring operators to submit deeper identity records, UBO disclosures, and crypto wallet documentation through the same portal that was just breached. A regulator collecting more sensitive material than its predecessor was also, by definition, holding more material worth targeting.
We are not suggesting the CGA made a deliberate tradeoff. What we are suggesting is that institutions undergoing rapid regulatory expansion, combined with leadership instability, public allegations about their internal processes, and a change in ministerial oversight within the same twelve-month window, carry a structural vulnerability that goes beyond cybersecurity architecture. The MGA breach in March showed that a long-established European regulator could be accessed without immediate detection. If Wittmann’s own account is taken at face value, she described breaking in as relatively straightforward.
The CGA says it is treating this with “utmost seriousness.” The industry needs to know not just that it is being treated seriously, but that the operators who trusted the portal with their most sensitive corporate data will receive clear, direct answers about whether that data was touched. Every day the scope remains unknown is another day that question goes unanswered.