Croupier. The industry, dealt straight.

EnforcementRegulationCuraçao

CGA says false-identity account had access to its licensing portal until September

The Curaçao regulator says access ran from December 2025 until it was spotted in September 2026. It has not yet established what data was taken.

The Curaçao Gaming Authority (CGA) said on 22 September 2026 that its online licensing portal was accessed without authorisation for several months through an account registered under a false identity. It called the breach serious under Curaçao law and said it would report the matter to the relevant authorities.

The CGA said a German security researcher had claimed in international media to have extracted data on Curaçao operators and internal CGA documents. The regulator said this was consistent with its own investigation, which led to an earlier statement on 17 September 2026.

According to the CGA, the account was registered in December 2025 on the customer-facing side of the portal. The researcher used a variant of a real person's name together with an existing company listed in the Curaçao Chamber of Commerce registry. Access continued until September 2026, when it was identified and ended.

The CGA said the full extent of the material obtained has not been established. It said it would not repeat figures it cannot verify and would state what was taken once the investigation supports it.

Key details

  • Entry point: the customer-facing part of the licensing portal.
  • Account: registered December 2025 under a false identity; access ran until September 2026.
  • Response: security strengthened in the back office and customer interface since 17 September 2026, plus software security upgrades.
  • Operators: informed of changes at their end and urged to implement them as soon as possible.
  • Legal step: the CGA said it would report the event to the relevant authorities.
  • Licensing process: the CGA said it has run due diligence on applicants since the 2024 reform of Curaçao online gaming. It said individual documents should not be used to judge a licensing process without the full context of each application.

Why it matters

Licensed operators have a specific task: the CGA has told them to apply security changes on their side of the portal as soon as possible.

The notice does not say which operators' data was affected, what categories of document were taken, or whether affected parties will be told individually. The CGA said it will give more information as its investigation progresses.

Get stories like this first. Follow Croupier on Telegram. Join

Drafted with AI assistance from the regulator's official announcement, fact-checked automatically against that source and reviewed by the editor before publication. How we work.