Curaçao Gaming Regulator Confirms Security Breach - Source Code Lab
HomeNews

Curaçao’s regulator was breached. Nobody yet knows what the attacker read.

September 22, 2026

Curaçao’s gaming regulator has confirmed a security breach of its online licensing portal, with the full extent of data accessed still unknown. The Curaçao Gaming Authority (CGA) disclosed on 17 September that unauthorised access had occurred, though it stated the breach has been contained and the source identified.

The regulator said no compromise of its core technical infrastructure has been found, but crucially has not yet determined what information the attacker may have viewed or extracted. The CGA has committed to notifying any affected parties once the scope of the breach becomes clear.

What Data May Be at Risk

The licensing portal houses sensitive commercial and personal information for all operators holding or applying for a Curaçao licence. This includes ownership structures, ultimate beneficial owner (UBO) details, source of funds documentation, and bank account information.

For operators in the application process, complete due diligence files reside within the compromised system. The nature of regulatory submissions means this data represents some of the most confidential information gaming businesses provide to any authority.

Until the CGA provides clarity on what was accessed, licensees and applicants should operate under the assumption that their full application files may have been viewed by the unauthorised party.

Immediate Implications for Licensees

The breach creates immediate operational and security concerns for Curaçao’s licensed operators. With no confirmation yet of what data was compromised, operators face uncertainty about whether competitor-sensitive information or personal data of executives and beneficial owners has been exposed.

Curaçao remains one of the most widely used licensing jurisdictions in the iGaming industry, with hundreds of operators holding licences under its regime. The breach therefore has potential implications across a significant portion of the global online gaming market.

Operators may need to review their own security protocols and consider whether any information stored in the portal could pose risks if exposed. This is particularly relevant for businesses in competitive markets where ownership structures and financial arrangements are commercially sensitive.

Regulatory Confidence and Next Steps

The incident raises questions about the security infrastructure protecting one of the industry’s major licensing jurisdictions. While the CGA has stated the breach is contained and the source identified, the lack of clarity on what was accessed will concern operators who entrusted sensitive data to the system.

The regulator’s commitment to notify affected parties suggests it is conducting a thorough investigation to determine the scope of the breach. However, the timeline for this assessment remains unclear, leaving licensees in a holding pattern as they await further information.

Operators holding or applying for Curaçao licences should monitor communications from the CGA closely and prepare to respond if notified that their data was among information accessed during the breach.

Add Source Code Lab as a preferred
source on Google

Source Code Lab

Source Code Lab Editorial Team publishes the latest iGaming news, industry analysis, and insights on iGaming software and platform solutions, including casino platforms, sportsbook technology, and gaming integrations. Visit Source Code Lab for more information.

Location Map

Let's Build Success

From concept to launch, we help build winning gaming platforms. Let's discuss your project.

Blog Form