Home News Dutch Regulator Acts After Investigation Exposes Cruks Identity-Check Weakness
Dutch Regulator Acts After Investigation Exposes Cruks Identity-Check Weakness
Cruks Technology Was Not Breached
Cruks, also known as Gokstop, blocks registered individuals from licensed online gambling, gambling arcades and casinos. PowCrime found that some excluded people entered physical venues by presenting another person’s identification.
Cruks checks whether the identity submitted by a venue has an active exclusion. Staff must first establish that the document belongs to the visitor. If somebody else’s valid document is accepted, the register checks that document holder’s status instead.
The findings therefore do not show that Cruks was hacked or bypassed at system level. They point to a weakness in the human controls surrounding the technology.
Human Verification Remains Critical
The KSA said it published guidance in 2025 to clarify Cruks and identity-check requirements for gambling arcades. The latest case demonstrates that written procedures must be supported by consistent execution. Employees need to compare visitors with their documents, escalate uncertain matches and avoid relaxing checks for familiar customers.
The incident also highlights the difference between registering vulnerable players and enforcing their exclusion. Although recent changes to Cruks registration have accelerated entry into the system, that protection still depends on reliable controls at each physical venue.
Technology can check submitted identity data, but it cannot correct an inaccurate assessment by entrance staff. This reflects the KSA’s broadened player-protection approach, which increasingly focuses on whether safeguards work in practice.
Regulatory Action and B2B Implications
The KSA has not disclosed whether its action involves information requests, inspections or formal investigations. No fines, licence restrictions or other measures have been announced. The venues should not be described as sanctioned unless the regulator publishes a final decision.
Operators should review staff training, escalation procedures, busy-period supervision and controls preventing membership cards or other identifiers from being transferred. Technology suppliers may also face questions about how their systems support accurate verification.
The case forms part of a wider move towards evidence-based protection. Dutch initiatives include an open-source gambling risk model for assessing harmful online behaviour. Although it concerns online activity, the principle is comparable. A protection system only works when its output produces an effective intervention.