Ace Alliance Horizon & Speed Rome
Ace Alliance Horizon & Speed Rome
Early Bird Passes Available! | November 2, 2026
Get Your Pass!
Table Of Content :

The Curaçao Gaming Authority Breach Raises Oversight Questions

trust
Ace Alliance: Delivering Trust Through Expertise
From exclusive events and interviews to real-time market trends, Ace Alliance brings you unbiased, well-informed, and data-driven content. Our editorial team adheres to strict editorial standards, ensuring that the information you receive is not only relevant but also trustworthy.

Built by market experts hosting events since 2023, with our first event in Riga, Latvia gathering over 300 top level iGaming industry executives, Ace Alliance is able to provide you with reliable information from direct interaction with experts and leaders in the sector.
Altay
Altay Celikkaya
Content Manager
Updated:
Reading Time: 3 minutes

The Curaçao Gaming Authority’s online gaming portal breach has moved beyond a cybersecurity incident after an investigation published on 22 September raised questions about how it assesses ownership information during licensing. The CGA disclosed on 17 September that it had experienced unauthorised access to its portal, and that a forensic investigation was underway, while Follow the Money said its journalists had examined documents on hundreds of licensed gambling companies and identified cases where ownership questions remained unresolved.

Curaçao flag and Curaçao Gaming Authority branding featured in an Ace Alliance graphic highlighting licensing scrutiny following the portal breach.

Regulation & Compliance

Key Takeaways on Curaçao’s Portal Breach and Regulatory Oversight

  • The CGA confirmed unauthorised access to its online gaming portal and said it had identified the source.

  • Follow the Money said documents reviewed by its journalists raised questions about ownership verification across licensed gambling companies.

  • The regulator has not yet established the full scope of the incident or confirmed which information may have been accessed.

  • The case adds scrutiny to Curaçao’s licensing and compliance framework as the jurisdiction continues implementing reforms under the LOK.

CGA Says Full Scope Remains Under Review

In its official 17 September notice, the CGA said the unauthorised access had been contained after it and its service provider activated incident-response procedures. The provider also began a forensic investigation to establish what happened and what information may have been accessed.

The authority said its investigation had not identified a compromise of its core technical infrastructure at that stage. However, it stressed that the assessment remained incomplete.

The CGA said:

It would be premature to draw conclusions regarding the overall impact of the incident.

The regulator has introduced additional monitoring and security measures while the investigation continues. It also said individuals, applicants, licensees or other stakeholders would be contacted directly if the review determines that their information may have been affected.

The incident has similarities with the Malta Gaming Authority breach reported earlier this year, when the MGA also confirmed unauthorised access to part of its IT environment and opened an investigation into the scope of the event.

Investigation Raises Ownership Questions

The wider regulatory issue comes from Follow the Money’s investigation published on 22 September. The outlet said it reviewed licensing documents obtained through the breach and found examples in which questions remained about whether declared ultimate beneficial owners reflected the people exercising effective control over gambling businesses.

Those findings are the journalists’ conclusions from the documents they examined and should be distinguished from the CGA’s own public assessment. The authority’s 17 September statement did not determine the full scope of the breach or confirm which information had been accessed.

Ownership verification is particularly important because Curaçao has been reshaping its gambling framework under the National Ordinance on Games of Chance. The CGA has introduced new compliance requirements in 2026, including stricter cryptocurrency rules for B2C licensees covering transaction monitoring, wallet controls and formal risk assessments.

The authority has also acted against operators making false licensing claims. Earlier this year, the CGA warned the public about unlicensed GEM55 gambling websites that it said were falsely presenting themselves as authorised and misusing elements of its Digital Authorisation Seal.

Licensing Oversight Comes Into Focus

The latest reporting therefore places attention on more than the technical security of the portal. For licensed operators and B2B partners, the larger question is how consistently ownership, control and supporting information are verified before and after a licence is granted.

The CGA has not announced any licensing changes in response to the incident. Its current position remains that the investigation is ongoing, with further action dependent on the findings. The distinction is important because the document-based findings reported by Follow the Money are separate from the regulator’s still-active forensic review of the portal breach.