Curaçao Gaming Authority confirmed unauthorised access to its operator licensing portal ran from December through September. The breach was detected and closed in September.
Access was gained through the client-facing side of the portal. The account was registered using a variation of a real person's name and an existing company from the Curaçao Chamber of Commerce registry. CGA called the incident a serious offence under Curaçao law and said it will refer the case to competent authorities.
The statement followed reports in international media where a German security researcher disclosed access to the portal and extraction of data on licensed operators and internal CGA documents. The regulator confirmed those claims match findings from its internal investigation. The full scope of information taken has not been established. CGA said it will notify affected individuals, applicants and licensees as required by law.
From 17 September the regulator tightened portal security, added protection measures in the back office and client interface, and rolled out software updates. Licensed operators received notices of changes they must implement on their side.
CGA also clarified licensing procedures. Since the start of Curaçao online gambling reform the regulator has followed internal vetting procedures for applicants, including document review and queries on outstanding issues before a licence is granted. The regulator said conclusions about the licensing process should not be drawn from isolated documents without the full context of each application. The investigation continues.