Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Regulatory

Curaçao's Regulator Confirms Its Licensing Portal Was Open to a False Identity for Nine Months

Antonina TupikovaBy Antonina Tupikova · Founder, iGaming Times2 min read
Sign in password screen quantum lab

The Curaçao Gaming Authority now says the intruder in its licensing portal came in through an ordinary applicant account registered under a false identity in December 2025, and stayed until September. It also defended its licensing checks, in wording that appears to accept some questions were still open when licences were granted.

  • The Curaçao Gaming Authority (CGA) says access was obtained through the customer-facing part of its licensing portal, using an account registered in December 2025 under a false identity
  • The account used a variant of a real person's name combined with a company that exists in Curaçao's Chamber of Commerce registry, and access continued until September 2026, according to the regulator's follow-up statement dated 22 September
  • The CGA says the account matches the claims of a German security researcher reported in the international media, calls the access a serious breach under Curaçao law and says it will report it to the relevant authorities
  • The regulator says it has not yet established what was taken and "will not repeat figures it cannot verify"; it has tightened portal security and asked licensed operators to make changes on their side
  • It defended its due diligence since the 2024 reform and warned against judging its licensing on "separate documents", after leaked files were reported to show licences granted with ownership questions unresolved

The Regulator's Account of How It Happened

The CGA first disclosed unauthorised access to its licensing portal on 17 September, saying the access had been contained and its source identified, but that the scope was not yet known. Its follow-up, dated 22 September, goes further. It says a German security researcher's claims, published in international media, to have accessed the portal and extracted data on Curaçao operators and internal CGA documents are "consistent with its internal investigation".

According to the CGA, access came through the customer-facing side of the licensing portal, the part used by applicants and licensees, via an account registered in December 2025 under a false identity. The researcher "unlawfully used a variant of the name of a real person combined with an existing company in the Curacao Chamber of Commerce registry", the regulator said, and access ran from December 2025 until it was identified and ended in September 2026. The CGA does not name the researcher. The hacker Lilith Wittmann said on Tuesday that she had been inside the regulator's systems for nine months, and Follow the Money has reported that she registered under the name of a trust-office manager known to the regulator with a fictitious applicant foundation. The CGA's reference to an existing registered company differs from that account in detail.

The regulator says the full extent of the material obtained has not been established, and that it "will not repeat figures it cannot verify and will state what was taken once the investigation supports it". Since 17 September it has strengthened security in both the back office and the customer interface, installed software security upgrades, and told online gaming operators about changes they need to make at their end, urging them to act "as soon as possible". It describes the access as "a serious breach under Curacao law" and says it "will pursue reporting of this event to the relevant Authorities".

iGaming glossary: 430+ terms explained.

A Defence of Its Licensing, With a Qualification

The statement also answers the reporting on what the files contain. The CGA says it has followed "robust internal procedures" in its due diligence since the online gaming reform began in 2024, evaluating applicants' documents and following up on its own questions before forming a view on each licence. It then adds: "This does not mean that there were still some pending matters to address by the licensed operators and followed up accordingly by the CGA." It says it does not consider it prudent "to draw conclusions on its licensing process by looking at separate documents and not considering the whole context of the particular applications".

The Weak Point Was the Front Door

The regulator's account is more uncomfortable than a sophisticated intrusion would have been. By its own description, nobody broke through its core infrastructure; someone registered as an applicant under a borrowed name and a real company, and the portal treated that account as trustworthy for nine months. A licensing system whose job is to verify who stands behind an applicant did not verify who stood behind its own user account. The CGA has now asked operators to change settings at their end, which suggests the fixes reach beyond its own servers, and they will want to know what their portal accounts could see.

The Licensing Defence Concedes More Than It Denies

The sentence about pending matters is awkwardly drafted, but its most natural reading is that some questions to licensed operators were still open after licences were granted and were followed up later. That is close to what the leaked files are reported to show, and close to what the CGA itself told Follow the Money about not rejecting applicants during the transition to the new regime. Asking readers to judge each application in its full context is reasonable. It is also a context only the regulator can supply, and until it does, the most detailed public picture of how Curaçao licensed its operators will be the one taken from its own portal.

Sources

Citations and primary documents this article references. Captured at the time of writing.

Comments

Be the first to comment.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.