• Curaçao Chronicle
  • (599-9) 523-4857

CGA Defends Curaçao Gaming Licensing Process After Leaked Documents Draw International Scrutiny

Local, Politics, | By Correspondent September 23, 2026

 

WILLEMSTAD – The Curaçao Gaming Authority (CGA) is defending the integrity of its licensing procedures after documents obtained through unauthorized access to its online portal became the subject of international media investigations into Curaçao’s gaming industry.

In a statement issued September 22, the regulator warned against drawing conclusions about individual licensing decisions based on separate internal documents without considering the complete application files and the context in which the documents were produced.

Curaçao Gaming Authority visiting the Minister of Justice

The response follows international reporting based on material obtained by a German security researcher who, according to the CGA, accessed the regulator’s online portal without authorization between December 2025 and September 2026.

The incident has brought renewed international attention to the way Curaçao evaluates online gaming companies seeking licenses under the island’s reformed regulatory system.

The CGA reiterated that since Curaçao began reforming its online gaming sector in 2024, it has applied what it describes as robust internal procedures when conducting due diligence on applicants.

According to the regulator, the process involves evaluating documents submitted by operators and following up on questions that emerge during the review before forming an opinion on whether a license should be granted.

The CGA acknowledged that licensed operators could still have outstanding matters requiring additional attention after a license had been issued. Those issues, according to the authority, remained subject to follow-up by the regulator.

The CGA therefore argues that individual documents showing unanswered questions or pending issues do not necessarily provide a complete picture of the licensing process.

“The CGA does not find it prudent to draw conclusions on its licensing process by looking at separate documents and not considering the whole context of the particular applications,” the regulator stated.

The comments are significant following international reports raising questions about ownership structures, sources of capital and other issues involving companies seeking authorization to operate under Curaçao’s gaming framework.

The CGA did not address individual operators or specific licensing cases in its September 22 statement.

Instead, the regulator concentrated on explaining its overall due-diligence process while confirming that the documents at the center of the international reporting originated from unauthorized access to its system.

According to the CGA, the account responsible for the breach was created in December 2025 using a false identity. A variation of a real person’s name was allegedly combined with an existing company registered with the Curaçao Chamber of Commerce.

The unauthorized access remained possible until September 2026.

The regulator says it has since strengthened its online portal, introduced security measures in its back-office and customer-facing systems and implemented software security upgrades.

The full scale of the breach remains under investigation. The CGA said it will not endorse or repeat estimates concerning the amount of information extracted until investigators have established what was actually obtained.

The authority also intends to report the unauthorized access to the relevant authorities, describing it as a serious breach under Curaçao law.

The incident places the CGA in the position of addressing two separate but closely connected issues: the security failure that allowed unauthorized access for months and questions arising from the contents of documents subsequently examined by international journalists.

While the regulator strongly rejects conclusions about its licensing decisions based on documents viewed in isolation, further scrutiny is likely to depend on what the continuing investigation establishes about both the extent of the breach and the context surrounding the individual licensing files.

+