WILLEMSTAD – The data breach involving the Curaçao Gaming Authority’s licensing portal is drawing new attention to the role of foreign private companies in reviewing applications for Curaçao online gaming licenses.
Information about the operation of the hacked portal indicates that access was not limited to employees of the Curaçao Gaming Authority (CGA). Employees of two private companies outside Curaçao also had accounts and participated in important stages of the licensing assessment process.
Random Consulting, based in Malta, was involved in due diligence work. According to the available information, its responsibilities included checking documents, determining whether applications were complete, consulting databases and examining background information.
A second company, Cyprus-based HSJ Consult, subsequently carried out what is described as the “suitability” assessment.
That stage involves determining whether an applicant is considered suitable for a gaming license and preparing a recommendation regarding whether the license should be issued and what conditions may be appropriate.
The CGA remains the authority that formally issues the license.
The arrangement means, however, that important preparatory elements of Curaçao’s licensing process have been carried out outside the regulator itself. Document verification, background checks, risk-related assessments and preparation of recommendations used in the licensing process have partly involved external contractors.
The issue has taken on additional significance because of the nature of the information processed during those assessments.
Gaming applications can contain passports and other identity documents, corporate ownership structures, financial information and details concerning Ultimate Beneficial Owners. The breach therefore raises questions not simply about who could enter the portal illegally, but also about how access to individual files was structured among legitimate users of the system.
Curaçao trust-sector organization United Trust Companies (UTC) has not alleged that Random Consulting or HSJ Consult had unnecessary access to files.
Instead, the organization is focusing on the broader principle governing sensitive regulatory information: companies required to provide confidential information to a government regulator should be able to trust that the information is properly protected and used only for the purposes for which it was submitted.
That principle has become more important following indications about the potential extent of the breach.
According to UTC, the CGA has informed the sector that it assumes the complete licensing-portal database was accessed and searched between December 2025 and September 2026.
Corporate Service Providers have consequently been asked to notify people who may be affected, while individuals whose identity documents became public have been warned about possible identity misuse.
The revelations place two separate questions before the gaming regulator: how an unauthorized party was able to gain extensive access to the licensing system, and how access to some of Curaçao’s most sensitive gaming-regulatory information is organized between the CGA and private contractors operating abroad.