The breach of Curaçao’s gambling licensing portal is becoming more than a cybersecurity incident. It is now a stress test for the Caribbean jurisdiction’s overhaul of online-gambling regulation.
On 17 September, the Curaçao Gaming Authority, or CGA, confirmed unauthorized access to its online portal. The authority said it had contained the access, identified its source and launched a forensic investigation. Crucially, it also said the investigation had not yet established the full scope of the incident or determined what data had been accessed.
That caveat matters. Every operator licensed in Curaçao files through the portal, which holds corporate records and personal-history information about the people behind each applicant. The CGA’s public register listed 616 licences as of 16 September: 523 held by gambling operators and 93 by suppliers.
According to the cross-border investigation known as Casino Secrets, the leaked material concerns roughly 1,350 licence applications from 111 countries. The documents reportedly identify about 800 owners linked to 646 licensed gambling companies, collectively operating thousands of websites.
The scale turns the case into a compliance issue for banks, payment companies, crypto exchanges, gambling suppliers and regulators far beyond Curaçao.
The data gap
The leaked records reportedly include licence applications, regulator assessments, passports, tax documents and financial information. Such material would ordinarily sit at the centre of integrity screening: it should allow a regulator to establish who owns a company, who controls its decisions, where their wealth came from and whether prior regulatory or criminal red flags require enhanced scrutiny.[gamesbasis]
Yet reported findings from the files suggest that some licence applications continued despite unanswered ownership questions. The reporting has raised particular questions around Stake and 1xBet, while also identifying links to brands including Blaze.com and Qbet.com. These reports concern the adequacy and consistency of due diligence; they do not establish wrongdoing by every operator or individual named in the leaked material.
This distinction is essential. A licence can confirm that an entity has entered a regulatory process. It does not, by itself, prove that the entity’s beneficial-ownership disclosures, payment flows and commercial operations remain accurate over time.
For financial institutions, the key risk lies in a mismatch between four identities:
- The consumer-facing gambling brand
- The licensed legal entity
- The entity processing deposits and withdrawals
- The people who ultimately control or economically benefit from the operation
If those four do not align, a standard onboarding file can provide a misleading picture of risk.
Reform meets reality
The timing makes the breach more consequential. Curaçao’s National Ordinance on Games of Chance, known as LOK, shifted the jurisdiction away from the old master-licence and sublicence structure. The CGA now presents itself as the online-gambling regulator and as the AML/CFT supervisor for the sector.
The previous structure had long drawn criticism because master licence holders could issue sublicences to other operators. That arrangement made it harder for outside stakeholders to identify the party responsible for an online casino, assess the quality of its controls or establish the full ownership chain.
The reformed system was designed to address that problem through direct licensing and more formalised integrity review. However, the incident highlights a difficult contradiction: a regulator can collect more sensitive ownership and compliance data, but it must also protect it effectively.
The breach therefore creates two connected risks:
- Supervisory risk: leaked documents may reveal that older licensing decisions were taken with incomplete or contested ownership information.
- Data-protection risk: applicants, directors, compliance officers and beneficial owners may face identity theft, extortion, phishing or targeted social-engineering attacks if sensitive files were accessed.
The CGA has stated that it will contact affected individuals, applicants, licensees and stakeholders directly if the ongoing investigation finds their information was compromised.
Why crypto firms should care
Crypto-facing casinos present a more complex tracing problem. A gambling group may accept deposits in digital assets, use a payment intermediary, convert funds through third parties and operate several brands under different companies. Consequently, the company named in a licence register may not be the same entity that appears in a blockchain investigation, a merchant descriptor or a customer complaint.
That makes beneficial ownership only the first layer of review. Compliance teams should also map wallets, deposit addresses, payment-service providers, domain names, app publishers, hosting infrastructure and affiliate relationships.
The practical question is simple: can the firm evidence a clear and consistent link between the regulated operator, the commercial brand and the transaction flow?
Where the answer is no, firms should not rely on a licence as a shortcut to lower risk. Instead, they should consider enhanced due diligence, including refreshed ownership declarations, source-of-wealth evidence, sanctions screening, adverse-media reviews and blockchain transaction analysis.
The red flags
The incident creates several clear review triggers for regulated firms with gambling-sector exposure:
- A licence holder uses a different legal name from its consumer-facing brand
- The registered operator has changed ownership, directors, domains or payment providers without a clear commercial explanation
- Customer funds move through offshore entities with no obvious operational role
- Crypto deposit wallets do not clearly belong to the licensed operator or its disclosed group
- The business relies heavily on affiliates, white-label suppliers or third-party payment processors
- Public ownership information conflicts with licence records, company filings, media reports or litigation documents
- The same individuals appear across unrelated gambling brands, service providers or jurisdictions
- The company cannot explain the source of wealth behind rapid expansion, major marketing expenditure or acquisitions
These indicators do not prove illicit activity. However, they justify closer scrutiny because they can obscure the actual decision-makers and beneficiaries of a gambling business.
What happens next
The immediate factual position remains limited. The CGA has confirmed unauthorised access but has not confirmed the full extent of accessed data or the consequences of the incident.
Meanwhile, the investigation’s reported numbers give the story its real weight: approximately 800 owners, 646 licensed gambling companies, 1,350 applications and 111 countries.
For the industry, the case may become a benchmark for whether Curaçao’s regulatory reset can withstand scrutiny. The relevant test will not be the number of licences issued. It will be whether the CGA can demonstrate that each licence corresponds to a verified owner, an accountable operating entity and a monitored flow of funds.