Skip to content

Is your gambling license at risk after the Curacao Gaming Authority data leak?

On September 17, 2026, the Curacao Gaming Authority said an unauthorized party had gotten into the licensing portal where every online gaming license application is filed. This article explains what happened and in what order, who’s actually affected, and what to do next, whether or not your file was exposed.

Is your gambling license at risk after the Curacao Gaming Authority data leak? image

On September 17, 2026, the Curacao Gaming Authority said an unauthorized party had gotten into the licensing portal where every online gaming license application is filed. The access came from a Berlin-based security researcher, Lilith Wittmann, who had held administrative access to the portal for roughly nine months.

Five days later, journalists at Follow the Money published what the files showed in an investigation it ran with Wittmann and media partners NRK, NDR, Jetzt, and SVT. What’s out there now includes license applications, ownership disclosures, identity documents, and the regulator’s own internal assessments for hundreds of companies.

This article explains what happened and in what order, who’s actually affected, and what to do next, whether or not your file was exposed.

What happened at the Curacao Gaming Authority

The breach ran for roughly nine months before anyone outside the portal knew about it.

  • On December 3, 2025, Berlin-based security researcher Lilith Wittmann logged into the CGA licensing portal for the first time. She registered under the name of a Dutch trust-office manager the regulator already knew, paired with her own email address, and applied on behalf of a fictitious entity called Dreamcatcher Private Foundation. The application was approved within days;
  • From December 2025 to September 2026, Wittmann used an access-control vulnerability to gain and hold administrative access to the portal, the system where every Curacao online gaming license and supplier application gets filed and where trust offices manage their clients’ licenses;
  • On September 17, 2026, confronted about the access, the CGA closed the vulnerability and confirmed unauthorized access had occurred. It said the breach was contained, the source identified, its “core technical infrastructure” not compromised, and the full scope still under forensic investigation. It promised to notify affected individuals, applicants, and licensees directly;
  • On September 22, 2026, Follow the Money published its investigation, Casino Secrets, alongside Wittmann and media partners NRK, NDR, Jetzt, and SVT. The outlet said plainly that the documents came from hacking, and that it had only used the material Wittmann took in December, before FTM knew about the breach;
  • That same day, the CGA issued a second statement warning against drawing conclusions from documents viewed in isolation, saying the access relied on a false identity, and confirming it was strengthening portal and software security. It also said it would report the access as a serious breach under Curacao law;
  • On September 23, 2026, Wittmann released a public, searchable database of more than 40,000 documents. It comes with its own warning attached: records may be old, incomplete, or simply wrong, and anything found in it should be checked before anyone relies on it.

What was actually in the portal

The portal held the paperwork behind roughly 646 licensed companies, and that’s where the personal exposure comes from.

On the corporate side, there were license applications, structure diagrams, business plans, and financing information.

On the individual side, there were Personal History Disclosure Forms for UBOs, directors, trustees, financiers, and key persons, along with passports, tax returns, addresses, CVs, employment history, and criminal or administrative record data.

These are the exact categories the CGA’s own privacy statement says it processes. The files also contained the regulator’s internal assessments, checklists, and comments on each application, essentially a record of what the CGA itself flagged and how it responded.

What the leaked files showed about licensing decisions

Follow the Money’s reporting, based on the leaked files, is less about whether these licenses exist and more about how the CGA handled the ownership questions behind them.

According to the outlet, the files show about 800 unique owners behind 646 licensed companies running thousands of sites, and it says it verified 897 UBO records covering 767 individuals. It reports that the regulator repeatedly granted licenses after its own assessors had flagged serious problems, often accepting vague or incomplete answers, with recommendations that frequently read something like “the license may be granted,” pending later information that rarely showed up. In some files, an owner’s source of wealth wasn’t clear. In others, the declared owner didn’t seem to have enough money to plausibly be the real owner.

None of this amounts to a finding of wrongdoing, but rather Follow the Money’s account of what the regulator’s own files record, and the reporting doesn’t show these companies responding on the record.

The CGA hasn’t disputed that it granted licenses while ownership questions were still open. Its position is that the sector is in a transition period following the 2024 law, that requirements were deliberately phased so companies could come into compliance step by step, and that its practice isn’t to refuse a license or terminate activity the moment a question comes up. It has called Curacao-licensed sites operating in unlicensed markets “a matter of concern,” but says it’s “not black and white.”

Who is affected

Five groups had personal data sitting in the portal, and simply being named in the files isn’t evidence of wrongdoing:

  • The first is UBOs and owners: Follow the Money reports 767 verified individuals across 646 companies, plus roughly 30 whose status couldn’t be confirmed. Most don’t live in Curacao, but all of them had personal data filed with the regulator;
  • The second is resident directors. Curacao law requires a licensed company to have its seat in Curacao and to be managed by at least one natural person who lives there, or by a Curacao entity with a resident director, a local-substance requirement at the center of company formation in Curacao. Follow the Money reports that 94 percent of the companies had at least one Dutch director, and 40 percent of directors were born in the Netherlands;
  • The third is trust office representatives. Follow the Money identified 40 individuals across 30 trust offices: 31 hold Dutch passports, 14 were born in Curacao, and 12 were born in the Netherlands. Three offices alone manage more than 50 letterbox companies between them, a small, locally visible group carrying a disproportionate share of the exposure;
  • The fourth and fifth groups are key persons, such as compliance officers, AML and CFT officers, and chief executives, and financiers, people disclosed as a funding source rather than as an owner of record.

A lot of the people in these categories run entirely legitimate businesses. Showing up in the files usually just means they applied for or held a Curacao license the normal way.

What it means for affected owners and directors

We should start with the personal data question. The portal held passports, tax returns, financial disclosures, CVs, addresses, and criminal-record excerpts. More than 40,000 documents are now searchable by the public, and the researcher has said she plans to release the full UBO list too. The real risks here are identity theft, financial fraud, phishing that references details only a filed application would contain, and reputational damage from being tied to a controversial brand.

Curacao’s data protection rules don’t offer much practical help. The Data Protection Ordinance (Ordinance No. 84 of 4 September 2010) sets a security duty under Article 13 but does not itself contain a general data-breach notification requirement. The College Bescherming Persoonsgegevens, Curacao’s supervisory authority, was formally installed in January 2022, although it has not remained consistently active since then.

While the right to privacy is protected under Article 12 of the Staatsregeling, the practical remedies available following a data breach remain limited. The GDPR may offer additional protection in some cases, particularly where an organisation offers goods or services to, or monitors, people in the EU, although whether it applies here would depend on the circumstances.

These source-of-funds questions overlap heavily with standard anti-money laundering diligence, and they’re the same gaps the CGA’s own assessors flagged in the leaked files.

Whatever was in your file is now visible to the regulator, to journalists, and, to some degree, to the public. Files that were approved on the condition that more information would follow later could get revisited. A director who disclosed everything fully doesn’t have much to worry about from the leak itself.

The bigger risk is the nominee problem. Curacao bans bearer shares, and the LOK requires licensees to disclose who actually owns and controls them, not just who’s named on paper. The leak makes it possible to check whether those two things match: whether the person listed as owner or director was really the decision-maker, or just a name on a filing.

There’s also criminal exposure, though it’s not the likely outcome for most people involved. The LOK’s criminal provisions reach deliberate violations with up to four years in prison and a sixth-category fine, and non-intentional violations with up to a year’s detention and a fifth-category fine. For most people caught up in this, the real consequences will be regulatory and reputational rather than criminal.

That includes counterparty de-risking: banks, payment providers, and gaming suppliers routinely verify status, and being publicly tied to an enforcement story can slow down or end a relationship fast. For a trust office, the concentration numbers above matter directly, since a small handful of firms carry most of the exposure here.

This is general information, not legal advice tailored to every company owner’s file, but a few steps make sense for almost anyone in this situation:

  • Ask the CGA directly whether your file was affected. It has committed to notifying affected parties;
  • Reconstruct your own file: what you disclosed, when, and what’s changed since. Any change to UBOs, control, or key persons has to be reported to the regulator;
  • Get legal advice before the regulator comes to you, especially if any earlier disclosure was incomplete;
  • Coordinate with your trust office, co-directors, and counsel so everyone’s account lines up;
  • Treat the public database as unreliable. It comes with its own accuracy warning. Don’t rely on it, and don’t use it to look up other people’s data;
  • Protect yourself against fraud: keep an eye on your accounts, secure your identity documents, and warn family and staff about phishing that might reference your filings;
  • If Curacao is on your shortlist for a gambling license, it may be worth considering alternatives: tighter supervision is coming, and the CGA could pause new license issuances altogether until the situation is addressed.

What it means for Curacao’s licensing market

The CGA will likely tighten supervision after something this size. Local substance requirements, resident directors, and UBO tracing were already core to the 2024 law, and they’re likely to shift from paperwork exercises to actual enforcement priorities. Anyone looking at a Curacao structure, whether applying fresh or already licensed, should plan for a Curacao gaming license process that checks ownership and control more rigorously than it did during the period this leak covers, and for closer scrutiny of local director and key person arrangements.

Founders comparing jurisdictions in light of all this might also want to look at LegalBison’s broader gambling license options, or a different offshore gambling license as an alternative path.

How to verify a Curacao license

A Curacao online gaming license has a reference number in the format OGL/YYYY/NNN/NNNN, along with a digital seal that resolves through the authority’s certificate endpoint at cert.cga.cw. To check one, take the reference number or the seal shown on the operator’s site and confirm it resolves to an active, matching entry, the same check a counterparty, a bank, or a player asking “how do I look up a Curacao gaming license” can run themselves.

How LegalBison helps

LegalBison advises on Curacao gaming licensing, company formation, and the kind of ownership and control-structure review the LOK now puts front and center in every application.

For anyone reviewing what was in their file, the firm can help with UBO and control-structure review and with notifying the regulator of changes, backed by ongoing compliance officer support.

For anyone still deciding whether Curacao is the right jurisdiction, LegalBison’s Curacao gaming license team and broader legal services practice can walk through current requirements for your specific business model. Get in touch today for a free consultation.

Frequently asked questions

Is my data in the Curacao Gaming Authority leak?

The CGA has committed to notifying anyone whose information was reached. Until you hear from them directly, the better move is to reconstruct what you personally submitted through the portal and ask the CGA, rather than searching the public database, which isn’t reliable enough to confirm or rule out your inclusion.

What should I do if my Curacao license file was exposed?

Get legal advice before the regulator raises questions, reconstruct your disclosure history, coordinate with your trust office and co-directors, and notify the CGA of any change to UBOs, control, or key persons since your original filing.

Can the CGA revoke my license because of what the leak revealed?

The LOK allows revocation where the application information turns out to be so incomplete that the original decision would have gone differently, and suspension on grave suspicion. The leak itself isn’t grounds for revocation, but it has made older, unresolved disclosure gaps visible to the regulator.

Are Curacao gaming licenses still valid?

Yes. The breach hit the licensing portal, not the underlying licenses, and the regulator says its core technical infrastructure wasn’t compromised. Licenses can still be verified at cert.cga.cw.

Who owns a Curacao-licensed casino?

Ownership records are filed with the CGA and aren’t routinely public. Follow the Money’s reporting, based on the leaked files, disclosed ownership details for a number of named platforms, but the CGA’s public register itself doesn’t publish beneficial ownership.

Get In Touch With Our Experts!

Our team of experts will be glad to provide you with answers and a one-stop-shop solution to all your legal corporate needs.

Step 1 of 4

Tell us about your business

Pick one that best describes your business