-
CGA data breach. What happened
For those who missed it, the CGA confirmed on September 17 that its online gaming portal was accessed without authorisation.
The breach has been contained and the source identified, but the forensic investigation is still ongoing, and the full scope of what was accessed hasn't been established. The CGA has committed to notifying affected licensees and stakeholders directly once it is.
What's now known is that the access lasted roughly nine months. The person behind it was a German security researcher who has done similar work involving other gaming regulators. She released documents citing public interest in understanding who actually controls Curaçao-licensed companies. The CGA has described it as a serious breach under Curaçao law and intends to report it to the relevant authorities.
Licensing files contain information not just about the named operator but about the full corporate structure behind it: directors, shareholders, UBOs, and the technical and compliance partners involved in running the operation. Anyone whose information passed through the portal as part of a licensing process should be assessing their potential exposure as the notification recommends.
One thing this puts a spotlight on is how risk is distributed across different operating models. Where regulation allows it, one way to distribute and reduce that exposure is through a sub-licence or licensed white-label arrangement, which means your partner's security and compliance standards matter just as much as your own.
Further updates will come from the CGA directly. Worth monitoring their official channels rather than relying on third-party reporting while the picture is still incomplete.
-
Tags for this Thread
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules