NewsRegulation4 min read

Curaçao Gaming Hack Exposes UBO Identities Across Hundreds of Gambling Companies

An investigation into data stolen from Curaçao’s gaming regulator has revealed the identities of ultimate beneficial owners behind hundreds of gambling companies, providing new insight into the scale of the regulator’s data exposure.

Written by Editorial Desk22 September 2026

Curaçao Gaming Hack Exposes UBO Identities Across Hundreds of Gambling Companies

The Curaçao Gaming Authority (CGA) hack has taken a significant turn after an international investigation analyzed confidential documents obtained from the regulator’s licensing system. The findings indicate that sensitive information relating to the ultimate beneficial owners (UBOs) of hundreds of gambling companies was accessible through the compromised system, expanding the potential impact of the breach beyond the initial uncertainty surrounding the incident.

Gambling Lore previously reported on the CGA’s confirmation that its online gaming portal had been accessed without authorization. At the time, the regulator said it had contained the incident and launched a forensic investigation, while the full extent of the compromised information remained unknown.

That picture has now become clearer following an investigation conducted by Follow the Money alongside several European media organizations and cybersecurity researcher Lilith Wittmann. The investigation, known as “Casino Secrets,” analyzed documents obtained from the compromised system and identified ownership information connected to hundreds of gambling organizations.

According to the investigation, the material covers 646 gambling organizations and roughly 800 unique owners, highlighting the breadth of information that was stored within the regulator’s systems. The documents reportedly include licensing applications, regulatory assessments and other records submitted during the licensing process.

The exposure goes beyond basic corporate registration information. The investigation found that the compromised records contain sensitive documentation submitted to the CGA as part of its due-diligence procedures, including information used to establish the identities and backgrounds of individuals ultimately controlling licensed gambling businesses.

UBO identities exposed

The disclosure of UBO identities is one of the most significant developments since the breach was first reported. Ownership structures within online gambling can involve multiple corporate entities, jurisdictions and intermediaries, meaning the regulator’s records can provide information that is not necessarily available through public company databases.

The investigation also found instances where CGA employees questioned information supplied during licensing applications, including concerns surrounding ownership structures and whether the individuals identified in regulatory filings represented the full ownership of particular businesses. Those internal assessments provide an unusual view into the regulator’s due-diligence process.

The identities themselves have not been reproduced here due to the sensitive nature of the information involved. The wider significance is that confidential UBO information collected by the regulator appears to have been accessible as part of the breach, potentially exposing individuals who had provided their information for regulatory purposes.

Sensitive regulatory records compromised

The documents reportedly contain considerably more than ownership information. Researchers say the material includes licensing applications and internal regulatory records, alongside sensitive personal and financial documentation submitted to support applications.

The scale of the information is particularly significant because the CGA requires applicants and relevant individuals to provide extensive documentation as part of its licensing and compliance procedures. The regulator's systems therefore represent a concentrated repository of information that would ordinarily be protected from public disclosure.

The investigation has also raised questions about how effectively information supplied to the regulator was being assessed. In several cases, the documents reportedly show CGA personnel identifying inconsistencies or requesting additional information during the licensing process.

How the breach unfolded

The investigation has provided additional details about how the unauthorized access was allegedly obtained. According to Follow the Money, Wittmann created a fictitious gambling company and used the application process to obtain access to the CGA's online portal.

Once access was granted, she allegedly obtained the ability to retrieve documents stored within the system. The investigation indicates that the access began months before the CGA publicly confirmed the breach, potentially giving the attacker an extended period in which to access regulatory information.

The CGA has not independently confirmed every detail of the investigation or the full volume of information that was accessed. Its own investigation remains focused on determining the scope of the incident and identifying which individuals and organizations may have been affected.

Wider implications for Curaçao

The revelations come as Curaçao continues to transition toward a more centralized regulatory framework for online gambling. The CGA has assumed a greater role in directly licensing and supervising operators, making the security of its systems increasingly important to the industry's regulatory infrastructure.

The breach creates a difficult situation for the regulator because the information exposed was collected specifically for compliance and due-diligence purposes. Operators and their owners are required to provide sensitive information to obtain and maintain licenses, creating an expectation that those records will be appropriately protected.

For the gambling industry, the latest findings shift the story from a suspected cybersecurity incident to a much broader data-exposure issue. The identities of UBOs behind hundreds of gambling businesses have reportedly been exposed, while the full consequences of the breach — including whether additional information will be published — remain to be determined.

The CGA's investigation is ongoing, and the regulator has indicated that affected parties will be contacted if it determines that their information was compromised. Until that process is complete, the precise scope of the breach remains subject to further investigation.

Continue reading

Read More

Get Connected with the Industry