The Curaçao Gaming Authority has disclosed that its online gaming portal was the target of a cyberattack, marking a significant security incident for the offshore regulator.
The CGA confirmed the breach on Friday, 18 September 2026, stating that unauthorised access to its portal had been identified and subsequently contained.
Alongside its own response teams, the regulator’s service provider was immediately brought into action once the incident was detected.
The CGA said: “Upon detection of the incident, the CGA and its service provider immediately activated their incident response procedures and its provider commenced a forensic investigation to determine what happened.”
A forensic investigation is currently underway to establish the full scope of the breach, though authorities have not yet released comprehensive details about what data or systems may have been affected.
The regulator acknowledged that the source of the unauthorised access had been identified, though it stopped short of naming the party or parties responsible.
The CGA said: “While the unauthorised access has been contained, the investigation remains ongoing and has not yet established the full scope of the incident.”
The Curaçao Gaming Authority, which licenses a large number of online gambling operators worldwide, plays a central role in regulating the global iGaming industry from its Caribbean jurisdiction.
A breach of this nature raises questions about the security of licensing data, operator information, and potentially sensitive records held within the regulator’s digital infrastructure.
The CGA moved to reassure stakeholders of its commitment to openness throughout the process, pledging continued updates as the investigation progresses.
The regulator stated: “The CGA recognises the concern that this incident may cause and remains committed to transparency throughout this process. Further updates will be provided as appropriate as additional facts are established.”
Engagement with relevant authorities is ongoing, and the CGA indicated that this limits what it can share publicly at this stage.
The regulator concluded: “As the matter remains subject to investigation and engagement with the relevant authorities, no further details can be disclosed at this time.”

