Editoriallicensing

Curaçao Gaming Authority portal breach: what we know

Data as of: CGA statement of 17 September 2026, read 21 September 2026; CGA register editions dated 16 and 21 September 2026; CGA certificate pages read 21 September 2026. 18+.

By the BullsRank desk · Published 21 SEP 2026 · Last updated 21 SEP 2026 · 5 min read

On 17 September 2026 the Curaçao Gaming Authority (CGA) said it had "identified unauthorized access to its online gaming portal". The access "has been contained and the source of the access has been identified". The CGA also said its investigation "has not yet established the full scope of the incident."

Four days later, that is still where the public record stands. The CGA has not said what information was accessed. It has not said whether player information was involved. Here is what its statement does and doesn't cover, what the regulator's public checks showed on 21 September, and how to tell a genuine CGA message from a fake one. If you only want to check a licence, our guide to checking a crypto casino licence covers both Curaçao and Anjouan.

What the CGA has confirmed

The regulator's statement of 17 September 2026, published on its news page, confirms five things:

  • Someone accessed its online gaming portal without authorisation.

  • The access has been contained, and its source identified.

  • The CGA and its service provider started incident response, and the provider began a forensic investigation.

  • The investigation "has not identified any compromise of the Authority's core technical infrastructure".

  • The CGA has added monitoring and security measures while the investigation continues.

It also sets out who will hear from it. Where the investigation finds that "information relating to individuals, applicants, licensees, or other stakeholders may have been affected, those parties will be notified directly".

What the CGA has not said

The statement does not say which information was accessed, how many records, or over what period. It does not name the portal's address. It does not mention players by that word. It says it is "currently assessing whether and which information was accessed", and that "given the nature of the information held by CGA, it would be premature to draw conclusions regarding the overall impact".

Some coverage has speculated about what the portal holds and which operators might be exposed. We are not repeating any of that as fact. Until the CGA publishes findings or notifies the people affected, nobody outside the investigation knows what was taken.

What the "online gaming portal" is used for

The CGA's own website labels portal.cga.cw as its "Online gaming portal". What flows through it is described in the CGA's own documents. Its Player Complaints Policy Guidelines (version 1.1, 18 June 2025) require licensed operators to upload to "the CGA Portal" their complaints policy, by 31 July 2025, and an agreement with at least one CGA-certified dispute-resolution provider.

So the portal is where licensees file compliance documents with the regulator. That tells you what kind of system it is. It does not tell you what was accessed. The CGA's statement doesn't say whether its public register or certificate pages share any system with the portal.

What the public checks showed on 21 September

The CGA kept publishing. On 21 September 2026 it posted a new edition of its online gaming licence register, dated that day. We compared it with the edition dated 16 September, the day before the statement:

  • Entries: 663 on 16 September, 665 on 21 September. The two new entries were both issued on 17 September 2026.

  • Status changes: none. No existing entry changed status between the two editions.

  • Past-date entries: 280 of 665 (42.1%) carried a printed expiry date that had passed on 21 September without being marked expired or revoked. On 16 September the same count was 275 (41.5%). The rise comes from four dates that passed in between and from one new entry whose printed expiry, 17 March 2026, is earlier than its issue date. It does not come from status changes.

The register moves slowly and in batches, as our Curaçao register census shows edition by edition. Nothing in these two editions looks like a reaction to the incident, and the CGA hasn't said that licences were affected.

We also opened the 13 CGA certificate pages our database links to, for casinos we track. Twelve loaded and read "current status is Active". One, for Rollbit's former Curaçao licence, returned "Not Found"; that licence has read "Expired" in the register since the edition dated 8 September. Old certificate links on cert.gcb.cw now redirect to cert.cga.cw.

Of the 62 operators BullsRank tracks, 22 show a Curaçao licence number on their profile. None of their register entries changed between the 16 and 21 September editions.

How to tell a genuine CGA message from a fake one

The CGA says it will contact affected parties "directly". A data incident at a regulator is also a good excuse for anyone sending fake notices. The web addresses the CGA itself used on 21 September 2026:

  • www.cga.cw: the website. Its news page carries the 17 September statement.

  • portal.cga.cw: the online gaming portal, as labelled on the CGA's site.

  • cert.cga.cw: certificate pages for licensed domains. Older cert.gcb.cw links redirect here.

  • gamingcontrol.spin-cdn.com: the file host the CGA links to for its register PDFs and press releases.

This list is what we observed, not a list the CGA publishes. If a message about the incident sends you anywhere else, or asks for passwords, documents or payment, check the CGA's news page first.

If you have an open dispute with a casino, the incident doesn't change the route. The CGA's guidelines say it "does not mediate in individual disputes": you complain to the operator first, then to its dispute-resolution provider. Our guide to the Curaçao complaint process sets out the steps and deadlines.

What we will update

This page changes when the CGA publishes further findings or a new register edition changes the picture. Each update carries its date. We have not contacted the CGA for this article; any statement it sends us will be added here with its date.

Cite as: BullsRank, 2026. "Curaçao Gaming Authority portal breach: what is confirmed, and what isn't." Read 21 September 2026.

About BullsRank. BullsRank (bullsrank.com) is an independent iGaming intelligence platform. It verifies operator claims against primary sources — regulator registers and operator terms — and publishes each claim with its source and the date it was checked. As of 21 September 2026 it tracks 75 operators. Methodology · Corrections policy.

Independence. No operator pays for coverage, placement or a score, and none has editorial input. How BullsRank makes money: transparency.

18+. Gambling carries financial risk. If it stops being a game: GamblingTherapy.org, Gamblers Anonymous.

Was player data taken in the Curaçao Gaming Authority breach?
The CGA has not said. Its statement of 17 September 2026 says it is still assessing whether and which information was accessed, and that individuals, applicants, licensees or other stakeholders whose information may have been affected will be notified directly.
Are Curaçao casino licences still valid after the breach?
The CGA has not said the incident affected any licence. Its register edition dated 21 September 2026 lists 665 entries, and no existing entry changed status compared with the edition dated 16 September. Check a specific licence against the latest register edition and the certificate page for the domain.
What is the CGA online gaming portal?
It is the system the CGA's website labels "Online gaming portal", at portal.cga.cw. The CGA's complaints guidelines require licensees to upload documents such as their complaints policy and dispute-resolution agreement to "the CGA Portal".
How do I know a message about the breach really comes from the CGA?
The CGA published its statement on its own news page at cga.cw. On 21 September 2026 the regulator used www.cga.cw, portal.cga.cw, cert.cga.cw and gamingcontrol.spin-cdn.com. Treat any message that points elsewhere, or asks for passwords, documents or payment, with suspicion and check cga.cw first.