Skip to content

Coins

Crypto Casinos Face Doxxing Risk After Curaçao Regulator Hacked

Key Highlights Curaçao Gaming Authority (CGA) confirmed a cyberattack on its online gaming portal on September 17, with investigation ongoing into the scope of data accessed Crypto casino operators licensed...

Key Highlights

  • Curaçao Gaming Authority (CGA) confirmed a cyberattack on its online gaming portal on September 17, with investigation ongoing into the scope of data accessed
  • Crypto casino operators licensed by CGA — including major brands like Stake and 1xBet — face potential exposure of sensitive KYC documents, corporate records, and beneficial ownership details
  • Curaçao’s regulatory framework has historically relied on minimal due diligence, though new anti-money laundering legislation was introduced this year to address reputation concerns

Regulator Confirms Breach, Scope Unclear

The Curaçao Gaming Authority (CGA) disclosed on September 17 that hackers had gained unauthorized access to its online gaming portal, the central system used for license applications, renewals, and ongoing compliance filings. In a public statement, the regulator acknowledged the intrusion but stopped short of detailing what specific datasets were compromised. “While the unauthorized access has been contained, the investigation remains ongoing and has not yet established the full scope of the incident,” the CGA said. “The CGA is currently assessing whether and which information was accessed, as well as the potential consequences arising from such access,” the regulator added. The authority pledged to directly notify any affected individuals, applicants, licensees, or other stakeholders should the investigation confirm material impact.

Industry Speculation Centers on Operator Data Exposure

The announcement triggered immediate speculation across industry forums and social media, where participants highlighted the sensitive nature of data routinely submitted to the CGA. On X, user @smokeylisa posted: “CGA investigates unauthorized access to its online gaming portal” Well that’s not good…Are we about to see the KYC of UBOs leaked for various CGA licensed casinos? pic.twitter.com/Lq0PZcobm5 The concern centers on Know Your Customer (KYC) dossiers for Ultimate Beneficial Owners (UBOs), which typically include government-issued photo identification, proof of address, corporate structure documents, and source-of-funds declarations. If exfiltrated, such information could enable identity theft, targeted phishing, or extortion campaigns against operators and their principals.

Curaçao’s Regulatory History Under Scrutiny

Curaçao has long served as a primary licensing jurisdiction for crypto-native casinos, attracting operators such as Stake, 1xBet, and — until its license was apparently revoked this month — Rollbit. The island’s appeal has rested on a streamlined, low-friction licensing process that critics argue prioritized volume over rigorous vetting. While the CGA has historically conducted only minimal background checks on applicants, the jurisdiction moved this year to introduce new legislation mandating transparent anti-money laundering (AML) procedures and strengthened identity verification requirements. The breach now raises questions about whether those reforms included commensurate investments in cybersecurity infrastructure commensurate with the sensitivity of the data collected.

Why This Matters

The CGA hack underscores a systemic vulnerability in offshore gambling regulation: regulators themselves become high-value targets because they aggregate the most sensitive personal and corporate data of every licensee they oversee. For the crypto casino sector — already navigating banking restrictions, advertising bans, and evolving global compliance standards — a mass doxxing of beneficial owners would represent a catastrophic operational and reputational blow. The incident also tests Curaçao’s credibility as it attempts to shed its reputation as a lax jurisdiction. Stakeholders will be watching closely for the CGA’s forensic findings, the timeline and completeness of breach notifications, and whether the regulator’s post-breach response aligns with the stricter AML and data-protection standards its new legislation promises.

Frequently Asked Questions

What data might have been exposed in the CGA breach?

The CGA has not confirmed the specific datasets accessed. However, the portal processes license applications and compliance filings that typically contain KYC documents for beneficial owners (passports, proof of address), corporate registration records, source-of-funds evidence, and ongoing transaction monitoring reports.

Which crypto casinos are licensed by Curaçao?

Major operators historically licensed by the CGA include Stake, 1xBet, and formerly Rollbit — whose Curaçao license appears to have been revoked in September 2026. Dozens of smaller crypto casinos also hold Curaçao sub-licenses or master licenses.

What should affected operators do now?

Operators should monitor official CGA communications for breach notifications, engage independent cybersecurity firms to assess their own exposure, and prepare incident response plans for potential doxxing or extortion attempts targeting their principals. They should also verify whether their submitted KYC packages contain reusable credentials that should be rotated.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.