For roughly nine months, someone who should not have been inside the Curaçao Gaming Authority’s online licensing portal was inside it anyway. The Curaçao Gaming Authority (CGA) confirmed that unauthorized access began in December 2025, ran until the regulator identified it in September 2026, and was obtained through a false identity. On 17 September 2026, CGA notified licensees and said the access had been contained. Primary trade coverage of the confirmed window and identity method is in iGaming Expert’s report; the same-day local disclosure is summarized by Curaçao Chronicle. Canonical BreachHistory record: https://breachhistory.com/curacao-gaming-authority/curacao-gaming-authority2026.
That CGA confirmation is the spine of this story. German security researcher Lilith Wittmann later claimed she was the person who registered with a borrowed Dutch trust-office manager’s name (and her own email), spent months in the portal, and published a searchable set of roughly 40,000+ licensing documents covering ownership links for on the order of 646 Curaçao licensees. Treat her publication and CasinoSecrets corpus as secondary reporting about impact — not a substitute for the regulator’s own notice that unauthorized portal access happened, was contained, and is still under forensic review.
What CGA confirmed
In its 17 September 2026 statement, CGA said it had detected unauthorized access to its online gaming portal. The regulator and its service provider activated incident-response procedures, identified a source, and contained the access. A forensic investigation continued. At the time of that notice, CGA said investigators had found no indication that core technical infrastructure was compromised — an important boundary. This was framed as portal unauthorized access, not a confirmed wipe of every backend system on the island.
CGA also said it could not yet state the full scope of what was viewed or copied, or the complete downstream consequences. That caution stayed in place even after trade press reported later detail on how long the access window lasted. When a regulator says “investigation ongoing,” readers should hear: containment and identity of the access path can be known before a finished inventory of every file touched.
Follow-up coverage carried CGA’s fuller timeline: access obtained in December 2025 via a false identity, continuing until discovery earlier in September 2026. CGA said it had implemented additional monitoring and security measures across back-office and customer-facing interfaces, and that it would notify individuals, applicants, licensees, or other stakeholders directly if the investigation showed their information was affected — consistent with applicable legal and regulatory duties.
How the access worked — what is public
The public kill chain is short and ugly, and it does not require a zero-day novel exploit story to matter.
According to Wittmann’s account as reported by iGaming Expert, she registered for portal access using the name of a Dutch trust office manager paired with her own email address, then received access to the regulator’s portal. CGA’s confirmed fact pattern matches the method class: unauthorized access obtained through a false identity, not (on present public evidence) a ransomware encryptor or a remote code exploit against “core technical infrastructure.”
Identity verification on a licensing portal is not a paperwork nicety. When the people who grant and supervise online gambling licences accept a mismatched identity package, the portal becomes a long-lived document library for whoever sits behind the fake name. Nine months is not a drive-by — it is a sustained relationship with a system that believed the registrant was someone else.
What remains unpublished in CGA’s own voice is a full technical post-mortem: which exact registration checks failed, whether any human reviewer signed off, what logging existed, and when the first anomalous session should have been visible. Inventing those steps would invent facts. The verified public method class is false-identity registration leading to portal access.
What the researcher published (secondary to CGA)
After CGA’s notice, Wittmann publicly claimed responsibility and described nine months of access. On 23 September 2026, reporting around CasinoSecrets / 15M said she released part of the material into a public search tool with more than 40,000 documents, searchable by company and domain, and framed as revealing ownership and operating links across Curaçao-licensed gambling companies. Secondary coverage places the ownership-mapping exercise on the order of roughly 646 licensees — a researcher/corpus figure, not a CGA-attested “X records stolen” census.
Wittmann’s description of typical Curaçao application packs — company-register extracts, corporate structure charts, business plans, financing information, internal assessment notes, support tickets, and reviewer comments — explains why a licensing portal dump is not a consumer email list. It is the paperwork that shows who owns what and what assessors asked along the way. CasinoSecrets warns that some records may be old, incomplete, or inaccurate.
Wittmann is associated with Europe’s Chaos Computer Club and previously accessed material tied to the Malta Gaming Authority. That history explains why trade desks recognized the name quickly. It does not change verification hierarchy: CGA confirmed the unauthorized portal access; the researcher’s release is how much of the impact became visible publicly.
What was likely in scope — and what was not
From CGA’s role and from the secondary document descriptions, expect licensing-adjacent material: applicant and licensee corporate records, ownership and control charts, domain-to-entity mappings, financing narratives, and internal review artifacts. That is sensitive for beneficial-ownership transparency fights, for competitors, for journalists, and for anyone who wants to craft highly specific business-email compromise against a Curaçao-licensed brand.
What this is not, on present evidence:
- A confirmed mass dump of every retail player’s deposit history from every Curaçao casino
- Proof that CGA’s “core technical infrastructure” was rooted, per the regulator’s September statement
- A finished, CGA-published person-level PII census with a single headcount
- Permission to treat every CasinoSecrets hit as courtroom-ready truth without checking primary registers
Player-facing brands will still feel secondary harm. Ownership charts and internal notes are rocket fuel for phishing that cites real subsidiary names, real domains, and real assessor language. “We don’t have a player CRM dump” does not mean “nobody is at risk.”
Timeline readers can use
- December 2025: Unauthorized access to CGA’s online gaming portal begins, obtained through a false identity (CGA-confirmed window as reported in trade press).
- December 2025 – early September 2026: Access continues for roughly nine months while the registrant holds portal privileges.
- September 2026 (pre-notice discovery): CGA identifies the unauthorized access; contains it; service provider begins forensics.
- 17 September 2026: CGA issues notice to licensees / public statement: unauthorized portal access detected, contained, source identified; investigation ongoing; no indication of core infrastructure compromise at that stage; stakeholder notification promised if personal or other protected information is shown affected.
- ~18 September 2026: Local and trade outlets restate the containment and ongoing-scope language.
- Post-notice: Wittmann claims responsibility and describes the false-identity registration method; CGA responds on due-diligence process for licensing and says it cannot yet determine the full extent of material obtained until investigation completes.
- 23 September 2026: Secondary reporting: CasinoSecrets opens public search over 40,000+ documents from the claimed CGA-derived set; ownership mapping for a large swathe of licensees enters public discussion.
- 28 September 2026 (this article): BreachHistory indexes the verified CGA portal incident at curacao-gaming-authority2026.
If you only keep two dates, keep December 2025 (start of access) and 17 September 2026 (CGA licensee notice after containment).
Who is at risk
Curaçao licensees and applicants
These are the populations inside the portal’s natural document set. Corporate officers named on applications, UBOs on structure charts, and compliance contacts listed in tickets should assume their names, addresses, and corporate narratives may now be easier for strangers to assemble — whether or not CGA has finished its individual notification analysis. Expect phishing that pretends to be “CGA post-breach re-verification,” “urgent beneficial-ownership update,” or “forensic counsel needing a fresh upload of your application pack.”
Trust offices, PSPs, and professional intermediaries
Curaçao’s licensing ecosystem leans on Dutch and international intermediaries. A false identity that borrowed a trust-office manager’s name is itself a warning flare for those firms: attackers and researchers both understand that intermediary brands are skeleton keys to regulatory portals. Trust offices should treat cold requests that cite “CGA portal remediation” as hostile until verified on a known phone number.
Employees and contractors named in application packs
Business plans and org charts often name people who never expected to be searchable next to a gambling licence. Those individuals face résumé-level exposure and targeted social engineering even when no player wallet data is involved.
Players and the general public
For a random casino customer asking “was I affected by the CGA data breach,” the honest answer is: CGA has not published a player-level census. Risk is mostly indirect — scam emails abusing Curaçao-licence branding — unless you are an officer, applicant contact, or intermediary named in licensing files. Do not download alleged “full CGA player dumps” sold on forums; those archives are frequently malware bait.
Journalists, NGOs, and competing operators
Beneficial-ownership transparency was the public-interest pitch behind CasinoSecrets. That does not make every scraped PDF accurate, but competitive intelligence will spike. Operators should prepare board-ready ownership explanations from primary sources, not a third-party search UI alone.
What CGA said about licensing integrity
Wittmann’s parallel critique alleged CGA had overlooked serious leadership problems when granting licences. CGA pushed back: since becoming overseer under the newer framework in 2024, it said it follows robust due diligence — evaluating documents, following up on questions, and refusing judgments from isolated pages ripped out of context. That is a dispute about regulatory quality beside the security incident, not a substitute for the confirmed unauthorized-access facts. CGA also said it could not determine the full extent of material obtained until investigation work finished: containment can be real while inventory remains incomplete.
Industry context: when the regulator’s portal is the prize
Online gambling regulators hold a strange combination of secrets and public duties. They must know who really owns an operator, how money moves, which domains map to which licence, and what assessors still doubt. That same corpus is exactly what investigative reporters — and criminals — want. A consumer breach dumps emails. A licensing-portal breach dumps the map of the industry.
Curaçao’s sector has spent years under pressure to move from older master-licence models into a more centralized CGA-led regime. A nine-month false-identity stay inside the new portal is not only an IT embarrassment — it is a stress test of whether the modernized licensing machine can tell a real intermediary from a carefully named impostor. Other gambling authorities watching Malta’s earlier Wittmann-linked episode and now Curaçao’s confirmed access should treat portal identity proofing as a board-level control, not a help-desk checkbox. Prolonged unauthorized access is often worse than a loud one-day ransomware banner, because the quiet window is when exfiltration looks like ordinary licensed use.
Phishing and fraud patterns to expect
Whether a given reader’s file is in the 40,000-document search set or still only inside CGA’s unfinished forensic inventory, the brand “CGA breach” will power scams. Concrete lures to reject:
- “CGA Compliance: re-upload your licensing dossier after the September portal incident — new SharePoint enclosed.”
- “Your UBO chart was in CasinoSecrets — pay crypto for takedown.”
- “Trust office verification: confirm the Dutch manager identity used on your CGA account.”
- “Player support: Curaçao regulator requires you to re-KYC via this mirror site.”
- Messages that paste iGaming Expert or Chronicle screenshots and demand an OTP “to secure your licence.”
Real CGA or counsel notices will not ask for cryptocurrency, remote-access software, or passwords typed into a random form. Out-of-band verify using contact channels you already have from prior licensing correspondence — not from the email that frightened you.
What you should do
- Licensees and applicants: Inventory which documents ever lived in the CGA portal. Assume those filenames and narratives are known to strangers until CGA’s investigation says otherwise. Brief executives and communications teams with a single accurate statement that cites the September 17 notice, not forum rumor.
- Rotate portal credentials and review who still has access on any CGA or intermediary account tied to your group. Remove dormant users. Enforce phishing-resistant MFA where the portal supports it.
- UBO and officer hygiene: Watch for identity fraud against people named on structure charts. Consider credit monitoring where available for named individuals in high-risk jurisdictions.
- Trust offices and PSPs: Alert staff that impostors may abuse your firm’s naming conventions. Require dual control on any “regulator portal registration” performed on a client’s behalf.
- Security teams: Hunt for unusual outbound transfers of licensing packs from shared drives that mirrored what you uploaded to CGA. Preserve logs. Coordinate messaging with counsel rather than improvising a player-count you do not have.
- Do not download alleged “full CGA dumps” from Telegram or leak forums. Prefer official CGA updates and reputable trade reporting.
- Do not pay takedown vendors who claim they can scrub your company from a public investigative database for a fee.
- Players: Treat cold “Curaçao licence re-verification” mail as fraud unless it matches a known operator channel you already use. Change reused passwords on gambling sites as general hygiene, not because CGA published your wallet file.
- Journalists: Lead with CGA’s confirmed unauthorized-access window and containment; label researcher document counts as secondary; cite iGaming Expert, Curaçao Chronicle, and 15M / CasinoSecrets coverage accurately.
- If you later receive a direct CGA or counsel notice: Follow that letter’s categories. It becomes your personal or corporate exposure source of truth — not a search UI and not this blog.
Was I affected?
Short answer for most retail gamblers: CGA has not published a player-by-player list tied to this portal incident. The verified population centers on the licensing portal — applicants, licensees, intermediaries, and people named in regulatory files.
Short answer for operators and named officers: if your group held or sought a Curaçao licence during the December 2025–September 2026 window, treat portal-held application material as potentially exposed pending CGA’s finished scope work and any direct notice. Secondary public search tools may already surface documents linked to your domains or entities; verify matches against your own records before panicking or before issuing denials you cannot sustain.
For searches like “Curaçao Gaming Authority data breach,” “CGA breach 2026,” or “was I affected CGA portal,” prioritize the regulator’s September 17 notice, later CGA updates, and skepticism toward anyone selling “the full 2 TB” as a consumer check service.
What this incident is not
It is not an unverified ransomware leak-site rumor substituted for a regulator statement. It is not, on present CGA wording, proof that every backend system behind Curaçao licensing was compromised. It is not automatic confirmation that every CasinoSecrets document is complete or current. It is not a reason to invent a million-player census.
It is a verified CGA disclosure of unauthorized licensing-portal access from December 2025 through September 2026 via a false identity, contained before the 17 September licensee notice, with ongoing forensics — and with a high-profile researcher publication of tens of thousands of documents as the main public window into likely contents.
Canonical record and sources
BreachHistory indexes this incident as a verified Curaçao Gaming Authority confirmation: unauthorized access to the online gaming / licensing portal from December 2025 to September 2026 obtained through a false identity; access contained; licensees notified 17 September 2026; forensic investigation ongoing; no indication of core technical infrastructure compromise at the September notice stage. Researcher Lilith Wittmann’s claim of responsibility and publication of roughly 40,000+ documents / ownership mapping on the order of ~646 licensees is catalogued as secondary impact reporting. Full entry: https://breachhistory.com/curacao-gaming-authority/curacao-gaming-authority2026.
Primary and reputable secondary sources used here: iGaming Expert — CGA unauthorised access extent; Curaçao Chronicle — unauthorized access investigation; 15M — CasinoSecrets opens 40,000 Curaçao gaming files. Related BreachHistory reading on privileged portals and regulator-adjacent incidents includes NAIC’s 2026 regulator compromise coverage and London Hydro’s customer-portal theft — different facts, same discipline of separating confirmed operator/regulator language from secondary dumps.
If CGA later publishes a finished inventory, names affected natural persons, or revises the infrastructure-compromise finding, update the catalog row. Until then the accurate one-liner stays tight: CGA confirmed nine months of false-identity access to its licensing portal, contained it, notified licensees on 17 September 2026, and is still measuring full document impact while a researcher’s 40k-file release fills the public gap.