The Curaçao Gaming Authority (CGA) has disclosed that its online gaming portal suffered unauthorised access, in a statement issued Friday, September 18. The regulator, which oversees a significant share of the world’s offshore online gambling licensing, said the breach has been contained and that the source of the access has been identified.
According to the CGA, its incident response procedures were activated as soon as the breach was detected, and its service provider launched a forensic investigation to determine what happened. The regulator said the unauthorised access has since been contained, but that the investigation is ongoing and has not yet established the full scope of the incident. It is still assessing what information, if any, was accessed and what the consequences of that access might be.
The CGA said its investigation has not found any compromise of its core technical infrastructure, though it cautioned that the sensitivity of the data it holds makes it too early to draw firm conclusions about the incident’s overall impact. As a precaution, it has introduced additional monitoring and security measures while the investigation continues, and said it is treating the matter with “utmost seriousness.”
The regulator added that it is working to establish all relevant facts and will take further action as warranted by the investigation’s findings. Where individuals, applicants, licensees, or other stakeholders are found to have been affected, the CGA said those parties will be notified directly in line with applicable legal and regulatory requirements.
“The CGA recognises the concern that this incident may cause and remains committed to transparency throughout this process,” the regulator said, adding that further updates would follow as more facts are established. It said no further details could be disclosed at this stage given the ongoing nature of the investigation and its engagement with relevant authorities.
The disclosure comes roughly six months after the Malta Gaming Authority confirmed it had also been the target of a hack, in March of this year.