Crypto casinos registered in Curaçao may be at risk of having sensitive information exposed after the island’s gambling regulator said last week that it had been hacked.
Curaçao has long been a hub for online casinos because of relatively relaxed gambling laws under the Curaçao Gaming Authority, or CGA. On September 17, the CGA said hackers had accessed its online gaming portal, but it did not disclose the full extent of the breach.
The regulator said, 「While the unauthorized access has been contained, the investigation remains ongoing and has not yet established the full scope of the incident. The CGA is currently assessing whether and which information was accessed, as well as the potential consequences arising from such access.」
That disclosure led to speculation on X that crypto casino operators could be doxxed by the attackers. On September 21, user @smokeylisa wrote, 「CGA investigates unauthorized access to its online gaming portal. Well that's not good. Are we about to see the KYC of UBOs leaked for various CGA licensed casinos?」
The report said the CGA will directly notify any affected individuals, applicants, licensees, or other stakeholders if the hack is found to have affected them.
Because of that, some users on X speculated that details submitted by crypto casino operators, including photo IDs and other personal information, may have been stolen and could be leaked or used by criminals for extortion.
Light-touch licensing drew casino registrations
Curaçao’s gambling regulator is known for carrying out only minimal checks on casinos applying for licenses. Crypto casinos including Rollbit, 1xBet, and Stake have all been registered there.
The report added that Rollbit’s Curaçao license appears to have been revoked this month.
New rules were introduced this year
According to Protos, the country also tried to clean up its gambling reputation this year by introducing new legislation that required transparent anti-money laundering and identity verification procedures.
So far, the CGA has not said whether any specific data was exfiltrated or which licensees, if any, may have been affected.

