Logo
external image

Must Read Data Breach at the Curaçao Gaming Authority (CGA)

Must read this

Webzcas

Winter is Coming!
Staff member
Joined
Mar 31, 2005
Location
Block S25, South Stand, Ashton Gate, BS3
I have just received an email concerning a data breach at the Curaçao Gaming Authority.

Posted below:

IMPORTANT: CGA Data Breach​


Dear Client,

We wish to draw your attention to a reported data breach involving the Curaçao Gaming Authority (CGA).

The CGA has confirmed that it is investigating unauthorised access to its online gaming portal. A substantial volume of confidential licensing and corporate information has subsequently been made publicly accessible online.

If you have previously submitted information to the CGA, we strongly recommend that you assess your potential exposure, including information relating to your company, directors, shareholders and UBOs.

We also advise against downloading documents from the published database. Files obtained from an untrusted source may contain malware or other malicious content. If documents need to be obtained for review, they should be handled and vetted by an appropriately qualified IT or cybersecurity professional before being opened or circulated.

Please also remain alert to phishing, impersonation and other targeted attempts using information that may have originated from the leaked documentation.

...
 
Last edited by a moderator:
For those who missed this, here's what happened.

On September 17, the CGA confirmed that unauthorised users had accessed its online gaming platform. Since then, the source has been found and the breach has been contained. The CGA has promised to notify impacted licensees and stakeholders directly once the entire scope of the ongoing forensic investigation has been determined.

As of right now, it is known that the access was available for around nine months. It was created by a German security researcher who has worked with other gaming regulators on similar initiatives. She felt that the public was interested in knowing who owns Curaçao-licensed businesses, thus she made records public. According to Curaçao legislation, the incident is a significant violation, and the CGA plans to submit it to the appropriate authorities.

Where regulation allows it, one way to distribute and reduce this kind of exposure is through a sub-licence or licensed white-label arrangement. Meaning your partner's security and compliance standards matter just as much as your own.

Also, avoid downloading documents from published databases. Files most likely carry a malware risk.
 

Users who are viewing this thread

Accredited Casinos

Back
Top