Curaçao casino data leak is now a payments problem for PSPs, acquirers, and EMI compliance teams
A leak tied to the Curaçao Gaming Authority (CGA) has already exposed around 40,000 documents, about 2 TB, including UBO data, passports, tax returns, source of funds files, and business plans. For high-risk payment teams, the point is not gossip about an offshore regulator; it is that this is now a live map of merchant structures, connected entities, and onboarding data.
- Lilit Witman, a cybersecurity researcher in Berlin, reportedly had access to the CGA licensing portal for nine months and published the documents. The material covers data on the UBOs of about 800 owners across roughly 650 licensees, and the investigations are being published by FTM (Netherlands), NDR (Germany), SVT (Sweden), NRK (Norway), and The Guardian (UK).
- On 25 September, the CGA said it would not take part in SBC Summit Lisbon 2026 because all resources are being directed to the incident response. The regulator said it is conducting a forensic investigation, has filed reports with the competent authorities, is considering legal action against Witman, and is seeking removal of the published data. It also says it continues to operate normally.
- The payments angle is already visible in the reporting. In the corporate network of Platincasino’s owner, Maltese PorterPays Ltd. was identified. The Guardian also reported €15,6 mln in loans from the Santeda group to Luxembourg’s Buda Capital, and, in the case of Stake, transfers to companies linked to the founders.
- For PSPs, the first risk is hidden portfolio exposure: one UBO can sit behind dozens of brands and legal entities, while a single MID can end up processing traffic from sites the provider never intended to touch. That matters for acquirers and EMI risk teams because a clean-looking merchant profile can hide a very different operating footprint.
- Germany is the immediate compliance hotspot. GGL (Gemeinsame Glücksspielbehörde der Länder) can prohibit PSPs from servicing unlicensed operators, and now it has a ready-made corporate map to work with. Acquirers handling German traffic also face additional exposure under Visa GBPP and Mastercard BRAM.
The practical consequence for the market is straightforward: European acquirers and EMI providers are likely to run re-KYC (re-know your customer) reviews and quiet shutdowns in the coming weeks and months. If you service high-risk merchants, this is the kind of leak that turns into a portfolio clean-up, whether anyone planned one or not.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!