SBI Holdings to Acquire Bitbank for $288.6 Million – Deal Creates Japan’s Largest Regulated Crypto Exchange Group

Key Takeaways

Transaction Structure and Timeline

SBI Holdings signed agreements on June 24 to acquire all shares of Bitbank in a transaction valued at 46.7 billion yen, or approximately $288.6 million. The acquisition will be carried out through SBICAH GK, an investment arm of SBI Group. Once completed, Bitbank will operate as a wholly owned subsidiary.

The deal is structured in two phases. In the first step, SBI will acquire shares held by Bitbank’s founders and individual shareholders. This phase is scheduled for August 2026. In the second step, Bitbank will buy out shares currently held by corporate investors MIXI and Ceres. That stage is expected to be finalized by the end of October 2026.

The transaction remains subject to clearance from the Japan Fair Trade Commission and other standard closing conditions. Both companies have indicated that completion is expected around October 2026, assuming regulatory approval is granted.

Creation of Japan’s Largest Regulated Crypto Exchange Group

Following completion, the combined operations of SBI and Bitbank are expected to form the largest regulated crypto exchange group in Japan by trading volume. The group will integrate Bitbank with SBI VC Trade, SBI’s existing crypto exchange unit.

According to the announcement, the merged operation will account for an estimated 2.92 million crypto asset accounts. Assets under custody are projected to total approximately 1.1 trillion yen, equivalent to about $6.8 billion. On this basis, the enlarged group would surpass domestic competitors such as bitFlyer and Coincheck in trading volume.

The acquisition is described as the largest consolidation move in Japan’s regulated crypto market to date. For market participants, this signals a continued trend toward concentration among licensed operators.

SBI’s Ongoing Consolidation Strategy

The Bitbank acquisition follows a series of consolidation steps by SBI in Japan’s digital asset sector. In April 2026, SBI VC Trade absorbed Bitpoint Japan. With the addition of Bitbank, SBI further expands its footprint in exchange operations and custody services.

Bitbank has operated in Japan’s regulated crypto market for more than a decade. According to the company, it has recorded zero hacking incidents since launch. Its integration into SBI’s broader financial group brings together an established exchange brand with a large financial services conglomerate.

Bitbank CEO Noriyuki Hirosue is among the shareholders selling their stakes as part of the transaction. The deal marks the exit of a founder who built the exchange over more than ten years.

Regulatory Environment and Industry Changes

The acquisition takes place during a period of potential regulatory change in Japan’s crypto sector. Japanese authorities are examining whether digital assets should be brought under the Financial Instruments and Exchange Act. A reclassification could take effect as early as fiscal 2027.

If implemented, such a change would subject crypto exchange operators to stricter compliance requirements. In that context, scale and capital resources become increasingly relevant for exchange operators. The consolidation of platforms under larger groups may influence how the market adapts to tighter regulatory standards.

The pending review by the Japan Fair Trade Commission will determine whether the transaction can proceed as planned. Regulatory clearance is therefore a key remaining step before the merger is finalized.

Expansion Beyond Exchange Trading

The acquisition of Bitbank forms part of a broader expansion of SBI’s crypto related activities. On the same day the deal was announced, SBI launched JPYSC, described as Japan’s first trust bank backed yen stablecoin.

The group also introduced a Visa branded rewards card that converts spending into Bitcoin and other cryptocurrencies through SBI VC Trade. In addition, SBI completed a co launch of Ripple’s RLUSD dollar stablecoin in Japan.

These initiatives indicate that SBI’s crypto strategy extends beyond spot trading. The group is building exposure across exchange services, custody, stablecoins, and crypto linked payments. By integrating Bitbank, SBI increases its scale within this broader ecosystem.

Impact on Bitbank Users

Bitbank informed its customers that the acquisition will not affect existing services. Users can continue trading and using the platform during the ownership transfer. No operational disruptions have been announced in connection with the transition.

For account holders, the immediate structure of services remains unchanged. The key development is at the ownership and corporate level rather than in day to day trading conditions.

Our Assessment

SBI Holdings’ agreement to acquire Bitbank for 46.7 billion yen represents the largest consolidation in Japan’s regulated crypto exchange market so far. Once completed, the transaction will combine nearly 3 million accounts and approximately 1.1 trillion yen in assets under custody under a single group. The deal remains subject to regulatory approval and is expected to close around October 2026. In parallel, SBI continues to expand into stablecoins and crypto linked payment products, positioning the enlarged group across multiple segments of Japan’s digital asset sector.

US Credit Unions Managing $25B Join Stablecoin Infrastructure Pilot – Early-Access Program Expands Digital Asset Testing in Regulated Banking Sector

Key Takeaways

Stablecore Launches Early-Access Program for Credit Unions

Stablecore, a digital asset infrastructure provider for financial institutions, has introduced an early-access program aimed at US credit unions. The initiative is designed to allow smaller lenders to evaluate stablecoins and blockchain-based financial services before deciding on broader integration into their operations.

The program was announced in collaboration with Circuit, a credit union service organization focused on research and development, and Curql, a fintech investment collective representing more than 160 credit unions. Through this structure, participating institutions can test digital asset services within a controlled framework.

According to the announcement, credit unions managing roughly $25 billion in combined assets are eligible to explore the program’s features. The pilot provides hands-on access to stablecoin and digital asset tools rather than requiring immediate full-scale implementation.

Scope of Services: Stablecoin Payments, Bitcoin and Tokenized Deposits

The early-access initiative enables participating credit unions to test several digital asset services. These include stablecoin payment capabilities, tokenized deposits, Bitcoin support, crypto on- and off-ramps, and staking functionalities.

The testing phase allows institutions to evaluate how these services could operate within their existing banking infrastructure. Credit unions can assess technical integration, operational processes and internal compliance considerations before making decisions about permanent adoption.

Stablecore’s broader strategy focuses on integrating stablecoin and tokenized asset services directly into existing core banking systems. In February, the company joined the Jack Henry Fintech Integration Network. This network is operated by Jack Henry, a core banking technology provider serving approximately 1,670 bank and credit union core clients. Through this integration, Stablecore gains access to a large segment of financial institutions already connected to Jack Henry’s infrastructure.

Regulatory Developments: NCUA Proposes Stablecoin Licensing Framework

The launch of the pilot program comes amid evolving regulatory discussions around stablecoins within the US credit union system.

In February, the National Credit Union Administration, the federal regulator overseeing federally insured credit unions, proposed a licensing framework for payment stablecoin issuers operating through credit union subsidiaries. Under the proposal, any payment stablecoin issuer working through such a subsidiary would need to obtain an NCUA license before issuing stablecoins.

The proposal outlines a licensing process and supervisory framework. Additional rulemaking concerning reserve requirements, capital standards, liquidity management and risk controls is expected to follow at a later stage. The proposed rules were open for public comment through April 13.

This regulatory initiative signals that stablecoin activity within credit unions is moving into a more formal supervisory structure. The Stablecore pilot therefore aligns with a period in which federally insured institutions are preparing for clearer compliance expectations around digital asset issuance and services.

Credit Unions as a Growing Segment of the US Financial System

Credit unions remain a significant component of the US financial system. There are more than 4,200 federally insured institutions nationwide. While the total number of credit unions has declined over time, both membership and total assets have continued to grow.

As of the first quarter of 2026, total financial assets held by US credit unions reflect ongoing consolidation combined with asset expansion. The participation of institutions managing approximately $25 billion in assets in this stablecoin pilot indicates that digital asset experimentation is not limited to large commercial banks.

For financial service users, including those active in crypto payments or digital asset markets, credit union participation in stablecoin infrastructure testing may affect how digital payment options become available within regulated banking channels. The ability of credit unions to test on- and off-ramps and Bitcoin services within established banking frameworks may influence access points between traditional finance and crypto markets.

Our Assessment

The early-access program launched by Stablecore, in collaboration with Circuit and Curql, provides US credit unions managing approximately $25 billion in assets with a structured environment to test stablecoin payments, tokenized deposits, Bitcoin services and staking. The initiative follows regulatory steps by the NCUA to establish a licensing framework for payment stablecoin issuers operating through credit union subsidiaries. Together, these developments indicate that federally insured credit unions are moving toward formal evaluation and potential integration of stablecoin and digital asset services within existing banking systems.

StarkWare Launches Private KYC on Starknet – Zero Knowledge Proofs Aim to Reduce Personal Data Exposure

Key Takeaways

StarkWare Introduces Private KYC on Starknet

StarkWare has unveiled a Private KYC system on its Starknet network, presenting it as a demo that allows users to complete know your customer checks without disclosing their full personal information. The system relies on zero knowledge STARK proofs and STRK20 privacy features to confirm specific eligibility criteria while limiting the exposure of sensitive data.

According to the company, the approach enables users to prove individual attributes such as being over 18, holding a valid credential, or meeting other eligibility requirements. Instead of sharing an entire passport or detailed personal record, users can submit a cryptographic proof that confirms only the required fact.

StarkWare stated that identity verification processes often request complete documents when only a single data point is necessary. The Private KYC model is designed to reduce the amount of information collected and stored by institutions, which can become security liabilities once accumulated in centralized databases.

How the Private KYC Process Works

The process begins with users scanning their passport using a smartphone. The system uses the device camera and NFC chip to read the passport and confirm that the document is genuine and digitally signed by the issuing authority.

Once verified, users encrypt their identity data directly to their Starknet wallet. Rather than uploading full identity documents to a centralized server, the encrypted information remains under the user’s control. Relevant attributes are then registered in a public onchain registry.

When verification is required, users submit zero knowledge proofs derived from their encrypted data. Smart contracts validate these proofs. Verifiers can read the public registry to confirm that the necessary condition has been met, but they do not gain access to the underlying identity information. As StarkWare describes it, contracts check the proofs, not the passports.

This design aims to separate verification from data custody. Institutions confirm compliance requirements without creating additional copies of identity documents that would need to be stored and protected.

Data Breaches Provide Context for Privacy Focus

The launch comes at a time when data breaches continue to increase across industries. In 2025, the United States recorded 3,322 data compromises, representing a 79 percent increase over five years, according to StationX. The global average cost of a data breach stands at 4.4 million dollars.

Healthcare data has been particularly affected. Axis Intelligence reports that more than 1 billion healthcare records have been breached as of 2026, with an average breach cost of 7.42 million dollars. In 2025 alone, 772 large healthcare data breaches were confirmed in the United States, marking the highest annual total on record.

The crypto industry has also experienced significant incidents. In 2020, hardware wallet provider Ledger suffered a major database breach that exposed more than 270,000 customer records. The leaked data led to extensive phishing campaigns that persisted long after the initial incident.

Against this backdrop, StarkWare positions Private KYC as an alternative to traditional models that require companies to collect and store full identity datasets.

Comparison With Other Zero Knowledge Identity Models

StarkWare’s Private KYC system has drawn comparisons to World ID, a project associated with Sam Altman’s Worldcoin initiative. World ID uses zero knowledge proofs to verify that a user is human, based on biometric iris scans collected through dedicated hardware devices.

However, World ID has faced criticism over centralized custody of biometric data. StarkWare’s model differs in that it emphasizes self custody. Users encrypt their identity information directly into their own Starknet wallets rather than relying on a central database of biometric identifiers.

Both systems rely on zero knowledge cryptography to separate verification from raw data exposure. The key distinction lies in how and where sensitive information is stored and controlled.

Relevance for Crypto Platforms Requiring KYC

For crypto platforms, including exchanges, payment services, and other regulated applications, KYC compliance remains a standard requirement. Typically, this involves collecting copies of passports, proof of address, and other personal documents, which are then stored in company databases.

Private KYC introduces a model in which compliance checks can be completed through cryptographic proofs rather than direct document transfers. Verifiers confirm that a user meets predefined criteria without retaining full identity files.

For users of crypto based financial or gaming services, the model addresses a central tension in digital compliance: meeting regulatory standards while limiting personal data exposure. The demo illustrates how onchain registries and zero knowledge proofs can be combined to achieve selective disclosure.

Our Assessment

StarkWare’s Private KYC demo on Starknet presents a verification framework that uses zero knowledge STARK proofs to confirm specific eligibility criteria without revealing full identity data. The system relies on passport scanning, encrypted self custody storage, and onchain attribute registration.

The rollout takes place amid rising global data breaches and increasing costs associated with centralized identity storage. By separating verification from data custody, the model aims to reduce the volume of personal information held by institutions while maintaining compliance checks through cryptographic validation.

Bull Bitcoin Secures MiCA License in France – EU Users Retain Full Self-Custody and Privacy Features

Key Takeaways

MiCA License Secured in France After Multi-Year Compliance Process

Bull Bitcoin announced on June 23, 2026 that it has obtained a license under the European Union’s Markets in Crypto-Assets Regulation in France. The authorization enables the company to continue providing its Bitcoin exchange and payment services to users in EU member states without interruption.

Founder Francis Pouliot described the license as the result of a nearly three-year effort to enter the European market. According to his public statement, the process was fully self-financed, and the company did not seek funding from external investors or lenders.

The approval comes at a time when EU crypto rules under MiCA are tightening. Around the same period, the European Securities and Markets Authority ordered unlicensed crypto firms to exit the EU market as the MiCA deadline arrived. Against this backdrop, securing a license provides regulatory clarity for companies seeking to operate legally within the bloc.

Self-Custody Model and Privacy Tools Remain Unchanged

According to Bull Bitcoin, the MiCA license was obtained without altering its core operating model. The company states that all website and wallet features will remain the same as they were during the first half of 2026, with no additional restrictions or functional changes for users.

Bull Bitcoin operates as a Bitcoin-only, non-custodial exchange. Users must provide their own wallet address before completing a purchase. Bitcoin is then sent directly to the user’s wallet rather than being held in custody by the company. This structure means the platform does not retain control over client funds.

The company has long positioned itself around a self-custody approach. In addition to standard exchange services, it offers Bitcoin bill payment services for expenses such as rent, utilities, and real estate transactions. It also supports Lightning Network, Liquid, and Payjoin, which are tools associated with transaction efficiency and privacy.

Pouliot stated that obtaining the license did not require the company to compromise on what he described as its cypherpunk approach to self-custody and privacy. However, the announcement did not detail how potential tensions between user privacy expectations and MiCA compliance requirements were resolved.

Cybersecurity Audits Completed Without Third-Party Infrastructure

As part of the licensing process, Bull Bitcoin reported passing the required PASSI and DORA cybersecurity audits. The company emphasized that it did so without outsourcing its core Bitcoin infrastructure to external hosted providers.

According to Pouliot, relying on third-party infrastructure would have been easier and less costly but would have reduced internal control over systems. Instead, the firm maintained in-house management of its core infrastructure throughout the compliance process.

For users, this detail relates directly to how a service manages operational risk and technical control. Infrastructure decisions can affect data handling, system resilience, and service continuity. In this case, Bull Bitcoin states that its internal systems remain intact following regulatory approval.

BULL Wallet and Exchange Integration Continue Under New Authorization

In October 2025, Bull Bitcoin launched the BULL Wallet, described as a global, open-source, privacy-focused mobile application available on iOS and Android. The wallet includes opt-in integration with the company’s exchange.

Features include support for Payjoin, compatibility with Lightning and Liquid, and a policy of no data collection or push notifications. According to the company, both the wallet and its integration with the exchange remain unchanged under the newly obtained MiCA license.

For users in the EU who rely on integrated wallet and exchange services, the continuation of these features means the user experience remains consistent despite the regulatory shift.

European Expansion and Regulatory Positioning

Bull Bitcoin was founded in 2013 in Montreal by Francis Pouliot. The company has expanded its team in France and developed services tailored to the eurozone. The newly secured authorization provides what the company describes as a long-term regulatory foothold in Europe.

Pouliot has previously referenced the firm’s experience navigating Canadian oversight. The MiCA approval aligns with the company’s stated approach of meeting regulatory obligations while maintaining its core operational model.

The broader regulatory environment in the EU has prompted some crypto providers to alter operations or withdraw from certain markets. In this context, obtaining a MiCA license allows Bull Bitcoin to continue offering services legally across member states under a harmonized framework.

Our Assessment

Bull Bitcoin’s MiCA license in France allows it to continue operating its Bitcoin-only, non-custodial exchange and payment services across the European Union. The company states that its self-custody model, privacy features, wallet integration, and in-house infrastructure remain unchanged following regulatory approval. The development positions Bull Bitcoin among the providers that have secured authorization under the EU’s new crypto framework while maintaining their existing service structure.

Taiko Bridge Exploit Drains Up to $1.7 Million – Users Urged to Withdraw Assets After Chain Verification Compromise

Key Takeaways

Compromised Chain Verification Led to Unauthorized Withdrawals

Taiko, an Ethereum layer 2 blockchain, has confirmed a security breach affecting its bridge infrastructure and ERC20 vault on Ethereum. In a public statement, the project said its chain state verification mechanism had been compromised, undermining the core security assumptions behind its bridge deployments.

According to Taiko, the vulnerability allowed attackers to forge proofs and carry out unauthorized withdrawals. As a result, the integrity of bridges deployed on the network can no longer be relied upon under their previous security model.

The team advised users to withdraw assets from all Taiko bridges immediately. It also stated that affected systems had been paused and that it was coordinating with partners to contain the incident.

Flawed Message Validation Identified as Root Cause

Crypto security firm Blockaid analyzed the incident and reported that the issue appears to stem from a flaw in how the Taiko bridge validated source signals. Specifically, message proofs were accepted as valid on Ethereum without corresponding legitimate proofs on the Taiko blockchain.

This mismatch enabled the attacker to register fraudulent bridge messages and later retrieve them, triggering unauthorized releases of assets from the ERC20 vault. By exploiting the discrepancy between the two chains, the attacker was able to extract funds without providing valid proof on the originating network.

Blockaid initially estimated losses at a minimum of $1 million. Blockchain analytics firms Lookonchain and PeckShield later suggested the total value of stolen assets could be as high as $1.7 million.

Stolen Assets and Onchain Movements

Blockchain intelligence platform Arkham shows that wallets linked to the exploit currently hold approximately $1.5 million, primarily in Ether. One of the identified exploiter accounts holds more than $1.5 million worth of ETH.

PeckShield reported that 1.99 million TAIKO tokens, valued at around $189,000 at the time of reporting, were transferred to the crypto exchange MEXC. The token TAIKO is trading about 98 percent below its 2024 peak price of $0.084, according to CoinGecko.

The movement of tokens to an exchange may be relevant for users monitoring liquidity risks, token price volatility, or potential further transfers connected to the exploit. However, the majority of the reported stolen value appears to be denominated in Ether.

Part of a Broader Wave of June Exploits

The Taiko incident is the latest in a series of crypto protocol exploits reported in June. According to DeFiLlama, at least 23 exploits have occurred this month.

Among the largest incidents are the Humanity Protocol exploit, which resulted in losses exceeding $30 million, and the Syscoin Bridge exploit, which saw more than $8 million drained. In addition, a smart contract exploit on the Secret Network discovered on Friday led to the theft of $4.67 million worth of assets.

Other notable incidents this month include an attack that drained approximately $1.1 million from the OLPC or LABUBU liquidity pool on PancakeSwap, as well as exploits involving Aztec Connect, RetoSwap, and Raydium AMM. The accumulation of incidents highlights persistent vulnerabilities in bridge infrastructure and smart contract systems across multiple ecosystems.

Implications for Bridge Users and Cross Chain Activity

Bridges play a central role in enabling asset transfers between blockchains. They rely on verification mechanisms to confirm that transactions on a source chain are valid before releasing corresponding assets on a destination chain. When the verification process fails or is manipulated, funds locked in bridge contracts can be released without proper authorization.

In the case of Taiko, the compromised chain state verification mechanism directly affected the reliability of its deployed bridges. For users who have transferred assets between Ethereum and Taiko, the advisory to withdraw funds reflects a precautionary measure to limit further exposure while the issue is being addressed.

For crypto users, including those interacting with decentralized finance applications, betting platforms, or gaming protocols that rely on bridged assets, such incidents can disrupt liquidity and access to funds. They also reinforce the operational risks associated with cross chain infrastructure.

Our Assessment

Taiko has confirmed a breach of its chain state verification mechanism that enabled forged proofs and unauthorized withdrawals from its bridge and ERC20 vault on Ethereum. Estimated losses range from $1 million to $1.7 million, with most stolen assets held in Ether. The project has paused affected systems and urged users to withdraw funds from all bridges. The exploit forms part of a broader series of at least 23 crypto protocol incidents recorded in June, including several multi million dollar bridge and smart contract breaches.

LeoVegas Subsidiary Roar Vegas Wins Appeal Against SEK 8 Million Fine – Swedish Court Cites Insufficient Evidence of Duty of Care Breach

Key Takeaways

Administrative Court Cancels SEK 8 Million Fine

The Administrative Court in Linkoping has overturned a SEK 8 million administrative fine previously imposed on Roar Vegas, an operator owned by the LeoVegas group. The fine, originally issued by Spelinspektionen on 25 March 2025, followed a regulatory review of customer activity during the first quarter of 2024.

In its ruling dated 12 June under case number 3061-25, the court concluded that the regulator had not demonstrated a clear breach of the duty of care obligations set out in the Swedish Gambling Act. According to the court, the evidence presented did not meet the standard of being clear and unambiguous, which is required to impose a financial sanction.

For operators active in Sweden, the ruling clarifies how courts may assess the evidentiary threshold in enforcement actions related to safer gambling obligations.

Regulator Focused on High-Loss and Younger Players

Spelinspektionen based its enforcement decision on a review of 12 customer accounts identified as high-loss cases between 1 January and 31 March 2024. The regulator selected the highest-loss players across two age groups: 18 to 24 and 25 and older.

Three of those accounts formed the core of the regulator’s concerns. These players had monthly deposit limits ranging from SEK 100,000 to SEK 300,000. Spelinspektionen also cited rapid deposits, quick losses following deposits, and extended playing sessions as indicators of potentially harmful gambling behavior.

The regulator concluded that Roar Vegas had failed to intervene sufficiently or in a timely manner. On that basis, it issued both a formal reprimand and the SEK 8 million fine, equivalent to approximately $852,867.

Operator Cited Automated Alerts and Manual Reviews

In its defense, Roar Vegas did not dispute that the accounts in question showed risk indicators. However, the company argued that it had taken multiple steps to mitigate potential harm.

According to the court record, the operator’s safer gambling system included automated alerts, manual account reviews, deposit limits, and account suspensions. Roar Vegas also presented documentation such as action plans, system updates, and follow-up notes to demonstrate ongoing monitoring and intervention.

The company further argued that certain behavioral indicators, such as long login sessions or rapid losses after deposits, do not automatically prove gambling harm. It noted that similar patterns can occur in sports betting. Roar Vegas also referred to legal uncertainty prior to regulatory changes that took effect on 1 June 2024, particularly concerning the processing of personal health and financial data in responsible gambling checks.

The court accepted parts of this reasoning. It stated that license holders must balance privacy considerations, voluntary player tools, and stronger restrictive measures when assessing risk.

Court Applies Reasonable Time Standard

A central issue in the case was the timing and adequacy of interventions. Spelinspektionen argued that Roar Vegas acted too late and that its measures were insufficient.

The court agreed that certain interventions could have been implemented earlier. However, it emphasized that the law does not set fixed response times for every scenario. Instead, it applied what it described as a reasonable time standard, taking into account that online gambling operates continuously.

The ruling noted that some automated alerts were triggered quickly, in some cases as early as the day after initial deposits. The court concluded that while earlier action might have been possible in specific instances, the delays identified by the regulator did not reach the threshold required to justify a financial penalty.

Implications for Swedish Duty of Care Enforcement

Sweden has strengthened enforcement of safer gambling requirements in recent years. Duty of care provisions require operators to act when player behavior indicates elevated risk, but the legislation leaves room for judgment in determining when and how to intervene.

In this case, the court’s decision underscores that regulators must present detailed and conclusive evidence when alleging a breach. The documentation provided by Roar Vegas, including records of alerts and follow-up measures, played a role in undermining the regulator’s claim that a clear violation had occurred.

For licensed operators in Sweden, the ruling provides judicial guidance on how courts may evaluate internal control systems, response times, and documentation in future enforcement proceedings.

Our Assessment

The Administrative Court in Linkoping cancelled the SEK 8 million fine against Roar Vegas after finding that Spelinspektionen did not prove a clear breach of duty of care obligations. The court acknowledged areas where earlier intervention might have been possible but determined that the evidence did not justify a financial sanction. The ruling clarifies the evidentiary standard required in Swedish enforcement actions related to safer gambling and highlights the importance of documented internal procedures when regulatory decisions are challenged.

BMM Innovation Group to Exhibit at Peru Gaming Show 2026 – Focus on Testing, Cybersecurity and Regulatory Compliance

Key Takeaways

Exhibition at Peru Gaming Show 2026 in Lima

BMM Innovation Group will take part in the Peru Gaming Show 2026, scheduled for June 17-18 at the Jockey Exhibition Center in Lima. The company will exhibit at Booth No. 31-32, where it plans to present a range of services aimed at regulators, operators, and suppliers active in regulated gaming markets.

According to the company, its presence at the event reflects its ongoing involvement in Peru’s gaming sector. BMM states that Peru has been an important market for many years and that it continues to support the country’s growing gaming industry. The exhibition provides an opportunity for industry stakeholders to meet the company’s team and review its service offerings directly.

Services Covering Testing, Certification and Inspection

At the event, BMM Innovation Group will highlight the work of BMM Testlabs, its testing and certification division. The company will showcase services that include product testing, certification, and inspection for gaming technologies.

Testing and certification services are central to regulated gaming environments, where operators and suppliers must meet defined technical and compliance standards. BMM states that it has been active in supporting the Peruvian market for nearly two decades. It also notes that it was among the first approved testing laboratories under Peru’s updated regulatory framework for online gaming and sports betting.

This position under the updated framework means that BMM Testlabs has been formally recognized to assess gaming products in line with the country’s current regulatory requirements. For operators and suppliers targeting the Peruvian market, approved laboratories play a role in facilitating compliance processes.

Cybersecurity and PCI:DSS Services Through BIG Cyber

In addition to product testing, BMM Innovation Group will present cybersecurity services delivered through BIG Cyber. These services include managed cybersecurity, penetration testing, vulnerability assessments, and PCI:DSS services.

Cybersecurity has become a key operational area in regulated gaming markets. Managed security services and technical assessments such as penetration testing and vulnerability scanning are designed to identify and address system weaknesses. PCI:DSS services relate to compliance with standards for payment card data security, which is relevant for operators processing customer transactions.

By presenting these services at the Peru Gaming Show, BMM positions cybersecurity alongside compliance testing as part of its broader offering to regulators, operators, and suppliers.

Compliance Training Through RG24seven Virtual Training

The group will also showcase compliance-focused eLearning programs provided by RG24seven Virtual Training. These training modules are available in English, Spanish, and Portuguese.

According to the company, the programs are designed to support compliance in regulated gaming environments. Workforce development and structured training are presented as components of long-term operational readiness in regulated markets.

The availability of training in multiple languages reflects the company’s stated focus on international markets, including Latin America. For stakeholders operating across different jurisdictions, language accessibility can be relevant in implementing standardized compliance programs.

Peru as a Growing Gaming Market

BMM Innovation Group describes Peru as one of the fastest-growing gaming markets in Latin America. The company links this growth to increasing demand for trusted partners capable of supporting compliance, cybersecurity resilience, and workforce development across regulated environments.

The reference to Peru’s updated online gaming and sports betting regulatory framework indicates that the country has introduced revised rules governing these segments. Under this framework, approved testing laboratories such as BMM Testlabs play a defined role in assessing gaming products.

For operators and suppliers active in Peru, regulatory approval processes and compliance requirements are part of market participation. Service providers that offer testing, certification, cybersecurity, and training operate within this regulatory structure.

Industry Engagement at Booth No. 31-32

During the two-day event in Lima, visitors will be able to meet representatives from BMM Innovation Group at Booth No. 31-32. The company has also indicated that meetings can be scheduled in advance.

Trade shows such as the Peru Gaming Show serve as industry meeting points for regulators, operators, suppliers, and service providers. By exhibiting, BMM Innovation Group will present its combined capabilities in testing, cybersecurity, and compliance training to stakeholders operating in or evaluating the Peruvian market.

Our Assessment

BMM Innovation Group’s participation in the Peru Gaming Show 2026 centers on its role as an approved testing laboratory under Peru’s updated online gaming and sports betting regulatory framework and on its related cybersecurity and training services. The company states it has supported the Peruvian gaming sector for nearly two decades and will use the event to present testing, certification, cybersecurity, PCI:DSS, and compliance training solutions to regulators, operators, and suppliers active in regulated environments.

KSA Fines 711 €886,000 Over Duty of Care Breaches – Dutch Regulator Details Failures in High Risk Player Monitoring

Key Takeaways

KSA Investigation Focused on Ten High Loss Player Accounts

On 11 June 2026, the Netherlands Gambling Authority, known as KSA, published a decision imposing a €886,000 fine on 711 B.V., the operator of 711.nl. The sanction relates to breaches of Dutch duty of care requirements in the remote gambling market.

The regulator reviewed ten player accounts that recorded the highest losses at 711 between October 2023 and March 2024. According to KSA, these players not only incurred substantial losses but also gambled frequently and often during nighttime hours. The authority assessed whether the operator intervened appropriately when patterns of excessive or risky gambling behavior emerged.

KSA concluded that 711 failed in every one of the ten examined files. The decision covers conduct from 28 February 2022 to 26 June 2024, a period during which 711 held a Dutch remote gambling license.

Failures in Monitoring, Intervention, and Player Contact

Under Dutch regulations, licensed operators must actively monitor gambling behavior and intervene when there are signs of excessive play or addiction risk. These obligations are set out in the Bwrvk and Rwrvk framework. In practice, this means operators must analyze player activity, take suitable measures where necessary, and conduct personal conversations with players when there is reasonable suspicion of problematic gambling.

KSA found that 711 did not properly analyze gambling behavior in the reviewed cases. The regulator also stated that the operator failed to take suitable intervention steps and did not conduct timely and adequate personal contact with players when warning signs appeared.

Loss levels formed a central part of the authority’s assessment. One player lost nearly €78,000 in a single day. KSA compared this amount to more than two median annual salaries. Across all ten files, net deposits totaled €889,045.

The regulator further examined the operator’s approach to deposit limits. 711 allowed players to set limits up to €25,000 per day, €50,000 per week, and €100,000 per month. KSA also noted that 711 had an internal policy requiring a risk analysis once a player deposited or lost €2,500 or more. According to the decision, those analyses were conducted too late in the cases reviewed.

Fine Calculation Based on Turnover Rather Than Fixed Tariff

KSA did not apply its standard fixed fine structure. Instead, it based the sanction on turnover. The authority started with 1 percent of 711’s gross gaming result. It then added 0.25 percentage points due to what it described as higher culpability.

The amount was subsequently increased to €889,000 to align with the net deposits recorded in the ten examined player accounts. A reduction of €2,500 was applied because the case exceeded the reasonable time limit. This resulted in a final fine of €886,000.

According to KSA, the seriousness of the case justified publication of the operator’s name. The regulator stated that extreme gambling behavior continued for weeks and in some instances months without appropriate intervention. KSA also referenced a previous warning issued to 711 in June 2022 concerning duty of care enforcement.

The authority noted that 711 declined to provide financial data requested for an assessment of its ability to pay. As a result, no reduction of the fine was granted on that basis.

License Status and Next Steps

711 B.V. holds a Dutch remote gambling license valid from 16 March 2022 to 15 March 2027. The company is registered in Jabbeke, Belgium and operates the website 711.nl for the Dutch market.

The operator has the right to lodge an objection with KSA against the decision. At the time of publication of the decision, the fine had been formally imposed but could still be subject to further administrative review.

For users in the Netherlands, the case highlights how the regulator assesses compliance with duty of care obligations. The focus lies on concrete player files, documented losses, and the timing and adequacy of operator interventions. The decision also shows that KSA may adjust fines based on gross gaming result and specific case factors rather than relying solely on fixed penalty amounts.

Our Assessment

The €886,000 fine against 711 B.V. is based on documented failures in ten high risk player accounts between 2022 and 2024. KSA identified shortcomings in behavioral monitoring, intervention measures, and personal contact obligations under the Dutch Bwrvk and Rwrvk framework. The regulator calculated the penalty as a percentage of gross gaming result and aligned it with €889,045 in net deposits linked to the reviewed cases. The decision underscores the enforcement of duty of care requirements within the licensed Dutch online gambling market.