Home Gambling RegulationsTabcorp Penalized $350,000 by Victorian Regulator for Security Breach

Tabcorp Penalized $350,000 by Victorian Regulator for Security Breach

by Sienna Marques
0 views 2 minutes read
Tabcorp Penalized $350,000 by Victorian Regulator for Security Breach

Tabcorp has received a fine of AU$350,000 (US$245,413) from the Victorian Gambling and Casino Control Commission (VGCCC) due to its failure to implement mandatory multi-factor authentication (MFA) for nearly five months in 2025. This lapse left customer accounts open to unauthorized access.

The VGCCC's ruling determined that Tabcorp breached several provisions of the Wagering and Betting Technical Standards Act, specifically sections 8.3.1, 8.3.2, 10.3.2, and 10.4.3. MFA requires users to verify their identities through two forms of authentication, typically a password and a one-time code. The VGCCC found that Tabcorp’s proposed alternative security measures did not meet the necessary regulatory requirements.

Tabcorp reported a significant security breach to the commission on January 20, 2025, where at least 195 customer accounts had been accessed without authorization, which led to unlawful withdrawals totaling approximately $308,099. Notably, 14 of these accounts were compromised during the very period that MFA was not in place as required.

In another incident in May 2025, the company disclosed a bot attack that targeted inactive accounts lacking MFA defenses, resulting in about $13,471 being withdrawn from player accounts in Victoria, with total losses nationwide approaching $31,000. Both Tabcorp and associated banks compensated the affected customers.

The VGCCC rejected Tabcorp’s assertions that MFA was not compulsory or that alternative methods were sufficient, emphasizing that standard 8.3.1 mandates MFA implementation categorically. The commission underscored that the provisions requiring “appropriate security controls” inherently include MFA as a fundamental safeguard.

Considerations for the fine included the seriousness of the breaches, potential harm to customers, the length of non-compliance—nearly five months—and Tabcorp’s eventual cooperation in the matter. While the breaches were characterized as “towards the lower end of objective seriousness,” the length of non-compliance and the losses incurred by customers were deemed aggravating factors.

The penalty represents around 3.5% of the maximum fine allowable under the Gambling Regulation Act.

In its defense, Tabcorp argued that MFA became available to customers in March 2025, that detection systems were already in place, and that the violations were brief and due to technical difficulties. The VGCCC recognized Tabcorp’s cooperation and reimbursement efforts but found that the company did not fully acknowledge responsibility for the violations.

This fine follows a previous penalty of over $2.7 million imposed in July for breaching telemarketing and spam regulations over a period of 16 months. Recently, Tabcorp also acquired BetMakers for about $267 million.

You may also like