Home Gambling RegulationsTabcorp Fined $350,000 by VGCCC for Security Breach

Tabcorp Fined $350,000 by VGCCC for Security Breach

by Sienna Marques
0 views 2 minutes read
Tabcorp Fined $350,000 by VGCCC for Security Breach

Tabcorp has been handed a fine of AU$350,000 (US$245,413) by the Victorian Gambling and Casino Control Commission (VGCCC). This penalty results from the company’s failure to implement mandatory multi-factor authentication (MFA) for its wagering and betting system for nearly five months in 2025, which left customer accounts susceptible to unauthorized access.

The VGCCC's ruling found Tabcorp in violation of multiple sections of the Wagering and Betting Technical Standards Act, specifically sections 8.3.1, 8.3.2, 10.3.2, and 10.4.3. MFA requires users to provide two verification methods—such as a password plus a one-time code—before being granted access to their accounts. The commission determined that alternate security controls offered by Tabcorp did not adequately fulfill these regulatory requirements.

Tabcorp reported a significant security breach on January 20, 2025, which exposed at least 195 customer accounts to unauthorized access. This incident led to fraudulent withdrawals amounting to nearly $308,099, with fourteen accounts being accessed during the timeframe when MFA was not in place.

Additionally, in May 2025, Tabcorp disclosed a bot attack targeting inactive accounts lacking MFA protection, resulting in approximately $13,471 withdrawn from player accounts in Victoria, and national losses close to $31,000. Both Tabcorp and associated banks reimbursed the affected customers.

The VGCCC rejected Tabcorp’s argument that MFA was not a requirement or that alternative measures were adequate, emphasizing that standard 8.3.1 explicitly mandates MFA use. The commission interpreted other related provisions that call for “appropriate security controls” as requiring MFA as the basic level of protection.

The $350,000 penalty considered various factors, including the severity of the breaches and the actual and potential harm to customers. The commission also factored in the duration of the non-compliance—almost five months—and Tabcorp's eventual cooperation.

Although the breaches were deemed to be “towards the lower end of objective seriousness,” the length of non-compliance and customer losses were viewed as aggravating circumstances. The fine represents roughly 3.5% of the maximum penalty permissible under the Gambling Regulation Act.

Tabcorp defended its actions by stating that MFA had been made available to customers starting in March 2025 and asserted that detection systems were in place earlier. The company characterized the violations as brief, stemming from technical issues. Despite acknowledging Tabcorp's cooperation and the reimbursements made, the VGCCC concluded that the company did not fully take responsibility for the infractions.

In July, Tabcorp faced a separate penalty exceeding $2.7 million for breaching telemarketing and spam regulations over a span of 16 months. Just last month, the operator acquired BetMakers for approximately $267 million.

You may also like