Home Gambling RegulationsTabcorp Fined AU$350,000 for Regulatory Breach

Tabcorp Fined AU$350,000 for Regulatory Breach

by Sienna Marques
0 views 2 minutes read
Tabcorp Fined AU$350,000 for Regulatory Breach

Tabcorp has received a fine of AU$350,000 (US$245,413) from the Victorian Gambling and Casino Control Commission (VGCCC) due to a significant compliance failure. The penalty results from the company's failure to implement mandatory multi-factor authentication (MFA) in its wagering and betting system for nearly five months in 2025, which left customer accounts prone to unauthorized access.

In its ruling, the VGCCC determined that Tabcorp was in violation of several provisions of the Wagering and Betting Technical Standards Act, specifically sections 8.3.1, 8.3.2, 10.3.2, and 10.4.3. MFA requires users to supply two forms of authentication before they can access their accounts, typically a password combined with a one-time code. The commission concluded that alternative security measures proposed by Tabcorp did not adequately meet the necessary regulatory standards.

The lack of MFA led to serious security issues, including a significant breach that Tabcorp reported on January 20, 2025, where unauthorized access was made to at least 195 customer accounts. This breach resulted in illegal withdrawals amounting to approximately $308,099, with fourteen of these accounts accessed during the period when MFA was not enforced.

Additionally, in May 2025, Tabcorp reported a bot attack targeting dormant accounts that lacked MFA protection, leading to approximately $13,471 withdrawn from player accounts in Victoria, pushing total losses across the country to nearly $31,000. Affected customers were reimbursed by Tabcorp and their banks.

The VGCCC rejected Tabcorp’s argument that MFA implementation was not mandatory or that alternative security measures were sufficient, reinforcing that standard 8.3.1 explicitly mandates the use of MFA as a basic security requirement. The commission regarded the necessary security controls as inclusive of MFA.

In determining the $350,000 fine, the VGCCC considered multiple factors, such as the severity of the breaches, actual and potential customer harm, the lengthy duration of non-compliance, and Tabcorp’s eventual cooperation. While the breaches were classified as being on the lower end of the seriousness scale, the prolonged non-compliance and associated customer losses were seen as aggravating circumstances. The fine is about 3.5% of the maximum penalty set out in the Gambling Regulation Act.

In its defense, Tabcorp noted that MFA became available to its customers in March 2025 and stated that its detection systems had been in place longer. However, the VGCCC acknowledged the company’s cooperation in resolving issues but found that Tabcorp did not fully acknowledge its responsibility for the violations. Earlier in July, Tabcorp had been fined over $2.7 million for breaches related to telemarketing and spam regulations occurring over a 16-month timeframe. Notably, the company recently acquired BetMakers for around $267 million.

You may also like