Tabcorp has been penalized AU$350,000 (US$245,413) by the Victorian Gambling and Casino Control Commission (VGCCC) due to its failure to enforce multi-factor authentication (MFA) in its wagering system for almost five months in 2025, exposing customer accounts to unauthorized access.
The VGCCC's ruling determined that Tabcorp violated several provisions of the Wagering and Betting Technical Standards Act, citing sections 8.3.1, 8.3.2, 10.3.2, and 10.4.3. Under MFA requirements, users must provide two verification forms, such as a password and a one-time code, before they can access their accounts. The commission judged that Tabcorp's proposed alternative security measures did not conform to regulatory standards.
The absence of MFA led to significant security breaches. Tabcorp reported a major incident on January 20, 2025, where unauthorized access occurred across at least 195 customer accounts, resulting in illicit withdrawals amounting to around $308,099. Alarmingly, 14 of these accounts were compromised during the timeframe when MFA was not in effect as required.
Additionally, a bot attack on dormant accounts lacking MFA protections occurred in May 2025, which allowed approximately $13,471 to be withdrawn from player accounts in Victoria, contributing to total losses nationwide nearing $31,000. Affected customers were reimbursed by both Tabcorp and their respective banks.
In its deliberation, the VGCCC rejected Tabcorp's assertion that MFA was not a regulatory requirement or that their alternative controls were satisfactory, emphasizing that standard 8.3.1 mandates the use of MFA. The commission concluded that the provisions requiring "appropriate security controls" inherently included MFA as the fundamental safeguard.
The penalty of $350,000 took into account various factors, including the severity and nature of the violations, along with the real and possible damage inflicted on customers. The length of time without compliance (almost five months) and the company’s eventual cooperation were also considered. While the breaches were assessed as “towards the lower end of objective seriousness,” the prolonged non-compliance and customer losses were viewed as aggravating factors.
The fine amounts to approximately 3.5% of the maximum penalty outlined in the Gambling Regulation Act.
Tabcorp defended itself by indicating that MFA access was provided to customers from March 2025 and that its detection systems were operational for a longer duration. The company claimed the violations were brief and attributed to technical constraints. The VGCCC recognized Tabcorp's cooperation and compensations but noted that the company did not fully acknowledge responsibility for the incidents.
This recent penalty follows a previous fine of over $2.7 million imposed in July for breaching telemarketing and spam regulations over a 16-month span. In addition, Tabcorp recently acquired BetMakers for approximately $267 million.
