Home Gambling RegulationsTabcorp Receives $350,000 Fine from Victoria Regulator for Security Failures

Tabcorp Receives $350,000 Fine from Victoria Regulator for Security Failures

by Sienna Marques
0 views 2 minutes read
Tabcorp Receives $350,000 Fine from Victoria Regulator for Security Failures

Tabcorp has been fined AU$350,000 (US$245,413) by the Victorian Gambling and Casino Control Commission (VGCCC) due to a failure to implement mandatory multi-factor authentication (MFA) in its wagering and betting system for nearly five months in 2025, exposing customer accounts to unauthorized access.

The VGCCC's decision outlined multiple violations of the Wagering and Betting Technical Standards Act, specifically sections 8.3.1, 8.3.2, 10.3.2, and 10.4.3. Under MFA guidelines, users are required to provide two forms of verification, such as a password in combination with a one-time code, to access their accounts. The commission determined that the alternative security measures proposed by Tabcorp did not fulfill the necessary regulatory standards.

The need for greater security was underscored after Tabcorp notified the VGCCC of a significant breach on January 20, 2025, where unauthorized access occurred to at least 195 customer accounts, resulting in illicit withdrawals amounting to approximately $308,099. Notably, 14 of these accounts were accessed during the time when MFA was not in place as required.

Additionally, in May 2025, Tabcorp reported a bot attack that specifically targeted dormant accounts lacking MFA protections, leading to approximately $13,471 withdrawn from customer accounts within the state and nearly $31,000 in total losses nationally. Both Tabcorp and the banks involved reimbursed the affected customers.

In its rationale, the VGCCC rejected Tabcorp's assertions that MFA was optional or that the existing controls were sufficient. The commission emphasized that standard 8.3.1 explicitly mandates the use of MFA, interpreting related provisions requiring adequate security controls as inclusive of MFA as a baseline requirement.

The AU$350,000 fine considered several factors, such as the nature and seriousness of the breaches, actual and potential harm to customers, the length of non-compliance nearing five months, and Tabcorp's eventual cooperation.

Although the VGCCC classified the breaches as “towards the lower end of objective seriousness,” it viewed the extended period of non-compliance and the resulting customer losses as significant aggravating factors. The penalty represented about 3.5% of the maximum fine allowable under the Gambling Regulation Act.

Tabcorp contended that MFA had been available to customers since March 2025 and that existing detection systems had been in place for a longer time. The company cited brief contraventions due to technical limitations. The VGCCC noted Tabcorp's cooperation and reimbursements but concluded that the company did not fully acknowledge its responsibility for the security lapses.

In July, Tabcorp was also penalized over $2.7 million for violations regarding telemarketing and spam regulations over a 16-month duration. Just last month, the operator purchased BetMakers for approximately $267 million.

You may also like