Tabcorp has been fined AU$350,000 (US$245,413) by the Victorian Gambling and Casino Control Commission (VGCCC) due to a significant security lapse. The fine comes after the company failed to implement mandatory multi-factor authentication (MFA) for its wagering and betting system, leaving customer accounts exposed to unauthorized access for nearly five months in 2025.
The VGCCC's ruling identified breaches of several provisions of the Wagering and Betting Technical Standards Act, specifically sections 8.3.1, 8.3.2, 10.3.2, and 10.4.3. MFA is designed to require users to provide two forms of verification, such as a password and a one-time code, before accessing their accounts. The Commission concluded that alternative security measures proposed by Tabcorp did not fulfill the regulatory requirements.
On January 20, 2025, Tabcorp reported a major security breach that led to unauthorized access to at least 195 customer accounts, resulting in illicit withdrawals amounting to approximately $308,099. Notably, fourteen of these accounts were compromised during the period when the required MFA was not in place.
Additionally, in May 2025, the company faced a bot attack that targeted dormant accounts lacking MFA protections, which culminated in around $13,471 being withdrawn from player accounts in Victoria and total losses reaching about $31,000 nationwide. Both Tabcorp and customer banks took action to reimburse those affected.
The VGCCC rejected Tabcorp's defense, which argued that MFA was not obligatory and that other controls were adequate. The Commission's reasoning centered on standard 8.3.1, which clearly mandates the use of MFA. It interpreted other relevant provisions, which call for "appropriate security controls," as requiring MFA as a foundational security measure.
The Commission assessed the fine based on the severity of the breaches, the actual and potential harm to customers, the duration of non-compliance, which lasted nearly five months, and Tabcorp's cooperation throughout the process. Although the breaches were viewed as minor in terms of their seriousness, the length of non-compliance and customer losses were considered significant aggravating factors. The fine amounts to about 3.5% of the maximum possible penalty under the Gambling Regulation Act.
In defense, Tabcorp stated that MFA was available to customers starting March 2025, and while detection systems had been in place longer, they attributed the violations to temporary technical issues. The VGCCC acknowledged Tabcorp's efforts to cooperate and reimburse customers; however, it noted that the company did not fully accept responsibility for the incidents.
This penalty follows a previous fine totaling over $2.7 million for violations of telemarketing and spam regulations that took place over a 16-month timeframe. Recently, the operator also acquired BetMakers for approximately $267 million.
