Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Regulatory

Victoria Fines Tabcorp A$350,000 for Running Customer Accounts Without Multi-Factor Authentication

Antonina TupikovaBy Antonina Tupikova · Founder, iGaming Times2 min read
Australian Regulator Sanctions Tabcorp A$4M for Spamming VIPs, Breaching Marketing Laws

The Victorian Gambling and Casino Control Commission says Tabcorp ran its betting accounts for almost five months without the multi-factor authentication its licence required, while attackers drained customer accounts. The regulator also rejected Tabcorp's argument that the rules never required MFA at all.

  • The Victorian Gambling and Casino Control Commission (VGCCC) has fined Tabcorp Vic A$350,000, approximately US$247,000, for failing to implement multi-factor authentication (MFA) on customer accounts between 30 January and 23 June 2025
  • A malicious actor accessed at least 195 Tabcorp accounts and withdrew A$308,098.91 in January 2025, and a bot attack in May 2025 took about A$13,471 from Victorian accounts that had no MFA, according to the decision; Tabcorp reimbursed customers
  • Tabcorp argued that the technical standards did not require MFA and that its other controls complied, which the Commission called "an unduly narrow and technical interpretation" of its obligations
  • The regulator had refused a further dispensation in February 2025, after granting several since the licence began in August 2024, and Tabcorp did not force every customer onto MFA until 24 June 2025
  • The fine is about 3.5% of the A$9,879,500 maximum, raised because of what the Commission called Tabcorp's "significant history of non-compliance", including a A$4.6 million fine in 2024

A Licence Condition Tabcorp Said It Could Not Meet on Day One

Tabcorp Vic Pty Ltd has held Victoria's wagering and betting licence since 16 August 2024, for a 20-year term. The licence requires its wagering system to operate in line with the state's Wagering and Betting Technical Standards, four of which deal with account security: standard 8.3.1 requires MFA on any attempt to access a player account, 8.3.2 requires controls that detect potential unauthorised access such as repeated MFA failures, and 10.3.2 and 10.4.3 require secure authentication before any telephone or online bet is placed, according to the VGCCC's decision of 21 September.

On 15 July 2024, a month before the licence began, Tabcorp told the Commission it could not deliver a compliant MFA solution in time, citing technical challenges. The regulator granted a series of dispensations between 16 August 2024 and 29 January 2025. In January 2025 Tabcorp reported significant problems in beta testing, and on 29 January it asked for more time to 7 March, acknowledging that its planned solution would still leave some customers able to use older versions of the TAB app without MFA. On 6 February 2025 the Commission refused, kept Tabcorp's system unapproved until MFA was fully in place, and imposed weekly reporting. Tabcorp confirmed that on 24 June 2025 it had required all customers to upgrade to an app version with full MFA. The Commission found it non-compliant from 30 January to 23 June 2025.

The Harm the Rules Were Written to Prevent

The decision records two incidents. On 20 January 2025, during the dispensation period, Tabcorp reported that a malicious actor had accessed at least 195 customer accounts and withdrawn A$308,098.91; 14 of those customers were affected after the dispensations ended. On 28 May 2025 it reported a bot attack using credentials it said were probably sourced from the dark web, against dormant accounts without MFA. About A$13,471 was taken from Victorian accounts, part of roughly A$31,000 nationally. Tabcorp said 99% of customers had adopted MFA by 1 April 2025, but the remaining 1% were not required to adopt it until June. Affected customers were reimbursed, by Tabcorp or by their banks.

iGaming glossary: 430+ terms explained.

In its response to the Commission's show-cause notice in May 2026, Tabcorp argued that the standards were technology-neutral and did not prescribe MFA, that it had alternative controls in place, and that any non-compliance ended on 2 March 2025, when MFA became available. The Commission rejected all three arguments, noting that they were "inconsistent with Tabcorp's multiple requests for dispensation" on the same standards, and said it was "not confident that Tabcorp appreciates the substance and purpose of the MFA requirements". The fine is payable within 28 days.

The Regulator Fined the Argument as Much as the Breach

The Commission rated the contraventions "towards the lower end of objective seriousness", credited Tabcorp's technical difficulties, its reporting and its reimbursements, and found no deliberate disregard of its obligations. On those facts alone, A$350,000 might have been lower. What pushed it up is visible in the reasons: a company that spent six months asking for dispensations from a rule then argued, once enforcement began, that the rule had never applied to it. The Commission said it expects Tabcorp "to accept accountability for non-compliance" and "demonstrate it is genuinely contrite". For every wagering licensee in Victoria, the lesson is that a technology-neutral standard is not an invitation to choose a weaker technology, and that a legal position contradicting your own earlier correspondence will be held against you.

A Small Fine Against a Long Record

Tabcorp Holdings reported group revenue of about A$2.6 billion in FY25, according to figures the Commission cited, and the fine is a rounding error against that. The Commission leaned instead on history: a A$4.6 million fine in August 2024 for responsible gambling code breaches, A$1 million in 2023 for failing to follow its directions, and five letters of censure since late 2023. Tabcorp is also in the middle of a technology overhaul, having agreed to buy BetMakers last month to replace legacy systems. Account security is precisely the kind of capability that a platform migration can put at risk again, and the regulator has now told it in writing how it will read any repeat.

Trade coverage of the decision reported the fine as "$249K", a US dollar conversion; the penalty is A$350,000. It is a modest sum for a lesson that should travel well beyond Tabcorp: in Australia's wagering market, where the Australian Communications and Media Authority has spent the month penalising self-exclusion failures, account security is now being enforced as consumer protection, not treated as IT housekeeping.

Sources

Citations and primary documents this article references. Captured at the time of writing.

Comments

Be the first to comment.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.