Tabcorp Fined AU$350,000 Over Customer Account Security Failures
Tabcorp VIC Pty Ltd has been fined AU$350,000 by the Victorian Gambling and Casino Control Commission (VGCCC) for failing to implement mandatory multi-factor authentication controls on customer wagering accounts within the required timeframe. The disciplinary action relates to breaches of four security requirements between January 30 and June 23, 2025.

The fine was imposed following a decision dated September 21, 2026. The VGCCC found that Tabcorp had contravened technical standards governing customer account access and authentication under its wagering and betting regulatory arrangements. The standards required the use of multi-factor authentication (MFA), measures capable of detecting potential unauthorised access attempts, and appropriate security controls before customers could place wagers or conduct betting transactions through telephone or online channels.
Tabcorp had been given several periods of regulatory dispensation to allow additional time to implement MFA. The company had informed the Commission in July 2024 that it could not implement a compliant MFA solution before the commencement of its current wagering licence. The Commission subsequently granted multiple dispensations between August 2024 and January 29, 2025.
On January 29, 2025, Tabcorp advised the Commission that implementation would be delayed because of technical defects and requested another extension. The company also acknowledged that the MFA implementation it was developing at that stage would not provide full compliance because some customers could continue accessing older versions of the TAB application without MFA. The Commission refused the further request on February 6, 2025, determined that the wagering system would remain unapproved until MFA was fully implemented and imposed weekly reporting requirements.
Tabcorp subsequently made MFA available to customers in March 2025. However, the Commission found that making the functionality available was not sufficient because customers were not required to upgrade to a version of the TAB application incorporating full MFA protection. Full implementation occurred on June 24, 2025, when Tabcorp required customers to upgrade the application. The period from January 30 through June 23 therefore constituted the relevant period of non-compliance considered in the disciplinary proceedings.
During that period, the security risks addressed by the MFA requirements materialised. Tabcorp reported to the Commission on January 20, 2025 that a malicious actor had accessed at least 195 customer accounts and withdrawn a total of AU$308,098.91. Tabcorp subsequently advised that 14 of those customers had been affected during the period covered by the disciplinary action, while the remaining accounts had been compromised during periods when regulatory dispensations were in effect.
A separate incident was reported in May 2025, when Tabcorp experienced what it described as a bot attack. The attacker attempted to access customer accounts using credentials that Tabcorp believed had likely been obtained from the dark web. The affected accounts were dormant accounts that did not have MFA activated. Approximately AU$31,000 was withdrawn from Tabcorp accounts nationally, including approximately AU$13,471 from Victorian customer accounts.
Tabcorp reimbursed affected customers, with some customers also receiving reimbursement from their financial institutions. The Commission took the reimbursements into account when determining the appropriate disciplinary response.
Tabcorp disputed the Commission's interpretation of the technical standards. In its response to a notice to show cause issued in April 2026, the company argued that the standards did not prescribe a particular technology or authentication method and that it had other security controls in place. It also submitted that MFA had been made available to customers from March 2025 and that any non-compliance should therefore have ended at that point. Tabcorp attributed delays in implementation to technical challenges.
The VGCCC rejected those arguments. It determined that the relevant technical standards expressly required MFA and that the other provisions concerning appropriate security controls had to be read in conjunction with the MFA requirement. The Commission concluded that alternative controls did not remove the obligation to implement MFA.
The Commission also found that the failure to implement MFA continued for almost five months after the final dispensation had expired and after Tabcorp had been informed that no further dispensation would be granted. At the same time, it recognised that implementing MFA involved technical complexity, that approximately 99% of Tabcorp customers had adopted MFA by April 1, 2025, and that the company had devoted resources to implementing the system.
In assessing the seriousness of the breaches, the Commission said the relevant requirements were intended to protect customer accounts, funds and personal information. The security risks associated with the non-compliance resulted in actual unauthorised access and financial losses affecting customers. Nevertheless, the VGCCC classified the breaches as being towards the lower end of objective seriousness and found no evidence of deliberate disregard of regulatory obligations.
The Commission considered Tabcorp's previous regulatory history when determining the penalty. The company's former Victorian wagering licensee was fined AU$4.6 million in August 2024 for repeated breaches of the Responsible Gambling Code of Conduct and wagering licence requirements. In September 2023, the same former licensee was fined AU$1 million for failing to comply with two regulatory directions. The Commission also issued several letters of censure to the former licensee in 2023 and 2024 for other regulatory breaches.
Although the current wagering licence is held by Tabcorp VIC Pty Ltd, rather than the former Tabcorp Wagering (Vic) Pty Ltd, the VGCCC treated the current licensee as the continuation of the same regulated wagering business operated by the Tabcorp group. The Commission cited the continuity of systems, processes, operations and staff following the transfer of the licence in August 2024.
The statutory maximum fine available for the relevant disciplinary action was AU$9,879,500. The Commission imposed a single aggregate fine of AU$350,000 for the four technical-standard breaches, representing approximately 3.5% of the statutory maximum. It said the maximum penalty was generally reserved for the most serious and egregious breaches and considered that the circumstances in this case did not fall into that category.
The Commission also considered the size and financial capacity of the wider Tabcorp group. Tabcorp Holdings reported approximately AU$2.6 billion in revenue and AU$391.5 million in EBITDA for financial year 2025, together with net profit before significant items of approximately AU$49.5 million. The Commission said these figures indicated that the group had sufficient resources to absorb a financial penalty and that the fine therefore needed to be meaningful for regulatory deterrence.
The AU$350,000 penalty is payable within 28 days of the date of the Commission's reasons for decision. The VGCCC has stated that its enforcement framework can include disciplinary fines, licence variations, suspension or cancellation, depending on the nature and circumstances of regulatory non-compliance.
The Tabcorp decision places customer authentication and account security within the broader technical compliance obligations applicable to licensed wagering operators in Victoria. In this case, the regulator's findings concerned the failure to implement the specified MFA controls within the required period, rather than a finding that Tabcorp deliberately facilitated the unauthorised access. The Commission expressly recognised the technical challenges involved and the absence of deliberate disregard while nevertheless determining that the regulatory requirements had not been met.
By fLEXI tEAM





Comments