Thursday, September 24, 2026
HomeCasino NewsTabcorp Fined A$350K Over Account Security Failures

Tabcorp Fined A$350K Over Account Security Failures

Tabcorp VIC Pty Ltd has received a A$350,000 fine after failing to fully introduce mandatory multi-factor authentication controls for customer wagering accounts in Victoria.

The breaches occurred between January 30 and June 23, 2025, when some customers could continue accessing Tabcorp services without the required additional authentication step. During that period, unauthorised parties gained access to some wagering accounts and withdrew funds.

Tabcorp eventually completed the rollout of mandatory multi-factor authentication in June 2025 by requiring remaining customers to upgrade to a version of the TAB app that supported the security measure. Customers affected by unauthorised withdrawals later received reimbursements either from Tabcorp or their financial institutions.

Regulator Finds Four Technical Standards Breached

According to the Victorian Gambling and Casino Control Commission (VGCCC), Tabcorp breached four Wagering and Betting Technical Standards by failing to fully implement multi-factor authentication within the required timeframe.

Multi-factor authentication requires users to provide more than one form of verification before accessing an account. Tabcorp introduced the functionality in March 2025, although customers using older versions of its app could still log in without completing the additional authentication process.

By April 1, around 99% of customers had adopted MFA. Full enforcement did not take effect until June 24, when Tabcorp required remaining users to update their TAB app.

The incomplete rollout left some accounts exposed. A bot attack reported in May 2025 targeted dormant accounts using login credentials that Tabcorp said were likely obtained from the dark web.

Approximately A$31,000 was withdrawn from accounts across Australia during that incident, including A$13,471 from accounts belonging to Victorian customers.

The regulator’s decision also identified unauthorised access affecting at least 195 customer accounts, with withdrawals totaling A$308,098.91. Fourteen customers were affected during the period covered by the regulatory breaches, while other incidents occurred when Tabcorp was operating under approved dispensations.

“We expect strong systems to prevent breaches and protect customers. If breaches occur it is our expectation that licensees identify and resolve them quickly and address their underlying cause,” VGCCC Chairperson Chris O’Neill APM said.

Tabcorp Had Received Previous MFA Extensions

The regulator had previously allowed Tabcorp additional time to introduce the required security measures.

Several extensions were granted before the final dispensation expired on January 29, 2025. Tabcorp later sought another extension in February, but the regulator rejected that request.

In responding to the disciplinary action, Tabcorp argued that alternative security controls satisfied the relevant standards and maintained that any breach ended once MFA became available in March.

The company also pointed to technical difficulties associated with introducing the system.

The commission rejected Tabcorp’s interpretation, describing it as an “unduly narrow and technical interpretation” of its regulatory requirements. It concluded that compliance required mandatory implementation of MFA rather than simply making the feature available.

When determining the penalty, the regulator considered Tabcorp’s technical difficulties and the resources it committed to implementing MFA. It also took into account the reimbursement of affected customers.

The commission placed the breaches toward the lower end of the seriousness scale and found no deliberate disregard of Tabcorp’s regulatory obligations.

However, Tabcorp’s previous compliance record contributed to the size of the fine.

“Customer-protection requirements are necessary to safeguard Victorian customers and maintain confidence in regulated wagering products and services. This penalty reinforces to all gambling providers that they must fully implement and maintain those protections,” O’Neill said.

Previous Compliance Failures Add to Regulatory Record

The latest penalty follows earlier enforcement action against Tabcorp in Victoria.

In 2024, the regulator imposed a A$4.6 million fine over responsible gambling failures involving the group’s former Victorian licensee. Those breaches included shortcomings in staff training and failures involving support for a customer displaying signs of gambling harm.

The regulator also required Tabcorp to carry out a wider transformation program aimed at strengthening its compliance operations.

Tabcorp has faced regulatory action elsewhere in Australia as well. In July 2026, the company paid more than A$2.7 million in penalties after the Australian Communications and Media Authority identified spam and telemarketing rules breaches.

The latest Victorian case focuses specifically on account security and the requirement for wagering operators to maintain safeguards covering customer access.

Tabcorp has told the regulator that it completed the MFA rollout in June 2025. With the system now mandatory for affected TAB app users, the enforcement action addresses the period when the company had yet to apply the protection across its entire customer base.

RELATED ARTICLES

Most Popular

Recent Comments