Tabcorp Fined $350,000 by Victorian Regulator for MFA Failures

Tabcorp Fined $350,000 by Victorian Regulator for MFA Failures

The Victorian Gambling and Casino Control Commission (VGCCC) has fined Tabcorp AU$350,000 (approximately US$245,413) over the company’s failure to implement mandatory security protections. The penalty, handed down on Thursday, follows a period of nearly five months in 2025 during which customer accounts on Tabcorp’s wagering and betting platform were left exposed to a heightened risk of unauthorised access.

Why Was the Fine Issued?

At the heart of the VGCCC’s decision is Tabcorp’s failure to deploy mandatory multi-factor authentication (MFA) across its systems during a period in which customer account security was paramount. The regulator determined that Tabcorp breached four separate provisions of the Wagering and Betting Technical Standards Act — specifically sections 8.3.1, 8.3.2, 10.3.2, and 10.4.3 — by operating without the required authentication safeguards in place.

What Is Multi-Factor Authentication?

MFA is a security mechanism that requires users to present two or more independent forms of verification before being granted account access. In practice, this typically means combining something the user knows — such as a password or PIN — with something the user physically possesses, like a one-time code sent to a mobile device or generated by an authenticator app.

The VGCCC’s technical standards mandate MFA as a baseline security control for wagering operators. The commission examined alternative controls that Tabcorp claimed to have put in place and firmly concluded that these alternatives were not sufficient to meet the regulatory standard.

Timeline of Security Breaches

January 2025: Unauthorised Access to 195 Accounts

Tabcorp notified the commission of a significant security breach on 20 January 2025, which involved unauthorised access to at least 195 customer accounts. The incident resulted in illicit withdrawals totalling approximately $308,099. Critically, 14 of these accounts were accessed specifically during the window in which MFA was not implemented as mandated — meaning the absence of MFA likely played a direct role in the losses.

May 2025: Bot Attack on Dormant Accounts

The situation escalated further in May 2025, when Tabcorp reported a bot attack targeting dormant accounts that lacked MFA protections. This automated attack resulted in approximately $13,471 being withdrawn from player accounts in Victoria, with total nationwide losses across all affected states nearing $31,000. In both incidents, Tabcorp and customer banks jointly reimbursed affected individuals for their financial losses.

How the Regulator Reached Its Decision

The VGCCC dismissed Tabcorp’s arguments that MFA was not obligatory and that the alternative security controls implemented by the company were adequate. The commission highlighted that standard 8.3.1 of the Wagering and Betting Technical Standards Act explicitly mandates the use of MFA, and interpreted related provisions requiring “appropriate security controls” as treating MFA as the baseline protection against account compromise.

In setting the penalty amount, the VGCCC weighed several factors: the nature and seriousness of the breaches, actual and potential harm to customers, the duration of non-compliance (nearly five months), and Tabcorp’s eventual co-operation during the investigation.

While the commission noted that the breaches fell “towards the lower end of objective seriousness”, it identified the extended period of non-compliance and the concrete customer losses as aggravating factors. The fine of $350,000 represents approximately 3.5% of the maximum penalty available under the Gambling Regulation Act — a figure that reflects both the severity of the contraventions and mitigating circumstances.

Tabcorp’s Response and Defence

Tabcorp defended its actions on multiple fronts, arguing that MFA was made available to customers from March 2025, that detection systems had been in place for a longer period, and that the contraventions were brief and attributable to technical limitations rather than deliberate neglect.

The VGCCC acknowledged Tabcorp’s cooperation throughout the investigation and the company’s efforts to reimburse affected customers. However, the commission found that Tabcorp did not fully accept responsibility for the breaches — a factor that weighed against the company in the final penalty determination.

Broader Regulatory Scrutiny

This fine is the latest in a series of regulatory actions against Tabcorp. In July, the operator was fined more than $2.7 million after being found in breach of Australian telemarketing and spam regulations over a 16-month period. The company has also been active on the corporate front, completing the acquisition of BetMakers for approximately $267 million just last month as it continues to expand its technology and wagering operations.

Key Takeaways for the Wagering Industry

The VGCCC’s decision serves as an important reminder that security compliance is a non-negotiable requirement for licensed operators. As cyber threats become increasingly sophisticated, regulators are closely monitoring whether companies are implementing baseline protections like MFA — and are prepared to impose significant fines when those protections are absent.

For Tabcorp, the incident also underscores the reputational damage that follows security failures. While the company has moved swiftly to reimburse customers and cooperate with regulators, the pattern of breaches — and the ongoing attention from regulators — highlights the challenges facing large wagering operators in maintaining robust security postures across complex legacy systems.