iGAMINGHOUSE
Breaking
Licensing

Tabcorp Fined A$350,000 by VGCCC for Multi-Factor Authentication Failures

The Victorian Gambling and Casino Control Commission penalised Tabcorp A$350,000 after finding the operator failed to implement mandatory multi-factor authentication controls, exposing customer accounts to security breaches through the first half of 2025.

By Eleanor WhitfieldPublished Sep 24, 20264 min readAsia Pacific
VGCCC penalty notice and a digital security alert on a background of Australian currency

Key Takeaways

  • Tabcorp was fined A$350,000 by the VGCCC for failing to implement mandatory multi-factor authentication controls between January and June 2025.
  • The VGCCC found Tabcorp in breach of four technical standards related to MFA, leaving customer accounts exposed to security threats.
  • Security incidents during the non-compliance period included unauthorised access to 195 accounts and A$308,098.91 in stolen funds.
  • Tabcorp's delayed MFA rollout followed an earlier A$4.6 million penalty for responsible gambling code breaches.
  • The VGCCC maintains that operators must fully implement and maintain customer-protection requirements.

Tabcorp received a fine of A$350,000 from the Victorian Gambling and Casino Control Commission after the company failed to meet multi-factor authentication (MFA) requirements for customer accounts between January and June 2025. The VGCCC found that, despite a regulatory extension and a stated commitment to implementation, Tabcorp did not introduce MFA protections on time, resulting in direct customer impact and non-compliance with four technical standards.

VGCCC's Ruling and Enforcement Action

The VGCCC issued the A$350,000 penalty after determining that Tabcorp had not provided the mandatory MFA controls required under its licence. The regulator judged that this omission made Tabcorp's wagering and betting platform vulnerable. Tabcorp's breach of MFA rules occurred over a six-month period, from 14 August 2024—when its new licence commenced—through to 24 June 2025, the date on which the company reported full compliance. VGCCC Chair Chris O’Neill stated:

“We expect strong systems to prevent breaches and protect customers. If breaches occur, it is our expectation that licensees identify and resolve them quickly and address their underlying cause.”

The Commission emphasised that customer-protection requirements are essential to safeguard customers and uphold confidence in regulated products. This enforcement action follows earlier penalties: a A$4.6 million fine in 2024 for repeated responsible gambling code breaches, and a A$1 million penalty in September 2023.

Timeline of Multi-Factor Authentication Failings

Tabcorp first advised the VGCCC in July 2024 that it would not be able to comply with the new MFA technical standards by the 14 August 2024 licence start date. The regulator granted an extension until 29 January 2025. On 24 January 2025, just before the new deadline, the operator notified the regulator that significant issues had been discovered in beta testing. When Tabcorp requested another extension, the VGCCC declined.

On 24 June 2025, Tabcorp informed the Commission that it had implemented the required MFA measures, thereby closing a compliance gap lasting approximately six months. According to Tabcorp, 99% customer adoption of MFA had been achieved by 1 April 2025. Despite the delay, the VGCCC found that the period between August 2024 and June 2025 constituted a direct contravention of licence rules.

Customer Impact and Security Breaches

Tabcorp's delayed implementation had direct consequences for customers. On 20 January 2025, Tabcorp disclosed to the VGCCC that a "malicious actor" had accessed at least 195 customer accounts and withdrawn a total of A$308,098.91. Fourteen of those cases occurred during the non-compliance window. Tabcorp also reported a bot attack in May 2025, where hackers attempted to exploit dormant accounts—lacking active MFA—using credentials believed to have been obtained from the dark web. This incident led to a further A$13,471 being stolen.

Affected customers in both cases were either reimbursed by Tabcorp or by their respective banks. The sequence of security incidents underscored the operational risks posed by delayed adoption of MFA, a standard recognised in the payments and casino sectors as a baseline customer protection mechanism.

VGCCC Standards for Multi-Factor Authentication Compliance

The compliance standards imposed by the Victorian Gambling and Casino Control Commission require strict adherence to technical safeguards against unauthorised access. The VGCCC stated that Tabcorp failed to meet four specific technical standards related to MFA, leaving its betting and wagering system exposed. The Commission reiterated that licence holders must both fully implement safeguards on schedule and maintain them on an ongoing basis.

Chris O’Neill commented further:

“This penalty reinforces to all gambling providers that they must fully implement and maintain those protections.”

Regulatory Context and Ongoing Operator Obligations

Tabcorp’s most recent fine follows a pattern of enforcement from the VGCCC for compliance failures. The A$350,000 penalty is the latest in a series of significant fines: the A$4.6 million penalty in 2024 for responsible gambling code breaches remains the largest. The regulator’s actions are consistent with its stated policy of requiring rapid remediation of deficiencies and full accountability for customer protection lapses.

Tabcorp’s engagement with the VGCCC included ongoing communication about its implementation progress and requests for deadline dispensations—none of which absolved the company of regulatory liability.

Operators in Victoria are expected to keep pace with security standards and to act promptly on any identified risks. The VGCCC’s position is clear: failure to adhere to technical and customer-protection requirements will result in enforcement actions to protect both customers and the reputation of Victoria’s regulated gambling sector.

Frequently Asked Questions

Why did the VGCCC fine Tabcorp A$350,000?

The VGCCC fined Tabcorp A$350,000 for failing to implement mandatory multi-factor authentication controls on customer accounts between August 2024 and June 2025, breaching four technical standards.

How long did Tabcorp lack proper MFA controls?

Tabcorp lacked mandatory MFA controls for approximately six months, from the commencement of its new licence on 14 August 2024 until 24 June 2025, when MFA was finally implemented.

Were customers affected by Tabcorp's MFA failings?

Yes, at least 195 customer accounts were compromised, resulting in A$308,098.91 stolen, with additional funds lost to a bot attack on dormant accounts without active MFA; affected customers were reimbursed.

Did Tabcorp notify the VGCCC of MFA delays?

Tabcorp notified the VGCCC of implementation issues in July 2024 and January 2025, received one extension, and later reported compliance on 24 June 2025 after being denied a further extension.

How does this fine compare with Tabcorp's previous VGCCC penalties?

This A$350,000 penalty follows a A$4.6 million fine in 2024 for repeated responsible gambling code breaches and a A$1 million fine in September 2023, highlighting ongoing scrutiny from the VGCCC.

Source: EGR Awards

Tags

vgccctabcorpmulti-factor-authenticationcompliancefinessecurity

About the author

Eleanor Whitfield

Eleanor Whitfield

Regulatory Affairs Correspondent

Eleanor Whitfield tracks gambling legislation, licensing decisions, and regulator enforcement across key markets — from the UKGC, MGA, and Germany's GGL to Spain's DGOJ and the state-by-state map in the Americas. The reporting answers three questions precisely: what changed, where, and who it affects, with jurisdictions, effective dates, and penalty figures named exactly as published. Compliance officers and operators read Eleanor Whitfield to know which rulebook moved before their next board meeting.

More from Eleanor Whitfield

Related Articles

Gamble Responsibly

NCPGMalta Gaming AuthorityGambleAwareGLIGamCareeCOGRA18+

iGamingHouse is intended for users who are 18 years or older (or the legal age in your jurisdiction). Ensure online gambling is legal in your region before participating. Seek help from professional resources if you feel you have a gambling problem. Terms and conditions apply. All rights reserved © 2026.