iGAMINGHOUSE
Breaking
Licensing

Tabcorp fined A$350,000 for multi-factor authentication failures in Victoria

The Victorian Gambling and Casino Control Commission imposed a fine of A$350,000 on Tabcorp for failing to meet mandatory multi-factor authentication requirements between January and June 2025.

By Miguel SandovalPublished Sep 24, 20263 min readAsia Pacific
Regulator’s document and login screen with security alerts representing the fine against Tabcorp in Australia

Key Takeaways

  • Tabcorp received a fine of A$350,000 for not implementing MFA between January and June 2025.
  • At least 195 customer accounts suffered unauthorized access and losses exceeding A$308,000 during that period.
  • Tabcorp achieved a 99% adoption rate of MFA after the original deadline, but outside the required period.
  • The sanction follows previous fines from the VGCCC for violations in Victoria in 2023 and 2024.

The Victorian Gambling and Casino Control Commission (VGCCC) imposed a fine of A$350,000 on Tabcorp Holdings Limited for failing to implement mandatory multi-factor authentication (MFA) controls on its customers' accounts during the period from January to June 2025. The regulator determined that the absence of MFA left the betting and sports wagering system of the operator in the state of Victoria vulnerable.

Details of the fine against Tabcorp for MFA failures

The sanctioning procedure is based on the finding that Tabcorp failed to comply with four technical standards regarding MFA required by the VGCCC. In July 2024, Tabcorp communicated to the regulator that it would not be able to meet the requirements before the start of its new license, dated August 14 of that year. As a result, the VGCCC granted an extension until January 29, 2025, for full implementation.

On January 24, 2025, Tabcorp notified the VGCCC that it had "identified significant issues" during beta testing related to MFA and requested an additional extension, which was denied by the authority. The operator reported on June 24 of the same year that it had finally implemented the required authentication controls, leading the VGCCC to consider that there was a breach during a six-month period.

Operational impact and customer security

During the period without mandatory MFA, Tabcorp reported unauthorized access to at least 195 customer accounts, with losses recorded totaling A$308,098.91 according to Tabcorp's communication to the regulator on January 20, 2025. Between January and June 2025, fourteen customers were affected by such incidents.

In May 2025, the company also notified the regulatory authority about an automated attack via bots, in which hackers attempted to access inactive accounts—without active MFA—using credentials likely from the dark web. From this security breach, an additional theft of approximately A$13,471 occurred.

Tabcorp stated that all impacted customers in both incidents were compensated either by the company or their respective banks.

Late compliance and MFA evolution

According to information provided to the VGCCC, Tabcorp maintained constant communication with the Commission regarding the progress of MFA adoption, requesting specific exemptions for concrete deadlines and reporting a 99% adoption of MFA among customers as of April 1, 2025.

The chair of the VGCCC, Chris O’Neill, stated:

“We expect robust systems to prevent breaches and protect customers. When they occur, licensees must identify and resolve them quickly, as well as address the root cause.”
“Customer protection requirements are essential to safeguard users in Victoria and maintain trust in regulated betting products and services. This sanction reinforces that all providers must fully implement and maintain these measures.”

Sanction history and regulatory demands in Victoria

This fine of A$350,000 imposed on Tabcorp adds to recent precedents: in September 2023, the VGCCC fined Tabcorp A$1 million for previous violations, and in 2024, a larger penalty of A$4.6 million was imposed due to “repeated breaches” of the responsible gaming code of conduct in the Australian state. This history reflects the VGCCC's strict stance on the technical obligations and customer protection that licensed operators must observe in Victoria.

The Tabcorp case highlights the growing importance of advanced authentication controls in gaming and betting platforms, as well as the active oversight of regulatory authorities to ensure user protection and the integrity of the sector. More information on regulatory processes and sanctions is available in the regulation section.

Frequently Asked Questions

Why did the VGCCC fine Tabcorp in 2025?

The VGCCC fined Tabcorp A$350,000 for failing to implement mandatory multi-factor authentication controls on customer accounts between January and June 2025, violating four technical standards.

How many customers were affected by Tabcorp's security failures?

During the period without active MFA, at least 195 customer accounts suffered unauthorized access, resulting in thefts exceeding A$308,000, as reported by Tabcorp to the regulator.

How did Tabcorp respond to the incidents of compromised accounts?

Tabcorp reported that all affected customers were reimbursed either by the company or by their respective banks after the cyberattacks and theft of funds.

Did Tabcorp eventually comply with the MFA requirement?

Tabcorp reported a 99% adoption of MFA among customers by April 1, 2025, although this occurred after the mandated deadline and was considered a violation by the VGCCC.

Has Tabcorp been fined by the VGCCC previously?

Tabcorp had previously received other penalties from the VGCCC, including a fine of A$4.6 million in 2024 and another of A$1 million in 2023 for violations related to responsible gaming in Victoria.

Source: EGR Awards

Tags

finestabcorpmulti-factor-authenticationvictoriaregulationvgccc

About the author

Miguel Sandoval

Miguel Sandoval

Regulatory Affairs Correspondent

Miguel Sandoval tracks gambling legislation, licensing, and regulator enforcement — from Spain's DGOJ and the Latin American authorities to the UKGC, the MGA, and the state-by-state map in North America. The reports answer three questions precisely — what changed, where, and who it affects — with jurisdictions, dates, and penalties cited exactly as published. Operators and compliance officers read Miguel Sandoval to know which rulebook moved before their next meeting.

More from Miguel Sandoval

Related Articles

Gamble Responsibly

NCPGMalta Gaming AuthorityGambleAwareGLIGamCareeCOGRA18+

iGamingHouse is intended for users who are 18 years or older (or the legal age in your jurisdiction). Ensure online gambling is legal in your region before participating. Seek help from professional resources if you feel you have a gambling problem. Terms and conditions apply. All rights reserved © 2026.