Home > Legal & compliance > Tabcorp fined $350,000 by Victoria regulator

Tabcorp fined $350,000 by Victoria regulator

| By Kathryn Evans
The July penalty follows telemarketing violations and is the second time in three months the operator was fined, previously by the Australian Communications and Media Authority (ACMA).
Tabcorp fined over MFA failures

Tabcorp has been fined AU$350,000 (US$245,413) by the Victorian Gambling and Casino Control Commission (VGCCC). 

Thursday’s decision follows a failure to implement mandatory multi-factor authentication (MFA) across its wagering and betting system for nearly five months in 2025 which left customer accounts vulnerable to unauthorised access.

The VGCCC’s formal decision found Tabcorp in breach of multiple provisions of the Wagering and Betting Technical Standards Act – namely sections 8.3.1, 8.3.2, 10.3.2 and 10.4.3. 

MFA demands users present two forms of verification, such as a password plus a one-time code, before account access is granted. The VGCCC concluded that alternative controls suggested by Tabcorp were insufficient to meet these regulatory standards.

MFA failures led to security breaches

Tabcorp notified the commission about a significant security breach on 20 January 2025 that involved unauthorised access to at least 195 customer accounts. There were also illicit withdrawals totalling approximately $308,099. 

Fourteen of the accounts had been accessed during the period when MFA was not implemented as mandated.

Further, in May 2025, Tabcorp reported a bot attack targeting dormant accounts without MFA protections. This incident resulted in around $13,471 being withdrawn from player accounts in the state, with total nationwide losses nearing $31,000. 

Both Tabcorp and customer banks reimbursed the affected individuals.

Commission’s reasoning

The VGCCC dismissed Tabcorp’s claims that MFA was not mandatory or that alternative controls sufficed, highlighting that standard 8.3.1 explicitly requires MFA use. 

The commission interpreted related provisions mandating “appropriate security controls” as inclusive of MFA as the baseline protection.

The $350,000 fine reflected various considerations, including the nature and seriousness of the breaches as well as the actual and potential harm to customers.

It also considered the duration of non-compliance (nearly five months) and its eventual co-operation.

While deeming that the breaches were “towards the lower end of objective seriousness”, the commission regarded the extended non-compliance and customer losses as aggravating factors. 

The fine represented approximately 3.5% of the maximum penalty available under the Gambling Regulation Act.

Tabcorp’s position

Tabcorp defence was that MFA was made available to customers from March 2025, that detection systems existed for longer and that the contraventions were brief and due to technical limitations. 

The VGCCC acknowledged Tabcorp’s cooperation and reimbursements but found the company did not fully accept responsibility for the breaches.

The operator was also fined more than $2.7 million in July after the company was found to have violated telemarketing and spam regulations over a 16-month period. 

The operator acquired BetMakers for approximately $267 million just last month.

Subscribe to the iGaming newsletter