Tabcorp Hit With AU$350,000 Fine Over Multi-Factor Authentication Failures

Sep 28, 2026 3 min read John K Updated Sep 28, 2026
Tabcorp Hit With AU$350,000 Fine Over Multi-Factor Authentication Failures

Tabcorp has been fined AU$350,000 by the Victorian Gambling and Casino Control Commission (VGCCC) after failing to fully introduce mandatory multi-factor authentication across its wagering platform for almost five months.

The regulator found Tabcorp VIC Pty Ltd breached four Wagering and Betting Technical Standards between 30 January and 23 June 2025. The requirements covered customer authentication, detection of attempted unauthorised access and security controls for online and telephone betting.

Under the standards, customers attempting to access wagering accounts were required to use multi-factor authentication, while Tabcorp’s systems also needed controls capable of detecting suspicious access attempts, including repeated authentication failures.

Tabcorp had previously received several temporary dispensations after telling the regulator in July 2024 that technical difficulties would prevent it from implementing a compliant MFA system before its new Victorian wagering licence took effect. Those dispensations ran from August 2024 until 29 January 2025.

The company requested another extension after identifying problems during testing, but the VGCCC rejected that request on 6 February 2025. The regulator also determined that Tabcorp’s wagering system would remain unapproved until MFA was fully implemented and required the company to provide weekly progress reports.

Unauthorised access resulted in customer losses

The security weaknesses coincided with incidents in which customer accounts were compromised.

Tabcorp reported in January 2025 that a malicious actor had gained access to at least 195 accounts and withdrawn AU$308,098.91. Fourteen affected customers were compromised during the period later identified by the VGCCC as non-compliant, while the remaining incidents occurred while regulatory dispensations were still in force.

A separate incident was reported on 28 May 2025, when automated login attempts targeted dormant accounts without MFA enabled. Tabcorp said the credentials used in the attack were probably obtained from the dark web.

Approximately AU$13,471 was withdrawn from Victorian accounts during that incident, forming part of roughly AU$31,000 taken from Tabcorp accounts nationwide. Affected customers were reimbursed either by Tabcorp or their financial institutions.

By 1 April 2025, about 99% of Tabcorp customers had adopted MFA. However, the company did not make it compulsory for every customer until 24 June, when users of older versions of the TAB app were required to upgrade to a version supporting the full authentication system.

Regulator rejects Tabcorp’s interpretation of the rules

Tabcorp argued during the disciplinary process that the technical standards did not require a specific security technology and said MFA had been available from March 2025. It also maintained that other detection and security measures were already operating.

The VGCCC rejected that interpretation. It found that Technical Standard 8.3.1 expressly required multi-factor authentication, while related provisions required controls capable of detecting MFA failures and regarded MFA as the minimum appropriate protection for account access.

The regulator concluded that Tabcorp breached standards 8.3.1, 8.3.2, 10.3.2 and 10.4.3, creating grounds for disciplinary action under Victoria’s Gambling Regulation Act.

In determining the AU$350,000 penalty, the commission considered the duration of the breaches, the risk and actual harm to customers, Tabcorp’s previous compliance record and the need for deterrence. It also took account of mitigating factors including the technical complexity of the implementation, Tabcorp’s cooperation, customer reimbursements and the resources committed to completing the project.

The VGCCC described the breaches as being toward the lower end of objective seriousness but said the almost five-month period of non-compliance and the resulting customer losses were aggravating factors.

The maximum available fine was AU$9.88 million, meaning the AU$350,000 sanction represented about 3.5% of the statutory ceiling. The decision was formally issued on 21 September 2026, with the regulator publicly announcing the penalty on 24 September.

The latest action adds to Tabcorp’s recent regulatory penalties. In August 2024, the VGCCC imposed a AU$4.6 million fine over responsible gambling breaches, while a separate AU$1 million penalty was issued in September 2023 for failing to comply with regulatory directions.