Victorian Gambling Commission fined Tabcorp AU$350,000 for customer account security failures that exposed 195 betting accounts to unauthorized access and withdrawals totaling AU$308,098.
Tabcorp customer account security fine totals AU$350,000 ($295,000) for multi-factor authentication failures. Breaches occurred between January 30th and June 23rd 2025, exposing dormant accounts to bot attack withdrawals totaling AU$31,000.
- AU$350K Penalty Breakdown
- Multi-Factor Authentication Gap
- VGCCC Enforcement Actions
- Tabcorp Compliance History
Tabcorp faces AU$350,000 ($295,000) penalty from Victorian Gambling and Casino Control Commission over customer account security failures. The regulator found Tabcorp VIC Pty Ltd breached four technical standards between January 30th and June 23rd 2025. These breaches involved multi-factor authentication (MFA) implementation gaps. The feature launched in March 2025, but some customers continued using fine older app versions without mandatory security.
AU$350K Penalty Breakdown
The VGCCC imposed the penalty on September 21st following its investigation. The decision detailed unauthorized access to at least 195 customer accounts. About AU$31,000 ($22,000) was withdrawn nationwide from dormant accounts. Victorian accounts lost AU$13,471 ($9,567) specifically. The remaining AU$308,098.91 ($219,000) came from 14 customers during the fine period.
Of the 195 affected accounts, 14 customers experienced breaches during the regulatory dispensation period. The others were affected while regulatory dispensations remained in place. Affected customers received reimbursement from their financial institutions or Tabcorp. The regulator rejected Tabcorp’s arguments about alternative security controls meeting standards.
The commission described Tabcorp’s arguments as an ‘unduly narrow and technical interpretation’ of obligations. It found MFA was required for compliance. The penalty places breaches toward the lower end of seriousness. The regulator acknowledged technical difficulties and customer reimbursements. Tabcorp’s history of non-compliance warranted a larger penalty than would otherwise have been appropriate.
Multi-Factor Authentication Gap
Tabcorp made multi-factor authentication available in March 2025. The feature requires more than one form of identity verification to access customer accounts. Although 99 percent of customers adopted MFA by April 1st 2025, it was not mandatory for all customers until June 24th. Tabcorp required users to upgrade the TAB app on that date. The remaining gap exposed some dormant accounts to a bot attack reported in May 2025.
The attacker used login credentials likely obtained from the dark web. Tabcorp disclosed the breach following regulatory investigation. The four technical standards violations centered on MFA implementation timing. The regulator granted Tabcorp several extensions to implement MFA. The final dispensation ended on January 29th 2025. Tabcorp requested further extensions in February, but the commission rejected this request.
Australian gambling operators face strict technical standards for customer security. The VGCCC enforces these standards rigorously. AGBrief tracks how regulatory bodies handle security compliance across Asian markets. Tabcorp’s case demonstrates Australia’s strict enforcement approach to customer account protection. The penalty signals that security gaps attract meaningful consequences.
VGCCC Enforcement Actions
The Victorian Gambling and Casino Control Commission imposed the penalty on September 21st. The decision rejected Tabcorp’s technical challenges arguments. The commission found that MFA was required for compliance. Tabcorp’s history of non-compliance warranted a larger penalty. This included a fine of AU$4.6 million ($3.27 million) against the group’s former Victorian licensee in 2024 for responsible gambling failures.
The regulator placed the breaches toward the lower end of seriousness. It found no deliberate disregard of regulatory obligations. However, Tabcorp’s compliance history influenced the penalty amount. The VGCCC acknowledged technical difficulties and customer reimbursements. The commission devoted resources to implementation during its investigation.
Australia’s gambling regulatory framework emphasizes technical compliance. The VGCCC enforces standards consistently across licensed operators. This enforcement approach protects customers from unauthorized access. The penalty demonstrates that security gaps attract regulatory scrutiny. Australian wagering providers must maintain robust account protection measures.
Tabcorp Compliance History
Tabcorp’s compliance history includes a fine of AU$4.6 million ($3.27 million) in 2024. This penalty targeted the group’s former Victorian licensee for responsible gambling failures. The current AU$350,000 fine reflects this broader compliance pattern. The VGCCC considers historical violations when setting penalty amounts. Tabcorp’s repeated non-compliance warranted a larger penalty than would otherwise have been appropriate.
The regulator acknowledged technical difficulties during implementation. Customer reimbursements reduced the financial impact on affected individuals. Resources devoted to implementation influenced the penalty calculation. However, the commission rejected Tabcorp’s arguments about alternative security controls. The decision emphasizes MFA as a non-negotiable compliance requirement.
Australian gambling operators face increasing regulatory scrutiny. The VGCCC enforces technical standards rigorously. This enforcement approach protects customers from security breaches. Tabcorp’s case signals that security gaps attract meaningful penalties. Australian wagering providers must maintain robust account protection measures to avoid similar consequences.
Frequently Asked Questions
How much did the VGCCC fine Tabcorp for customer account security failures?
The Victorian Gambling and Casino Control Commission fined Tabcorp AU$350,000 ($295,000) for breaching four technical standards. The penalty covers multi-factor authentication failures between January 30th and June 23rd 2025.
How many customer accounts were exposed to unauthorized access?
The VGCCC found unauthorized access to at least 195 customer accounts. About AU$31,000 was withdrawn nationwide from dormant accounts. Victorian accounts specifically lost AU$13,471 during the breach period.
Why did the VGCCC reject Tabcorp’s compliance arguments?
The commission described Tabcorp’s arguments as an ‘unduly narrow and technical interpretation’ of obligations. It found MFA was required for compliance regardless of alternative security controls. The regulator rejected technical challenges to the multi-factor authentication mandate.
What previous penalties has Tabcorp received from Australian regulators?
Tabcorp’s former Victorian licensee received a fine of AU$4.6 million ($3.27 million) in 2024 for responsible gambling failures. The current AU$350,000 penalty reflects this broader compliance history and non-compliance pattern.
Were affected customers reimbursed for unauthorized withdrawals?
Affected customers received reimbursement from their financial institutions or Tabcorp. The VGCCC acknowledged customer reimbursements when setting the penalty. This mitigation reduced the financial impact on affected individuals despite the regulatory breach.
This article has been thoroughly researched and reviewed by the CasinoBait editorial team to ensure accuracy and relevance for Asian casino players.


