Published: 2026/09/24

Updated: 2026/09/24

Author: Nadia Winchester

Tabcorp Hit With A$350K Fine Over MFA Security Gaps

Victoria’s gambling regulator fined Tabcorp A$350,000 for failing to make multi-factor authentication mandatory on TAB accounts. That gap left some customer funds exposed to bot attacks in 2025.
Tabcorp MFA fine

Victoria’s gambling regulator has hit Tabcorp with a A$350,000 fine after the wagering giant failed to make MFA mandatory for all customer accounts within the required timeframe. For almost five months in 2025, some TAB customers could still log in with just a username and password. Fraudsters used that gap to access accounts and withdraw money. The Victorian Gambling and Casino Control Commission (VGCCC) found that Tabcorp VIC Pty Ltd breached four Wagering and Betting Technical Standards between January 30 and June 23, 2025.

What Led to the Tabcorp MFA Fine

Multi-factor authentication adds a second verification step, such as a code sent to a phone, before a customer can get into an account. The VGCCC required Tabcorp to introduce MFA on wagering accounts and granted the company several extensions to complete the work. The final dispensation expired on January 29, 2025, and the regulator refused Tabcorp’s request for more time a month later.

Tabcorp switched on MFA in March 2025, but customers running older versions of the TAB app could still skip the extra step entirely. Adoption climbed quickly, with around 99% of customers using MFA by April 1. However, the remaining users kept a back door open until June 24, 2025, when Tabcorp forced everyone left to update the app. Those missed months set up the fine that Tabcorp now faces over its MFA rollout.

Bots Went After Dormant Accounts

That back door did not stay unnoticed for long. In May 2025, a bot attack targeted dormant TAB accounts using login details that Tabcorp said likely came from the dark web. The attackers withdrew roughly A$31,000 from accounts across Australia, including A$13,471 from accounts belonging to Victorian customers.

The full picture is larger than that single incident. The regulator’s decision identified unauthorised access to at least 195 customer accounts, with withdrawals totalling A$308,098.91. Only 14 of those customers fell within the breach period itself, because the other incidents happened while Tabcorp still operated under approved dispensations.

Tabcorp or the customers’ own banks later reimbursed everyone who lost money through unauthorised withdrawals. Attacks like this rely on people reusing passwords across sites, which is exactly the risk a second verification step exists to block. The refunds softened the blow for customers, but they did not spare Tabcorp a fine over the MFA gap that made the withdrawals possible.

Tabcorp Argued the Protection Was Already There

In its response to the disciplinary action, Tabcorp argued that alternative security controls already satisfied the relevant standards. The company also maintained that any breach ended in March once MFA became available, and it pointed to the technical difficulties of rolling out the system. In effect, Tabcorp contested the basis for an MFA fine by arguing that offering the feature counted as compliance.

The VGCCC rejected that reading and described it as an “unduly narrow and technical interpretation” of the company’s obligations. In the commission’s view, compliance required mandatory MFA for every customer, and a feature that older app versions could bypass fell short of that standard. That distinction sits at the heart of the fine against Tabcorp, since the commission judged MFA by its enforcement, not its launch date.

How the Regulator Set the Penalty

The commission weighed several factors before settling on the size of Tabcorp’s fine for the MFA failures. It acknowledged the technical difficulties, the resources the company committed to the project and the fact that affected customers got their money back. It also rated the breaches at the lower end of the seriousness scale and found no deliberate disregard of the rules.

Tabcorp’s compliance history pushed the MFA fine up, however. VGCCC Chairperson Chris O’Neill APM said the regulator expects strong systems that prevent breaches. When problems do occur, he wants licensees to identify and resolve them quickly and deal with the underlying cause. He added that the penalty sends a message to all gambling providers that they must fully implement and maintain customer protections.

A Growing List of Tabcorp Penalties

Victoria’s regulator has come down on Tabcorp before, and in 2024 the VGCCC imposed a A$4.6 million fine over responsible gambling failures at the group’s former Victorian licensee. Those failures included gaps in staff training and in support for a customer showing signs of gambling harm. That case also pushed Tabcorp into a wider transformation program designed to strengthen its compliance operations.

The trouble extends beyond Victoria as well. In July 2026, Tabcorp paid more than A$2.7 million in penalties after the Australian Communications and Media Authority found breaches of spam and telemarketing rules. With the new MFA fine added, Tabcorp’s record of penalties now covers responsible gambling, marketing and account security.

What This Means for TAB Customers

Tabcorp told the regulator it completed the MFA rollout in June 2025, and the system is now mandatory for all TAB app users. The A$350,000 fine against Tabcorp therefore covers a closed chapter: the months when MFA remained optional for part of its customer base. Bettors can take a simple lesson from it: switch on every security option an operator offers and never reuse passwords.

For the wider industry, the message from Victoria is direct. The VGCCC judges security controls by how operators enforce them, and a protection that customers can skip counts for little once stolen credentials start circulating. Tabcorp learned that lesson through a six-figure MFA fine, and other wagering operators will want to check that their own safeguards leave no back doors open.

Nadia Content Expert

The Author

Nadia Content Expert

The Author

Nadia Winchester

Slots and News Reviewer

Nadia Winchester has worked in the gambling industry since 2018 and covers slots and industry news for CasinoDaddy. She plays every slot she writes about rather than summarising a provider's fact sheet: how the volatility actually feels over a session, how often the bonus round lands in practice, and whether the published RTP matches what the provider states. She is responsible for the site's slot reviews and free demo play section, writes the daily industry news, and builds and maintains many of the site's larger guide pages.

related news