Tabcorp Hit With A$350K Fine Over MFA Security Gaps
Victoria’s gambling regulator has hit Tabcorp with a A$350,000 fine after the wagering giant failed to make MFA mandatory for all customer accounts within the required timeframe. For almost five months in 2025, some TAB customers could still log in with just a username and password. Fraudsters used that gap to access accounts and withdraw money. The Victorian Gambling and Casino Control Commission (VGCCC) found that Tabcorp VIC Pty Ltd breached four Wagering and Betting Technical Standards between January 30 and June 23, 2025.
What Led to the Tabcorp MFA Fine
Multi-factor authentication adds a second verification step, such as a code sent to a phone, before a customer can get into an account. The VGCCC required Tabcorp to introduce MFA on wagering accounts and granted the company several extensions to complete the work. The final dispensation expired on January 29, 2025, and the regulator refused Tabcorp’s request for more time a month later.
Tabcorp switched on MFA in March 2025, but customers running older versions of the TAB app could still skip the extra step entirely. Adoption climbed quickly, with around 99% of customers using MFA by April 1. However, the remaining users kept a back door open until June 24, 2025, when Tabcorp forced everyone left to update the app. Those missed months set up the fine that Tabcorp now faces over its MFA rollout.
Bots Went After Dormant Accounts
That back door did not stay unnoticed for long. In May 2025, a bot attack targeted dormant TAB accounts using login details that Tabcorp said likely came from the dark web. The attackers withdrew roughly A$31,000 from accounts across Australia, including A$13,471 from accounts belonging to Victorian customers.
The full picture is larger than that single incident. The regulator’s decision identified unauthorised access to at least 195 customer accounts, with withdrawals totalling A$308,098.91. Only 14 of those customers fell within the breach period itself, because the other incidents happened while Tabcorp still operated under approved dispensations.
Tabcorp or the customers’ own banks later reimbursed everyone who lost money through unauthorised withdrawals. Attacks like this rely on people reusing passwords across sites, which is exactly the risk a second verification step exists to block. The refunds softened the blow for customers, but they did not spare Tabcorp a fine over the MFA gap that made the withdrawals possible.
Tabcorp Argued the Protection Was Already There
In its response to the disciplinary action, Tabcorp argued that alternative security controls already satisfied the relevant standards. The company also maintained that any breach ended in March once MFA became available, and it pointed to the technical difficulties of rolling out the system. In effect, Tabcorp contested the basis for an MFA fine by arguing that offering the feature counted as compliance.
The VGCCC rejected that reading and described it as an “unduly narrow and technical interpretation” of the company’s obligations. In the commission’s view, compliance required mandatory MFA for every customer, and a feature that older app versions could bypass fell short of that standard. That distinction sits at the heart of the fine against Tabcorp, since the commission judged MFA by its enforcement, not its launch date.
How the Regulator Set the Penalty
The commission weighed several factors before settling on the size of Tabcorp’s fine for the MFA failures. It acknowledged the technical difficulties, the resources the company committed to the project and the fact that affected customers got their money back. It also rated the breaches at the lower end of the seriousness scale and found no deliberate disregard of the rules.
Tabcorp’s compliance history pushed the MFA fine up, however. VGCCC Chairperson Chris O’Neill APM said the regulator expects strong systems that prevent breaches. When problems do occur, he wants licensees to identify and resolve them quickly and deal with the underlying cause. He added that the penalty sends a message to all gambling providers that they must fully implement and maintain customer protections.
A Growing List of Tabcorp Penalties
Victoria’s regulator has come down on Tabcorp before, and in 2024 the VGCCC imposed a A$4.6 million fine over responsible gambling failures at the group’s former Victorian licensee. Those failures included gaps in staff training and in support for a customer showing signs of gambling harm. That case also pushed Tabcorp into a wider transformation program designed to strengthen its compliance operations.
The trouble extends beyond Victoria as well. In July 2026, Tabcorp paid more than A$2.7 million in penalties after the Australian Communications and Media Authority found breaches of spam and telemarketing rules. With the new MFA fine added, Tabcorp’s record of penalties now covers responsible gambling, marketing and account security.
What This Means for TAB Customers
Tabcorp told the regulator it completed the MFA rollout in June 2025, and the system is now mandatory for all TAB app users. The A$350,000 fine against Tabcorp therefore covers a closed chapter: the months when MFA remained optional for part of its customer base. Bettors can take a simple lesson from it: switch on every security option an operator offers and never reuse passwords.
For the wider industry, the message from Victoria is direct. The VGCCC judges security controls by how operators enforce them, and a protection that customers can skip counts for little once stolen credentials start circulating. Tabcorp learned that lesson through a six-figure MFA fine, and other wagering operators will want to check that their own safeguards leave no back doors open.










