
SCCG Take — Regulators treat partial rollout of mandated security features as noncompliance. Operators with prior violations face elevated fines when customer account protections are not universally applied on time.
Tabcorp VIC Pty Ltd has been fined A$350,000 by the Victorian Gambling and Casino Control Commission after failing to fully implement mandatory multi-factor authentication on customer wagering accounts. The breaches ran from January 30 to June 23, 2025. During that window some customers logged in without the additional verification step, allowing unauthorised access and fund withdrawals.
Unauthorised parties compromised accounts in that period. Affected customers later received reimbursements from Tabcorp or their banks. As reported by World Casino News, the commission ruled that Tabcorp breached four Wagering and Betting Technical Standards by not completing the rollout inside the required timeframe.
Tabcorp introduced MFA functionality in March 2025. Customers on older versions of the TAB app could still bypass the extra step. By April 1 roughly 99% of customers had upgraded, yet full mandatory enforcement only took effect on June 24 after the company required remaining users to update their app.
A bot attack reported in May 2025 targeted dormant accounts with credentials obtained from the dark web. A$31,000 was withdrawn across Australia, including A$13,471 from Victorian customers. The regulator identified unauthorised access affecting at least 195 accounts with total withdrawals of A$308,098.91. Fourteen customers were impacted inside the breach window covered by the disciplinary action.
Chris O’Neill APM, VGCCC Chairperson, stated: “We expect strong systems to prevent breaches and protect customers. If breaches occur it is our expectation that licensees identify and resolve them quickly and address their underlying cause.” Tabcorp had obtained several prior extensions, the last expiring on January 29, 2025. A further extension sought in February was refused. The company maintained that alternative controls satisfied the standards and cited technical difficulties. The commission rejected that position as “an unduly narrow and technical interpretation.”
The regulator weighed Tabcorp’s resource commitment, the reimbursements made, and the technical obstacles encountered. It placed the breaches at the lower end of the seriousness scale and found no deliberate disregard of obligations. Tabcorp’s previous compliance history nevertheless contributed to the final amount.
In 2024 the commission imposed a A$4.6 million fine on the group’s former Victorian licensee for responsible gambling failures that included inadequate staff training and missed signs of customer harm. In July 2026 Tabcorp paid more than A$2.7 million after the Australian Communications and Media Authority cited breaches of spam and telemarketing rules.
O’Neill added: “Customer-protection requirements are necessary to safeguard Victorian customers and maintain confidence in regulated wagering products and services. This penalty reinforces to all gambling providers that they must fully implement and maintain those protections.”
This decision makes clear that making a security feature available is not the same as mandating its use across the entire customer base. Operators facing comparable technical standards cannot treat phased adoption or expired dispensations as sufficient. Where compliance histories already contain earlier penalties, regulators are likely to calibrate fines upward to drive complete and timely execution of required controls.
Reporting: World Casino News
Generated by SCCG’s automated editorial system from published source reporting. SCCG Management holds editorial responsibility.
Gaming, betting and prediction markets — the desk’s read, every weekday.
Subscribe →