Ace Alliance Horizon & Speed Rome
Ace Alliance Horizon & Speed Rome
Early Bird Passes Available! | November 2, 2026
Get Your Pass!
Table Of Content :

Tabcorp’s A$350,000 Fine Highlights Risk in 99% MFA Rollout

trust
Ace Alliance: Delivering Trust Through Expertise
From exclusive events and interviews to real-time market trends, Ace Alliance brings you unbiased, well-informed, and data-driven content. Our editorial team adheres to strict editorial standards, ensuring that the information you receive is not only relevant but also trustworthy.

Built by market experts hosting events since 2023, with our first event in Riga, Latvia gathering over 300 top level iGaming industry executives, Ace Alliance is able to provide you with reliable information from direct interaction with experts and leaders in the sector.
Altay
Altay Celikkaya
Content Manager
Updated:
Reading Time: 3 minutes

Tabcorp VIC Pty Ltd has been fined A$350,000 after Victoria’s gambling regulator found that mandatory multi-factor authentication was not fully implemented across its wagering system. According to the Victorian Gambling and Casino Control Commission’s formal decision, the operator failed to meet four technical standards between 30 January and 23 June 2025. During the period, customer accounts were accessed without authorisation and funds were withdrawn, including from accounts that did not have MFA active.

Tabcorp news graphic reading Hit With 350K Fine with the subheadline Incomplete MFA Rollout Breached Security Rules alongside the Australian flag and Tabcorp branding.

Regulation & Compliance

Key Takeaways From Tabcorp’s MFA Fine

  • Tabcorp was fined A$350,000 for failing to fully implement mandatory MFA requirements.

  • The non-compliance lasted from 30 January to 23 June 2025.

  • Around 99% of customers had adopted MFA by 1 April, but the remaining group could still access older app versions without it.

  • Some customers without active MFA were affected by a bot attack that resulted in withdrawals from Victorian accounts.

  • The VGCCC rejected Tabcorp’s position that making MFA available and using alternative controls was sufficient to meet the technical standards.

  • Full implementation was completed after customers were required to upgrade to a TAB app version incorporating MFA.

99% Adoption Did Not Equal Full Compliance

The VGCCC’s decision draws a distinction between making a security control available and enforcing it across the entire customer base.

Tabcorp told the regulator that MFA had been available from March 2025 and that 99% of customers had adopted it by 1 April. However, some customers could still use older versions of the TAB app without MFA. The Commission found that Tabcorp remained non-compliant until 24 June, when customers were required to upgrade to an app version incorporating full MFA functionality.

The regulator also rejected Tabcorp’s argument that its alternative detection and security controls satisfied the relevant requirements. It found that MFA was required for compliance and that, when the standards were read together, it represented the minimum appropriate security control for account access.

The enforcement action comes as the company continues investing in regulatory and risk programmes alongside its wider operations, an area highlighted in Tabcorp’s FY2026 results.

Account Access Incidents Show the Remaining Exposure

The decision details how the remaining gap translated into customer risk. In January 2025, Tabcorp reported that a malicious actor had accessed at least 195 customer accounts and withdrawn A$308,098.91. Tabcorp later advised that 14 of those customers were affected during the period covered by the disciplinary action, while the remaining cases occurred during earlier periods when dispensations were in place.

A second incident was reported in May, when a bot attack targeted dormant accounts without active MFA. Approximately A$13,471 was withdrawn from Victorian customer accounts, forming part of around A$31,000 withdrawn from Tabcorp accounts nationally. The decision states that affected customers were reimbursed either by their financial institutions or by Tabcorp.

VGCCC Chairperson Chris O’Neill said:

Customer-protection requirements are necessary to safeguard Victorian customers and maintain confidence in regulated wagering products and services.

Technical Compliance Remains an Operator-Level Issue

The Tabcorp case adds to recent Australian wagering enforcement focused on whether player-protection systems work as intended in practice. A recent Palmerbet BetStop compliance case similarly showed how an operational control can be in place while problems with its implementation prevent the intended customer protection from being delivered.

For operators and their B2B technology partners, the practical issue extends beyond launching a security feature. The VGCCC’s findings show that account-access controls may need to cover legacy app versions, dormant accounts and the full customer base before mandatory requirements are considered fully implemented.

The issue also sits within wider scrutiny of security controls across regulated gambling. Recent cybersecurity concerns following the Curaçao Gaming Authority portal breach have brought additional attention to how weaknesses in access controls can expose sensitive customer, operator or regulatory information.