Tabcorp has been fined A$350,000 after Victoria’s gambling regulator found gaps in customer account security. In a September 24 announcement, the Victorian Gambling and Casino Control Commission said the wagering operator had failed to put mandatory multi-factor authentication, or MFA, in place on time. Some customers later saw unauthorized access and withdrawals.

Why Tabcorp was fined
The VGCCC said Tabcorp breached four technical standards between January 30 and June 23, 2025. Those standards required stronger controls for customer accounts. The central issue was the absence of mandatory MFA during that period, according to the regulator.
MFA adds a second check beyond a password. That extra step can make a stolen or guessed password less useful to an intruder. It does not eliminate every risk, but regulators increasingly treat it as a basic defense for accounts that hold money and personal details.
The timing of the rollout
Tabcorp completed its MFA rollout in June 2025, the VGCCC said. The fine announced on September 24, 2026, addresses the earlier period of non-compliance. The regulator did not frame it as a finding that MFA remains absent today. That timing matters when judging the operator’s current controls.
What happened to affected customers
The VGCCC said some accounts suffered unauthorized access and withdrawals. It also said banks or Tabcorp reimbursed the affected customers. The public notice does not give an overall loss figure or a precise customer count, so those details remain unclear.
For customers, the case shows why account security goes beyond a password reset after an incident. A second login factor can reduce the chance that one exposed credential opens an account. Users should still use unique passwords and review account activity. They should contact their operator promptly if a transaction looks unfamiliar.
A compliance warning for wagering operators
The A$350,000 penalty puts a price on missing a required security control. More broadly, it shows how a technical standard can become an enforcement matter when an operator does not implement it. The commission’s notice focuses on the compliance failure and the customer impact, rather than on a new gambling product or market launch.
Operators that serve customers online have a practical lesson here: a control written into a standard needs a rollout date, testing and clear ownership. A late fix may protect accounts going forward, but it does not erase an earlier breach. Our report on Singapore’s new patron-data measures shows another way regulators are sharpening oversight of customer information. The September 24 decision closes one specific case, while the wider focus on account security continues.










