Tabcorp VIC Pty Ltd Receives AU$350,000 Penalty for Incomplete Multi-Factor Authentication Rollout

Olivia Keller · Sep 24, 2026

Tabcorp VIC Pty Ltd Receives AU$350,000 Penalty for Incomplete Multi-Factor Authentication Rollout

Victorian gambling regulator building exterior with official signage The Victorian Gambling and Casino Control Commission issued a AU$350,000 fine against Tabcorp VIC Pty Ltd in September 2026 after determining that the company failed to meet four wagering and betting technical standards. The violations centered on incomplete deployment of mandatory multi-factor authentication controls for customer accounts, a lapse that persisted from January 30 through June 23, 2025. During this window, certain accounts remained exposed to unauthorized access and withdrawals, including an incident involving automated bot activity targeting dormant profiles. Regulators documented that the partial implementation left gaps in account protection protocols required under Victoria's technical framework. Tabcorp later completed the full rollout of multi-factor authentication in June 2025, mandated application updates for users, and arranged reimbursements for affected customers in coordination with financial institutions. The commission highlighted that complete adherence to these standards forms a core element of consumer safeguards within the regulated wagering sector.

Timeline of the Technical Standards Breach

Documentation from the investigation shows the shortfall began on January 30, 2025, when Tabcorp VIC Pty Ltd had not yet activated multi-factor authentication across all required customer accounts. The period extended until June 23, 2025, creating an extended interval during which account security controls fell short of mandated specifications. A bot-driven attack on dormant accounts occurred within this timeframe, resulting in unauthorized withdrawal attempts that prompted further scrutiny from the commission.

Company records indicate that remediation steps commenced once the deficiencies came to light. Full activation of multi-factor authentication took place in late June 2025, accompanied by requirements for users to upgrade associated mobile applications. Reimbursement processes involved direct engagement with banks to restore funds to impacted accounts, and the operator confirmed that all identified losses received coverage.

Details of the Four Standards Violations

The Victorian Gambling and Casino Control Commission identified four distinct breaches of wagering and betting technical standards. Each related to the absence of complete multi-factor authentication deployment, which the framework lists as an essential control for preventing unauthorized account activity. The regulator's findings established that these gaps constituted non-compliance rather than isolated technical errors.

Investigators noted that dormant accounts proved particularly susceptible during the uncovered period. Automated systems exploited the missing authentication layer, generating withdrawal requests that bypassed standard verification steps. This pattern underscored the practical consequences of delayed implementation and reinforced the commission's emphasis on timely adherence to technical requirements.

Secure online betting interface showing authentication prompts

Tabcorp's Remediation and Regulatory Response

Following identification of the issues, Tabcorp VIC Pty Ltd completed the outstanding multi-factor authentication rollout across its Victorian wagering platform. The operator also enforced app upgrades to ensure compatibility with enhanced security features. Customer reimbursements proceeded through established banking channels, restoring balances where unauthorized transactions had taken place.

The commission issued the AU$350,000 penalty after reviewing the scope and duration of the non-compliance. Statements from the regulator stressed that full implementation of required controls remains necessary to maintain account integrity and protect account holders from external threats. The decision referenced both the technical shortfalls and the subsequent bot activity as factors contributing to the enforcement action.

Broader Context of Wagering Security Requirements

Victorian technical standards mandate multi-factor authentication as a baseline measure for customer account protection in licensed wagering operations. The framework requires operators to apply these controls uniformly, preventing selective or phased rollouts that leave segments of the user base exposed. The Tabcorp case illustrates how partial compliance can intersect with external threats such as automated attacks.

Financial institutions participated in the repayment process, coordinating with the operator to reverse unauthorized withdrawals. This collaboration formed part of the overall resolution and ensured that affected customers regained access to funds without extended delays. The episode aligns with ongoing regulatory focus on cybersecurity measures within Australia's gambling sector.

Conclusion

The AU$350,000 fine imposed on Tabcorp VIC Pty Ltd in September 2026 closes the formal review of the multi-factor authentication shortfall that spanned nearly five months in 2025. The Victorian Gambling and Casino Control Commission documented the four standards breaches, the resulting account vulnerabilities, and the operator's subsequent corrective measures. Full deployment of required authentication controls, combined with application upgrades and customer reimbursements, addressed the identified deficiencies. The case provides a record of enforcement action tied directly to the technical standards governing wagering platforms in Victoria.