Key Points
- The VGCCC found Tabcorp failed to enforce mandatory MFA across all wagering accounts from 30 January to 23 June 2025, during which some accounts were accessed without authorisation.
- This fine follows a A4.6m VGCCC penalty in 2024 and two separate ACMA penalties, A4,003,270 in June 2025 and more than A$2.7m in July 2026.
- Affected customers were reimbursed, but two regulators have now formally identified systemic weaknesses in Tabcorp’s compliance systems across different categories of breach.
Security controls are only useful when they are actually switched on. Tabcorp found that out the expensive way.
The Gambling and Casino Control Commission of Victoria issued an announcement on September 24, 2026, stating that Tabcorp VIC Pty Ltd has been penalised $350,000 for not being able to enforce the requirement for mandatory multi-factor authentication at its wagering site. The violation took place between January 30 and June 23, 2025, lasting almost five months wherein not all customer accounts were subject to a multi-factor identity check prior to access.
Multi-factor authentication is no longer an innovative concept in financial or wagering transactions. Customers need to prove their identity through a second step in order to be able to access their accounts.
What the VGCCC Found, and What Happened Because of It?
The regulator’s finding is worth reading carefully. The VGCCC confirmed that around 99% of customers had voluntarily adopted MFA by 1 April 2025, but the standard was not mandatory for every remaining user until 24 June. That distinction mattered. During the period of non-compliance, some accounts were accessed without authorisation and money was withdrawn. Affected customers were reimbursed by their banks or directly by Tabcorp, but the breach period itself covered four violations of Victoria’s Wagering and Betting Technical Standards.
VGCCC Chairperson Chris O’Neill said licensees were expected to act faster when problems emerge: “We expect strong systems to prevent breaches and protect customers. If breaches occur it is our expectation that licensees identify and resolve them quickly and address their underlying cause.”
The regulator concluded the A$350,000 figure was “appropriate and proportionate.” The VGCCC noted in its decision that the breaches sat toward the lower end of objective seriousness, acknowledged the technical complexity of full MFA rollout, and found no evidence of deliberate disregard for regulatory obligations. Tabcorp had devoted material resources to the implementation and completed it in June 2025.
Victoria Had Already Ordered Structural Change in 2024
The MFA fine does not arrive in isolation. In August 2024, the VGCCC handed Tabcorp an A$4.6m penalty for responsible gambling failings, its largest penalty against the company to that point. That investigation uncovered repeated failures between August 2020 and February 2023, including direct marketing sent to a customer who had opted out six times, inadequate staff training on harm minimisation, and a case where an account manager placed a “Responsible Gambling Call” to a customer showing signs of distress, then ended the call by offering an A$2,000 deposit match promotion.
Following that decision, the VGCCC directed Tabcorp to implement a structured transformation programme, covering harm minimisation, compliance governance and its retail agent network. The September 2026 fine marks the first significant enforcement action in Victoria since that programme began.
ACMA Was Also Applying Pressure From a Different Direction
While the VGCCC was monitoring Tabcorp’s transformation programme, Australia’s communications regulator was building its own case. In June 2025, the Australian Communications and Media Authority penalised Tabcorp A$4,003,270 for sending more than 5,700 non-compliant marketing messages to VIP customers. ACMA Authority Member Samantha Yorke described the violations as “utterly unacceptable,” noting it was the first time the regulator had found spam breaches inside a gambling VIP programme. Alongside the fine, ACMA accepted a three-year court-enforceable undertaking requiring independent review of Tabcorp’s direct marketing systems, quarterly audits and regular reporting.
This was still ongoing when ACMA released its second enforcement order in July 2026. Tabcorp had been fined more than A$2.7 million because ACMA had discovered that Tabcorp made 351 telemarketing calls to customers registered on the Do Not Call register without their permission, 82 calls at unauthorised times and almost 4,000 calls for which Tabcorp did not appropriately disclose its identity and the reason for contacting such individuals. ACMA had taken action against Tabcorp based on information supplied by the company about its sending over 217,000 marketing emails and SMSs to people who had unsubscribed from them.
Yorke’s assessment of the second action was direct: “The scale and range of these breaches point to serious weaknesses in TAB’s compliance systems. The ACMA expects TAB to fix these issues, and we will be watching closely to ensure it meets its obligations.”
Expert Analysis: The Pattern Is Harder to Explain Than Any Single Breach
We want to be precise here, because the VGCCC’s own findings draw a distinction. The regulator did not find that Tabcorp deliberately ignored the MFA requirement. The decision acknowledges technical complexity and the resources committed to rollout. That matters, and it should be part of the picture.
What is harder to reconcile is the cumulative record. Across two regulators, VGCCC and ACMA, Tabcorp has now faced enforcement action across responsible gambling, customer account security, spam law compliance and telemarketing conduct in the space of roughly two years. The VGCCC directed a structural overhaul in 2024. ACMA accepted a court-enforceable undertaking in June 2025. Yet a second ACMA action followed just over a year later, and the VGCCC has now found a further breach during the same period the transformation programme was supposed to be taking hold.
Our reading of this is not that Tabcorp is uniquely reckless. It is a large, operationally complex company with multiple moving parts, and regulators across Australia are actively enforcing in ways they were not five years ago. But the documented picture, ACMA’s own language about “serious weaknesses in TAB’s compliance systems,” and the VGCCC’s repeated enforcement actions raise a fair editorial question: at what point does the breadth of a company’s compliance gaps stop being a series of separate technical problems and start reflecting something harder to fix through programme design alone? We do not have that answer. The regulators appear to be asking the same question.