Tabcorp Fined AUD 350,000 Over Multi-Factor Authentication Failures
AI-GENERATEDAustralian gambling giant Tabcorp faces a significant fine after failing to implement mandatory security controls, leading to unauthorized account access.
The Australian betting landscape has been shaken by a new disciplinary action against Tabcorp VIC Pty Ltd. The Victorian Gambling and Casino Control Commission (VGCCC) recently imposed a fine of 350,000 AUD on the operator. This decision comes after a thorough investigation revealed that Tabcorp failed to implement mandatory security measures designed to protect customer wagering accounts. Specifically, the lack of multi-factor authentication (MFA) left thousands of users vulnerable to cyberattacks and financial theft during the first half of 2025.
According to the findings, the period of non-compliance lasted from 30 January to 23 June 2025. During these months, the wagering system did not meet four crucial technical standards required by the regulator. The absence of MFA, which requires more than one form of identity verification, allowed bad actors to infiltrate user accounts. These breaches resulted in real financial losses for customers as unauthorized withdrawals were successfully processed. This case serves as a stern warning to the global iGaming industry about the risks of technical negligence.
Numbers and facts
The 350,000 AUD penalty is part of a series of enforcement actions against Tabcorp. In early 2025, the company was hit with a staggering 4.6 million AUD fine for broad failures in governance and harm-minimization. The current fine reinforces the message that security is a non-negotiable pillar of a gambling license. The VGCCC emphasized that maintaining public confidence in regulated products is paramount, especially as more players move to mobile applications.
VGCCC Chairperson Chris O’Neill APM expressed disappointment in Tabcorp's failure to adhere to the established standards. He made it clear that large-scale operators have no excuse for delayed security rollouts.
"We expect strong systems to prevent breaches and protect customers. If breaches occur it is our expectation that licensees identify and resolve them quickly and address their underlying cause." - Chris O’Neill APM, Chairperson of the VGCCC
Tabcorp has informed the commission that it reached full compliance by late June 2025. This included forcing users to update their TAB mobile app to a version that supports MFA. The company also confirmed that all affected customers have been reimbursed, either through their respective banks or by Tabcorp itself.
Background
Multi-factor authentication is widely considered the gold standard for securing online accounts. By requiring a second layer of verification—such as a code sent to a mobile device or a fingerprint scan—operators can prevent over 99 percent of automated account takeover attempts. Tabcorp's failure to roll this out across its entire user base created a window of opportunity for hackers. The VGCCC's decision to penalize the firm reflects a growing trend among regulators to treat IT security with the same level of scrutiny as anti-money laundering (AML) protocols.
For the Victorian regulator, this fine is not just about the money but about setting a precedent. The Australian gambling market has seen increased pressure to improve consumer protections. As digital wagering grows, the responsibility of the license holder to safeguard sensitive financial data becomes a core operational requirement. Failure to do so now carries not only financial penalties but also significant reputational risks.
Why it matters for German players
For players in Germany, this case illustrates the importance of the strict regulations enforced by the Interstate Treaty on Gambling 2021 (GlüStV 2021). While Australia is still fine-tuning its digital security mandates, Germany has implemented some of the world's most rigid player protection systems. Every legal operator on the GGL whitelist must adhere to strict data security and identity verification rules. The central LUGAS system and the OASIS player block file provide layers of protection that make the German market significantly more secure than offshore jurisdictions like Curacao or Malta.
German law requires a 1,000 Euro monthly deposit limit and a 1 Euro maximum bet per spin for virtual slots. These limits, combined with mandatory account verification processes, ensure that even in the event of a security breach, the potential damage to a player is strictly limited. The Tabcorp incident reinforces why German authorities are so focused on a "closed loop" system of regulation where every technical aspect of the platform is audited by the GGL.
What it means for GGL-licensed casinos
German licensed casinos must maintain a proactive approach to cybersecurity. Any delay in implementing security patches or mandatory features like MFA could lead to immediate license suspension by the GGL. The Tabcorp case shows that even established industry giants are not immune to regulatory wrath when they fail their customers. For German operators, technical excellence is just as important as the variety of games offered. Maintaining a secure environment is the only way to ensure long-term sustainability in a highly regulated market like Germany.
Frequently asked questions
Why was Tabcorp fined in Australia?
The company failed to implement mandatory multi-factor authentication (MFA) controls. This technical failure allowed unauthorized persons to access customer accounts and withdraw money.
How much was the fine imposed on Tabcorp?
The VGCCC imposed a fine of 350,000 AUD on Tabcorp Victoria. This follows a previous 4.6 million AUD fine for different compliance failures earlier in the same year.
Were the affected customers compensated?
Yes, Tabcorp confirmed that all affected customers were reimbursed for their losses. The payments were handled either by the company or by the customers' banks.
Is my money safe in German online casinos?
Yes, operators with a GGL license must follow strict IT security protocols. Systems like LUGAS and official identity checks provide high levels of security compared to unregulated offshore markets.
Share
About the author

Lisa Lustich
Editor-in-chief & casino tester
Lisa Lustich has been testing German-language online casinos since 1997 and runs the Lustich.de newsroom. More than 400 published reviews, certified player-protection advisor (BZgA training, 2019).
All articles by Lisa Lustich →Sources & further reading
Whitelist of permitted online operators
Editorial guidelines Lustich.de
BZgA problem-gambling helpline: 0800 1 372 700
Gambling can be addictive. Please play responsibly. Help and counselling at 0800 1 372 700 (BZgA, free & anonymous).
Related topics
Further Reading
AI-GENERATEDTribal Gaming Leaders Unite Against Prediction Markets as Sovereignty Threat
The Indian Gaming Association (IGA) is rallying tribal nations to oppose prediction markets that offer sports betting disguised as financial products.
AI-GENERATEDMalta Tax Overhaul: New VAT and Gaming Tax Rules Effective from October
Malta has implemented significant changes to its gaming tax and VAT framework as of October 1, 2026, aiming to clarify exemptions and streamline reporting.
AI-GENERATEDUS Regulator CFTC Files New Prediction Market Rules for White House Review
The CFTC aims to clearly separate casino products from prediction markets. Meanwhile, CBS News is already using Kalshi data for the 2026 elections.











