TerminalExecutionOdds337ToolsContact
    DocsLog in
    1. Home
    2. Guides
    3. Betting accounts in Australia: the rules from sign-up to closure
    4. Betting account security: how to protect your bookmaker logins

    Betting account security: how to protect your bookmaker logins

    Betting account security in Australia: unique passwords, two-factor login, fake bookmaker sites and texts, shared devices, and what to do if you are hacked.

    By the B337 team. Last updated 8 October 2026.

    The short answer

    • Betting account security rests on three habits: a password used nowhere else, two-factor login wherever the bookmaker offers it, and opening the bookmaker only through its app or a web address you have checked.
    • The Australian Cyber Security Centre recommends passwords of at least 15 characters, and rates codes sent by SMS or email as the least secure kind of two-factor login.
    • If someone gets into your account, contact the bookmaker through its own app or website, change the password, cut your deposit limit, which applies at once, and check the bank account on file.
    • On a shared phone or computer, never save the login, and check whose fingerprints or faces are enrolled, because an app that signs in with them may accept any of them.

    On this page

    1. What someone can do with your betting login
    2. Passwords: long, unique and never shared
    3. Two-factor authentication (2FA) on a betting account
    4. Fake bookmaker sites, texts and calls
    5. Shared devices and people in your household
    6. If your betting account is hacked
    7. Software, tipsters and anyone else who wants your login
    8. Security mistakes and what they cost

    Betting account security means keeping everyone else out of an account that holds your money, your identity details and the bank account your withdrawals go to. Three habits do most of the work. Use a password of at least 15 characters that you use on no other site, turn on two-factor login wherever it is offered, and open the bookmaker only through its app or a web address you have checked.

    The rest is knowing what a fake site or message looks like, keeping shared devices locked, and acting fast if someone does get in. All of it works alongside the protections Australian betting accounts carry, such as the deposit limit every Australian online bookmaker must offer.

    What someone can do with your betting login

    A bookmaker login is a key to money, not just to a profile. With it, someone else can:

    With your login, someone canWhat limits the damage
    Bet whatever balance is in the accountKeeping the balance modest and withdrawing what you do not need there
    Deposit more from a card or bank account saved on fileA deposit limit, which nobody can raise in a hurry
    Read your name, date of birth, address and contact detailsReporting the breach quickly, so you can watch for misuse of those details
    Change the email, phone number or bank account on fileTwo-factor login, and checking those details whenever you log in
    Lock you out by changing the passwordAn email account with its own strong password and two-factor login

    Your email account matters as much as the betting account. Password resets go there, so whoever controls your inbox can usually take over everything linked to it.

    Passwords: long, unique and never shared

    The Australian Cyber Security Centre (ACSC) gives three rules in its personal cyber security handbook, published in September 2026. Make a password at least 15 characters long, make it unpredictable, such as a random mix of unrelated words, and use a different one for every account. The handbook also says to keep passwords private and to change any you think have been exposed.

    Unique is the rule that protects betting accounts most. If one site you use is breached and you reused that password, every account sharing it is open, including bookmakers whose own systems were never touched. A password manager makes unique passwords practical: the ACSC recommends one, protected by a strong master password and its own two-factor login.

    Tip: Start with your email, then each bookmaker. Replace any password you have used elsewhere, switch on two-factor login if the account has it, and clear any saved login from shared browsers as you go.

    Two-factor authentication (2FA) on a betting account

    Two-factor authentication (2FA), which the ACSC calls multi-factor authentication (MFA), adds a second check after your password, so a stolen password alone does not get anyone in. The ACSC rates it as one of the most effective ways to stop an account being hacked. Its handbook lists these options, in this order:

    TypeHow it works
    PasskeyYour device proves who you are, with no password typed
    Physical tokenA small device that shows a new code at regular intervals
    Security keyA small device with no screen, plugged in or connected wirelessly
    BiometricsYour face or fingerprint confirms it is you
    Authenticator appAn app on your phone that shows a one-time code
    SMS or email codeA one-time code sent to your phone or inbox

    The ACSC describes a passkey as more secure than a password, and one that stops a fake site capturing your login. It calls SMS and email codes the least secure option, because phone numbers and email accounts can be taken over.

    Two-factor login is not one of the 10 protections in the national consumer protection framework, so whether you can turn it on depends on the bookmaker. Check the security settings in each account and choose the strongest option it gives you.

    SMS codes have a known weak point. ACMA explains that a criminal holding your personal details can move your number to a new SIM or a new telco, then receive your codes. If your phone suddenly cannot make or receive calls or texts, or shows SOS only where the signal bars usually sit, contact your telco at once. Telcos must confirm your identity before porting a number or swapping a SIM, under rules ACMA enforces.

    Fake bookmaker sites, texts and calls

    Phishing is a message that pretends to come from someone you trust, to get your password, a login code or money. The ACSC's warning signs fit betting scams closely. They include an unexpected message, pressure to act fast, a request for a password or code, and a link or QR code you were not expecting. An odd sender address, a generic greeting, or a threat that your account will be closed are signs too.

    A text that shows a bookmaker's name proves little. The ACSC says scammers use familiar brand names. It adds that messages from senders not verified through ACMA's sender ID register may show as unverified, which helps but does not catch everything. Never log in from a link in a message: open the app, or type the address yourself.

    Calls can be faked too: the ACSC warns that a caller ID can look real but be fake, and that a caller may ask you to skip normal security steps. If someone rings claiming to be your bookmaker and asks for a password or a login code, hang up and contact the bookmaker yourself, through its app or a phone number on its own website.

    Fake sites copy a real bookmaker's look under an address a letter or an ending away from the real one. ACMA's register gives the website for most licensed providers, so check the address against the bookmaker's row on ACMA's register before you log in; checking a bookmaker is licensed shows how.

    A site with no row is worse, not safer. ACMA's warning is that an illegal operator may keep your winnings or vanish with customers' money, and that its customers have no Australian regulator to turn to.

    Some scams arrive as offers. A tipster or "investment" seller who asks for your login, or for money to bet with, is a red flag in itself; fake tipster red flags lists the rest.

    Shared devices and people in your household

    The ACSC's device advice applies straight to betting apps. Lock every device when you are not using it, and set it to lock itself within 5 minutes. Give everyone who uses a computer their own user account, and never save logins on a shared or public device. On public Wi-Fi, use your own mobile data or hotspot for anything involving money.

    Check who else can open your phone. If someone else's fingerprint or face is enrolled on it, an app that signs you in that way may let them in too. Remove any you do not want, and use a passcode only you know.

    People in your home are a separate question. Your account is verified to you alone, and many bookmakers' terms forbid or limit anyone else using it. A partner's bets on your account land in your statements and against your deposit limit, so neither describes your own betting any more.

    Anyone under 18 must never be able to open a betting app on a family device; the ACSC suggests child user accounts with parental controls, and blocking gambling transactions covers blocking software.

    Risk: Betting involves risk, and a shared account hides who is taking it. If someone else's betting is worrying you, helping someone with gambling covers what to say and where to get support, and responsible gambling lists free, confidential help.

    If your betting account is hacked

    The ACSC's signs of account compromise include changes you did not make, a password that stops working and being logged out on every device. A password reset you did not ask for, or transactions you do not recognise, are signs too. On a betting account, add bets, deposits or withdrawals you did not make. Then act in this order:

    1. Contact the bookmaker through its app or the contact details on its own website, never a link in a message. Ask it to lock the account and hold any withdrawal while it checks.
    2. If your email may be compromised, secure it first, because resets go there. Then change the bookmaker password, sign out of other devices if the option exists, and turn on two-factor login.
    3. Cut your deposit limit, and ask the bookmaker to cancel any increase you did not request. Under the national framework a cut applies at once, while a rise cannot apply until 7 days after it is requested.
    4. Check every detail on file, especially the email, phone number and nominated bank account, then go through recent bets, deposits and withdrawals.
    5. Call your bank if money moved that you did not authorise, and ask about replacing any card saved with the bookmaker.
    6. Write down what happened, when, and what you have done. Report it through ReportCyber at cyber.gov.au, and to Scamwatch if a scam message started it.
    7. Change the password anywhere else you used it.

    Example: Illustrative. Someone gets into your account on a Thursday night and asks to raise your weekly deposit limit from $150 to $2,000. That rise cannot apply until 7 days after the request, the following Thursday at the earliest. A cut to $20 that you make on Friday morning applies straight away, but ask the bookmaker to cancel the pending rise as well, because the national rules do not say a later cut cancels it.

    If the bookmaker will not accept that bets were placed without your consent, put the dispute in writing and ask for a reference number. Then raise it with the authority that licensed the bookmaker; how to complain about a bookmaker sets out each step. The ACSC also warns about recovery scams, so ignore anyone offering to get your money back for a fee.

    Software, tipsters and anyone else who wants your login

    Every copy of your login outside your own head and password manager is one more place it can leak. Many bookmakers' terms forbid or limit third-party access and automated betting, and a breach can end in capped stakes, voided bets or a closed account.

    Before typing a bookmaker password into any tool, read giving betting software your login, which covers where software runs, how logins are stored and what to ask. B337, for example, sets out how it holds the bookmaker logins its bot uses on its security page.

    When you stop using any tool or service that held a login, change that bookmaker password, so any copy left behind no longer works.

    Security mistakes and what they cost

    MistakeWhat it can cost
    One password for your email and every bookmakerOne breach opens every account, and the inbox their resets go to
    SMS codes as your only second factor, when the bookmaker offers betterA stolen phone number receives your codes
    Logging in from a link in a text or emailA copy of the site can capture your password and code
    A saved login on a family laptopAnyone using the laptop can bet your balance
    No deposit limitNothing caps deposits from your saved card while someone else is in
    Waiting days to report bets you did not placeMore time to drain the balance, and a weaker dispute
    Handing a tipster or scheme your loginBets you never chose, in an account the bookmaker can close under its terms

    Questions

    Do Australian bookmakers offer two-factor authentication?
    It depends on the bookmaker, because two-factor login is not one of the national framework's 10 consumer protections. Look in each account's security settings, and where you can choose, pick an authenticator app or passkey over an SMS code.
    Will a bookmaker refund bets someone else placed on my account?
    That depends on the facts and on the bookmaker's terms, so read its clause on account security first. Report it to the bookmaker in writing straight away, keep the reference number, and take an unresolved dispute to the authority that licensed the bookmaker.
    Is it safe to bet on public Wi-Fi?
    The Australian Cyber Security Centre advises against sensitive tasks such as online banking on public Wi-Fi, and suggests your own mobile hotspot where possible. A betting account holds money and identity details, so treat it the same way.
    What should I do with a text from my bookmaker that has a link in it?
    Do not tap the link: open the bookmaker's app, or type its address yourself, and check your account from there. Scammers use familiar brand names in texts, and a sender name proves nothing on its own.
    Should I close my betting account after it has been hacked?
    That is your choice: control comes back from securing your email, changing the password and checking the details on file, not from closing. If you would rather leave, the national framework requires the bookmaker to start closing the account as soon as it receives your request.

    Sources

    • Use unique and strong passwords, Personal cyber security handbook, Australian Cyber Security Centre
    • Set up multi-factor authentication, Personal cyber security handbook, Australian Cyber Security Centre
    • Learn how to spot scams, Personal cyber security handbook, Australian Cyber Security Centre
    • Recover from email and online account compromise, Australian Cyber Security Centre
    • What to do if your mobile number has been stolen, ACMA
    • Check if a gambling operator is legal, ACMA
    • Protect yourself from illegal gambling operators, ACMA
    • National Consumer Protection Framework for Online Wagering: National Policy Statement (updated 3 May 2022), Department of Social Services

    Related

    • Betting accounts in Australia: the rules from sign-up to closure
    • Is it safe to give betting software my login? What to check first
    • Security
    • Fake tipster red flags and how to spot a tipster scam
    • Betting account verification in Australia
    • How to read a betting activity statement
    • Betting deposit methods in Australia
    • How long betting withdrawals take and why they get delayed

    Betting involves risk. Bookmakers can restrict or close accounts and void bets, automation can fail, prices move, and a positive expected value (+EV) bet can still lose. Promotions carry each bookmaker's own terms. There is no guarantee of profit. 18+ only. For free and confidential support call 1800 858 858 or visit gamblinghelponline.org.au. See responsible gambling for limits and support.

    Products

    • Terminal
    • Execution API
    • Full Automation

    Guides and tools

    • All guides
    • Betting glossary
    • Betting calculators
    • How betting bots work
    • Arbitrage betting
    • Middle betting
    • Matched betting
    • Betting exchanges
    • Odds types explained
    • Horse racing software
    • Money back racing promos
    • Bonus bet converter
    • Terminal pricing
    • Execution pricing
    • How tokens work

    Company

    • About
    • Security
    • Responsible gambling
    • Contact
    • Terms
    • Privacy

    Think. Is this a bet you really want to place?

    18+ only. For free and confidential support call 1800 858 858 or visit gamblinghelponline.org.au. Self-exclusion: BetStop (betstop.gov.au).

    B337 is software, not a bookmaker or wagering service provider. Bets are placed in accounts you hold with Australian bookmakers. Bookmaker names are trade marks of their owners; B337 is not affiliated with or endorsed by them. Bookmaker terms may restrict automated betting.

    Bet337 © 2026Join our Discord