Home

Click here to go to the login pageClick here to go to the registration page


Loading...

Online Security

Golden Casket takes on-line security seriously and has implemented various measures which aims to provide you with a secure purchase environment.

Please spend a few moments reading this security information on precautions and potential threats.

Link to content on this page
7 ways we aim to protect you
How we protect your privacy
5 ways to protect yourself
Logging in safely
6 tips for safe purchasing
Security threats & Scams

7 ways we aim to protect you online

1. Encryption Top

Your Lotto Direct account is password protected requiring you to login through an SSL encrypted connection before gaining access to your account.

Winners Circle On-line and Lotto Direct use 128 bit Secure Socket Layer (SSL) encryption technology, which is common security technology on websites which ask you to provide sensitive or personal information. This level of encryption scrambles information between the user (you) and the host (us) making it very difficult for parties who try to intercept this information to read or change it. 128 bit SSL encryption is the same encryption standard which is used by most Banks and online merchants.

2. Account Monitoring Services Top

Golden Casket performs account and system monitoring services on a daily and periodic basis to safeguard our players and our systems by proactively identifying suspicious transactions. For example, Golden Casket monitors failed logins to player's accounts and will lock the account immediately when 6 failed logins are detected.
Golden Casket will then call the player to verify the failed logins. The account is only re-opened when the player is able to verify their personal details.

There are a range of other activities and reports we run to ensure the safety of your account, your personal information and your transactions. To ensure we maintain high integrity around these practices, we believe it's in your best interest, not to disclose them publicly.

3. Regulated Gaming Systems Top

Golden Casket prides itself on operating a gaming system of high integrity. Our systems, including the gaming system, are regulated by the gaming division of the Queensland Government, the Queensland Office of Gaming Regulation. The purchases you make through Lotto Direct, are processed through the same gaming system as purchases you make in a Golden Casket shop.

4. Secure Systems are a high priority Top

Golden Casket employs IT security professionals whose role is to maintain the security of our systems, our networks and gaming systems by managing firewalls, intrusion protection systems, virus protection, network security and regular patching. Golden Casket aims to secure our systems to best practice by maintaining a constant vigilance for emerging threats.

Golden Casket also contracts external security professionals to monitor the security of our website environment in line with accepted international standards. This regular monitoring ensures our systems continue to provide high levels of security for players.

5. Protecting your Bank Account & Credit Card details Top

Golden Casket treats your Password, Credit Card and Bank Account information with care. Your Passwords, Credit Card details and Bank Account details are encrypted in our database and Golden Casket takes steps to protect your personal information from misuse or loss, and from unauthorised access, modification or disclosure. To update your personal information, we ask that you login securely to your Lotto Direct account and update these details yourself in a secure environment.

The precautions we take, are designed to maximise the security of your Lotto Direct account and your personal information. For extra security, we also ask you to re-enter your login password when you're withdrawing funds from your Lotto Direct account.

You don't even need to give us your Bank Account or Credit Card details. Because we offer BPay® as well as Credit card deposit options, you don't even need to give us your Bank account or Credit Card details. And you don't need to enter this information over the internet. To deposit by BPay®, just contact your Bank (ie using your Bank's Phone or Internet banking facility) to setup the BPay® transaction. Your Bank will then send the funds securely to Golden Casket and we'll deposit them into your Lotto Direct account. And if you want to withdraw funds from your Lotto Direct account, just ask us to send you a cheque. Learn more about BPay deposits.

6. Session limits Top

As an extra precaution, you will be automatically logged out of Lotto Direct if your browser is inactive for
10 minutes. This may prevent another person from accessing your personal information, if you leave the computer unattended for an extended period of time. We do encourage you to logoff after every session.

7. Securing Passwords Top

Your Lotto Direct password is your gateway to the features of Lotto Direct so it's critical that it's kept secure at all times. You will be logging into Lotto Direct through an SSL-encrypted connection before being able to gain access to your account.

Your password is encrypted when stored in our database and our staff do not have access to it. Even if you forget your password, our staff cannot retrieve it for you. Instead they'll advise our system to cancel your old password, and automatically issue you with a new, temporary password, seen only by you. If you forget your password, before Golden Casket can send it to you, we will need to verify your identity by asking you some security questions, such as "What is your mother's maiden name". This ensures that only you can retrieve your password. You can choose the question and the answer to make it easier for you to remember.

For extra security, passwords must also meet strict security requirements enforcing a 6 to 12 character password containing at least one letter and at least 1 number. This makes your password harder to guess.

If you have security concerns, for example if you feel that your password might have been compromised, you should call us on 131 868. You can also lock your account immediately. Just login and click on the 'Lock My Account' button, which will do the following;

  • Your Lotto Direct account will be automatically locked by our system.
  • No-one, including you, will be able to login to your account while it is locked, even if you enter the correct password.
  • You will still be able to use your Winners Circle card to purchase entries in your local Golden Casket Agency.
  • On the next business day, a staff member from the Golden Casket contact centre will call you.
  • We will ask you questions about yourself relating to your membership to verify your identity.
  • We will then provide you with new login details for your account.

How we protect your privacy

Golden Casket will not sell or rent your personal information to any third party. The information you provide to Golden Casket is used by us to provide our lottery products and services to you. Some of your personal information (ie. things like name, address, email address, phone number) may be shared with trusted organisations who assist Golden Casket in sending you mail and prize cheques, conducting research, website development or so Golden Casket can contact you. For example Golden Casket may need to deliver you prize payment cheques, mail you a new Winners Circle card or promotional information, or to conduct Market Research (but only research which is for Golden Casket).

Golden Casket also takes extra care with your sensitive personal information such as Bank Account Details and Credit Card details. This information is stored in an encrypted format in our gaming system. This information is ONLY USED to process and finalise payment or transfer requests made by you, to or from the Financial Institutions you request.

For more information about how we deal with your personal information, it is important that you read our full Privacy Policy, available here.

5 ways you can protect yourself

1. Make sure emails are from Golden Casket Top

To make it easier for you to identify emails from Golden Casket, we will address emails we send to you with your name, so for example, "Dear Mr Smith and Ms Smith". But there are some things we will never do;

  • We will NEVER;
    • request personal details from you by email
    • request you to confirm your Winners Circle On-line logon details by email
    • Ask you to update your personal details by email
    • send you a link in an email, which links you to a login page.

  • You should treat all emails which are requesting your personal information, logon details or password details with extreme caution
  • Any emails you receive which appear to be from Golden Casket and are asking you for this information, could be an attempt at Phishing. We recommend you call Golden Casket immediately on 131 868 or email us at playersupport@goldencasket.com - We are more than happy to answer your security questions and concerns or review emails to confirm their authenticity. We may request you to forward the email to us - otherwise you should delete the email.
  • All emails and mail sent to you by Golden Casket will come from 'Brendan Hodgkinson' at Golden Casket player support (playersupport@goldencasket.com) as the sender. This is another way you can check the sender information is correct when you receive email as a way to ensure it's coming from Golden Casket.

2. Choose a Secure Password Top

The Winners Circle On-line and Lotto Direct sections of www.goldencasket.com use a password system requiring you to use both numbers and letters in your password. This is to ensure that the password is hard to guess.

  • Most importantly, never give out your password and card number to someone asking for this information by email. Golden Casket will not ask you for this information by email.
  • Do not give your password to anyone else, including family, friends or someone else asking you for this information. Golden Casket will not ask you for your password.
  • When thinking of a password to use, you should use a password that doesn't use any of your personal information (eg. your name or date of birth) which might make it easier for someone to guess.
  • You should also change your password regularly.

3. Check Encryption Top

  • Winners Circle On-line and Lotto Direct use 128 bit Secure Socket Layer (SSL) encryption technology, which is common security technology on websites which ask you to provide sensitive or personal information.
  • Encryption involves scrambling information between the user (you) and the host (us) making it very difficult for parties who try to intercept this information to read or change it.
  • When visiting Winners Circle On-line and Lotto Direct you will be operating in this SSL environment. An easy way to tell this is by looking at the navigation bar which will appear as https://www.goldencasket.com/... The "https" denotes that SSL encryption is active.
  • The other way to check is to look for the padlock icon in your browser which denotes an SSL transaction. You can double click on the padlock icon for more information about the Digital Certificate to ensure it is from Golden Casket.
  • What does the digital certificate look like -
    Internet Explorer users
    - Firefox & Netscape users

4. Install a Firewall on your home PCTop

  • To provide additional security for your personal computer, we strongly recommend using Firewall software for your computer, especially if you have an 'Always On' broadband connection.
  • A firewall is software for the home user (or can be hardware) which filters the traffic between your computer and the Internet. It is configurable by you, and helps to block or allow Internet traffic to and from your computer.
  • For more information on purchasing or setting up a firewall, you can visit some of the major providers of this software including Symantec and McAfee.

5. Use the LOGOUT function Top

  • When you are finished using Winners Circle On-line or Lotto Direct we encourage you to use the LOGOUT function, to protect against other people accessing your personal information if you walk away from the computer.
  • If your session is dormant for a period of time, our system will automatically Log you out and you will be required to log back in. This is to help ensure that no-one can access your personal information if you walk away from the computer.
How to Login Safely

Special precautions for public places Top

  • When in a public place, always type www.goldencasket.com into the browser
  • Winners Circle On-line and Lotto Direct allows you to 'Remember Me' which is a handy function when logging on at your next visit to the site. When using Winners Circle On-line or Lotto Direct from a Public Computer, we don't recommend selecting this option as the next user may be able to see your logon details.
  • ALWAYS LOG OUT after using Winners Circle On-line and Lotto Direct. Even though there is an automatic time-out on your session, this may still allow another user to gain access to your personal details.
  • Logon to Lotto Direct and Winners Circle On-line by visiting www.goldencasket.com
  • For extra security, you should type the goldencasket.com web address directly into your browser or bookmark our site and add it to your favourites. This is good practice to ensure you always visit the authentic Golden Casket website.
  • When visiting the Winners Circle On-line and Lotto Direct, you will be operating in an SSL security environment so always check that "https" appears in the navigation bar and that a padlock icon appears in your browser to denote an SSL transaction. To check the authenticity of the website you are visiting, you can double click on the padlock icon for more information about the Digital Certificate to ensure it is from Golden Casket.
  • If either the https or padlock are missing, close your browser and reopen a new browser, typing www.goldencasket.com into your new browser.

What does a Digital Certificate look like? Top

Internet Explorer users

Firefox and Netscape users


6 Tips for safe online purchasing
  1. Logon to Lotto Direct by visiting www.goldencasket.com (for extra security you should type it into your browser or bookmark our site)
  2. Never respond to an email which asks for your personal or logon information. Golden Casket will not ask you for this information by email. If you receive an email which looks suspicious, email us at playersupport@goldencasket.com
  3. To help identify emails from Golden Casket, look for emails which are addressed to you personally, eg Dear Mr Smith and Mrs Smith
  4. Never click on a link asking you to login. We will not send you a link to a Lotto Direct login page.
  5. When logging into Lotto Direct, check for " https" in front of our web address and click on the padlock icon to check the digital certificate is from www.goldencasket.com.
  6. Install virus protection software and firewall software to protect your computer.
Internet Security Threats & Lottery Scams

Phishing & hoax emails Top

  • Phishing is where a user receives a hoax email which looks like it comes from a trusted organisation such as Golden Casket, but is actually from a fraudulent third party.
  • These emails usually ask the user to logon to the website and confirm their personal or logon details, often for, 'Security Reasons'.
  • When the user does this, they are unwittingly keying their personal or log on details into a fake website. This enables the third party to utilise this information for fraudulent purposes.
  • Golden Casket will not request personal details or log on information from you by email. You should treat all emails which are requesting your personal information, logon details or password details with extreme caution.
  • If you receive an email such as this, which might be requesting re-registration or re-entry of personal details, or your urgent action for some other reason, and it appears to come from Golden Casket, you should immediately notify Golden Casket on 131 868. We may then request you to forward the email to us - otherwise you should delete the email.
  • In addition to this, there are a number of things you can do to minimise the chance of you being a victim of Phishing Scams. These include:
    • Logon to Lotto Direct and Winners Circle On-Line by visiting www.goldencasket.com.
    • For extra security, you should type the web address directly into your browser or bookmark our site and add it to your favourites. This is good practice to ensure you always visit the authentic Golden Casket website.
    • Check that the email is from Brendan Hodgkinson or PlayerSupport at Golden Casket player support (playersupport@goldencasket.com)
    • If you are in doubt about the authenticity of an email, delete it, call us on 131 868 or email us at playersupport@goldencasket.com.
    • Ensuring your Virus Protection software is up to date may also help.

Viruses, worms & trojan horses Top

  • Viruses can attack your computer from many sources including email attachments, so it is very important you don't open emails from unknown sources. It's especially important you don't open email attachments which you are not expecting or which come from sources you do not trust.
  • Worms are destructive programs that replicate themselves throughout your computer, sometimes by exploiting security vulnerabilities in the operating system.
  • A Trojan Horse is software that at first glance will appear to be harmless software but will actually do damage once installed or run on your computer. Trojans can introduce viruses and leave your computer vulnerable to attacks by hackers and intruders.
  • You can reduce your chances of being affected by viruses, worms and trojan horses by:
    • Deleting emails from unknown sources, without opening the emails.
    • Not clicking on links contained within emails of unknown sources.
    • Keeping your anti-virus software up-to-date and ensuring it is set to conduct regular scans of your computer.
    • Using a firewall to monitor Internet traffic to and from your computer.
    • Regularly updating your operating system with security patches provided by the vendor (usually available on the internet).

Spyware Top

  • Spyware is software which can be automatically loaded onto your computer without you knowing, when you visit websites or install new applications that may secretly contain it. It collects your personal information and can secretly send this information to a third party.
  • Products are available which help detect and remove spyware from your computer.
  • A good way to minimise the chance of unintentionally downloading spyware onto your computer is by using an anti-spyware program to scan your computer for this software. Many current Internet security software products come with this functionality built in. You should also regularly install security patches for your operating system.

Computer security Top

  • To help ensure your computer system is secure, you should check with your software vendor for software updates regularly, in particularly for operating systems. For example, Microsoft regularly issues security upgrades/patches for the Windows operating system to guard users against identified security threats.

Lottery Scams Top

The chance of winning big money in a lottery is a key strategy used by lottery scams worldwide. Keep in mind that if you "are the winner" and you are asked to "pay money" to receive your prize, you are most likely looking at a scam.

It has been brought to Golden Casket's attention that unauthorised operators based overseas, are representing themselves as Golden Casket or as Golden Casket International agents.

In communications, they advise that the recipient has won a large prize. To claim the prize, the recipient must send further details to the bogus "International Claims Agent", so that the prize can be claimed. The recipient is eventually asked to deposit a cheque into his or her bank account and then pay a fee (for processing or handling the international claims paperwork) before the prize can be collected.

This type of scam is known as an "Advance Fee Fraud". Advance fee frauds such as the Nigerian-style scam, ask you to provide money or your bank account details to facilitate the transfer of money.

  • DO NOT ever consider handing over this information to someone you do not know or trust.
  • DO NOT respond to any offers.

Please note that unless you have purchased a Golden Casket entry in Queensland, Australia, any correspondence you have received purporting to be from Golden Casket and advising you that you have won a prize, is a scam.

You are welcome to check with us by emailing us at playersupport@goldencasket.com or by phoning us on 131 868. You can call this number from a mobile (+ 61 7 3877 1000).


* Lotto Direct will be unavailable Christmas Day, Easter Sunday and during system maintenance.
BPAY® Registered to BPAY Pty Ltd ABN 69 079 137 518

  Have Fun & Play Responsibly
© Golden Casket Lottery 2007 - A Tatts Group Company