Breaking Australian immigration news brought to you by Migration Alliance and associated bloggers.
URGENT NOTICE RE MY IDENTITY
Migration Agents may receive an email from a person pretending to be me from an email address which is not mine. The email looks like it is from Liana Allan. The fake email being used to pass off as me is This email address is being protected from spambots. You need JavaScript enabled to view it. . So far I can verify that an email has been sent out from a person masquerading as me to other migration agents offering to auction the databases for websites I am involved with:
1/ Migration Alliance
2/ Legal Training Australia
3/ Visacorp
As you are aware, Migration Alliance was recently down as a result of serious security concerns. I would like to warn all agents not to engage with a person calling themselves 'Liana Allan' on an email other than my own. These email addresses are the email addresses I actually use:
This email address is being protected from spambots. You need JavaScript enabled to view it.
This email address is being protected from spambots. You need JavaScript enabled to view it.
This email address is being protected from spambots. You need JavaScript enabled to view it.
This email address is being protected from spambots. You need JavaScript enabled to view it.
The following email is not from me and should be regarded with the utmost caution:
This email address is being protected from spambots. You need JavaScript enabled to view it. (Delete or report this email - this is not my email address).
I note that this person has sent emails to numerous migration agents including my own staff, offering to auction off 'for sale full databases "migrationalliance", "legaltrainingaustralia" and "Visacorp" information here.
Office of the MARA notice today 14/11/2013
This is an automated email.
-------------------------------------------
Dear Registered Migration Agents
The Authority has received requests from agents as to how to deal with SPAM or suspicious emails in view of some recent incidents. There is no need to refer SPAM emails to the Authority as we are aware of the problem and have notified the appropriate agencies.
The best advice we can give you is the same message that is generally given about cyber security:
- Make sure you have antivirus software installed and that the virus definitions are kept up to date. This is best done by setting the software to automatically update.
- Make sure your software patching is kept up to date, especially your operating system (i.e. Windows or Apple iOS), your web browser, and other supporting software from Adobe, Java or anything that may take information from the internet.
- And be very careful opening suspicious emails. Do not click on links within emails or open attachments if the message is suspicious.
There is some good general advice here:
www.staysmartonline.gov.au
http://www.asd.gov.au/publications/csocprotect/socially_engineered_email.htm
If you have particular concerns about the volume of spam getting through, you could try talking to your internet service provider (ISP). Sometimes there are things that can be done by your ISP to control spam. You need to ask about "spam filtering".
Finally, if you think your business IT systems have been compromised you should contact the Computer Emergency Response Team (CERT) at www.cert.gov.au immediately. If nothing else, the reporting of your issues gives CERT an idea of the bigger picture.
Kind regards,
Office of the MARA
++++++++++++++++++++++++++++
If you receive any further emails I suggest that you inform the Office of the MARA as it would appear the entire profession is being bombed by spam. The person or people behind this are pretending that these emails are coming from my companies or me. This is not the case. If you receive any suspicious looking emails written in poor English then post them up here on the blog in comments. I am not offering anyone any databases, products, security services etc. Thanks Judit. I received the same email with the same phone numbers. Our IT team have told me it is pretty easy to buy mobile numbers.
This is getting ridiculous and is most annoying - I received at least 30 emails of the same sort since last night. Can you please ask your IT department to fix this issue ASAP as obviously your system has been hacked? What happened with my personal data stored in your system? Are they safe? Doesn't look so...
Hi Martin
Yes, it is annoying. I have had my identity stolen and this person / people are pretending to be me and pretending to send emails from my email address. I am not that person. The Australian Government CERT is onto it and our IT people are working on it. The DIBP IT Security have been notified as has the Office of the MARA CEO. This is a sustained industry-wide attack. The emails might appear to come from me. The hacker is in fact listing himself as www.yarolinux.co
As soon as I have any information at all I will post it up here.
If you receive any more emails please report it to the police, OMARA etc. You are not alone.
Once we can determine whether this hacker actually has our databases, and is not using generic emails located on the OMARA website we can advise the profession. At this stage it is not clear whether this is a hoax to extort money out of the entire profession.
Hopefully you can empathise with me as I have had my name hijacked.
My email address is NOT visacorp.sydney@gmail.com
I have copped more than 200 in last 2 days. Nobody expecting a sale does this; it is for nuisance value only. Any guesses who might do this? First name Eddy [and it ain't Obeid] who is welcome to continue to attack me as much as he likes. I will respond in like and give a little taste of a real Singapore Sling. Delete works just fine!
Office of the MARA email today: 14/11/2013
This is an automated email.
-------------------------------------------
Dear Registered Migration Agents
The Authority has received requests from agents as to how to deal with SPAM or suspicious emails in view of some recent incidents. There is no need to refer SPAM emails to the Authority as we are aware of the problem and have notified the appropriate agencies.
The best advice we can give you is the same message that is generally given about cyber security:
- Make sure you have antivirus software installed and that the virus definitions are kept up to date. This is best done by setting the software to automatically update.
- Make sure your software patching is kept up to date, especially your operating system (i.e. Windows or Apple iOS), your web browser, and other supporting software from Adobe, Java or anything that may take information from the internet.
- And be very careful opening suspicious emails. Do not click on links within emails or open attachments if the message is suspicious.
There is some good general advice here:
www.staysmartonline.gov.au
http://www.asd.gov.au/publications/csocprotect/socially_engineered_email.htm
If you have particular concerns about the volume of spam getting through, you could try talking to your internet service provider (ISP). Sometimes there are things that can be done by your ISP to control spam. You need to ask about "spam filtering".
Finally, if you think your business IT systems have been compromised you should contact the Computer Emergency Response Team (CERT) at www.cert.gov.au immediately. If nothing else, the reporting of your issues gives CERT an idea of the bigger picture.
Kind regards,
Office of the MARA
++++++++++++++++++++++++++++
After I received some 150+ emails from this guy, I wrote to him and asked him to show me proof that he has indeed the databases and what sum he has in mind for selling them…..
No reply as yet but maybe he will contact me, considering that I am offshore.
Will keep you posted here if anything happens…
What do you know!!! I have just received this message from our hacker:
QUOTE
-------- Original Message --------
Subject: Price List
Date: Thu, 14 Nov 2013 03:43:16 -0500
From: Liana Allan
To: office@emigrez.ro
Greetings, the full database contains all the information of the agents and users of these sites more than 1000 lines.
database migration alliance - 1000 dollars.
database legal training Australia - 1000 dollars.
database visacorp - 1000 dollars.
other services - negotiable.
databases containing over 10,000 lines of information migration agents.
The method of payment is paypal or bitcoins.
Thank you
UNQUOTE
Liana, maybe you can ask someone at CERT to contact me and we can follow up this matter?
Liana, some MAs I talked to were concerned about their Credit Card details which they used for paying CPD and Conferences. Can you please let us know if information about Credit Cards was stored in the stolen databases? In this case we should advise our Banks to cancel the Credit Cards.
Hi....just received an email for computer security work and also that he/she accepts donation....