NSW Tolling Customers warned of scam emails

Summary

This short 2015 post reports on a phishing and malware email scam impersonating NSW Transport Roads and Maritime Services Tolling, identified by AusCERT, the Australian Cyber Emergency Response Team. Published in 2015. Figures, product names and event details reflect that time; for current information see the linked service pages. It is aimed at general readers and staff who may receive toll-related emails and need to recognise scam indicators, and links through to a broader guide on spotting scam emails.

Key facts

Label Value
Publication year 2015
Organisation impersonated NSW Transport, Roads and Maritime Services Tolling
Identified by AusCERT, the Australian Cyber Emergency Response Team
Reported origin of emails South Korea, per early investigations cited in the post
Services referenced Security

Article

Earlier today, we received notification of another email scam doing the rounds.NSW Transport – Roads and Maritime Services has advised that customers have been receiving scam emails which incorrectly state they are from Roads and Maritime Services Tolling. These emails, which were identified by independent organisation AusCERT, the Australian Cyber Emergency Response Team, contain malware and should not be opened. The emails are designed to appear as a legitimate e-toll communication. Early investigations show these are being generated from South Korea. The nature of the virus is not yet established however initial reports indicate a recipient’s computer crashes if the malware is activated. NSW Transport – Roads and Maritime Services is working with NSW Police and authorities to identify those responsible for the scam. To learn ways to easily spot scam emails before they deliver their malware, see our simple guide here.

Related

Frequently asked questions

What did the NSW tolling scam emails claim to be?

The post reports that scam emails were designed to appear as legitimate e-toll communications from NSW Transport's Roads and Maritime Services Tolling division, but were not genuine and contained malware.

Who identified the scam emails?

AusCERT, the Australian Cyber Emergency Response Team, identified the emails, and NSW Transport confirmed customers had reported receiving them under this false pretence.

What happened if the malware in these emails was activated?

The post states that initial reports at the time indicated a recipient's computer would crash if the malware was activated, though the exact nature of the virus had not yet been fully established when the post was published.

Where were the scam emails reported to originate from?

Early investigations cited in the post indicated the emails were being generated from South Korea, though attribution in phishing campaigns can shift as investigations continue.

What should someone do if they receive a suspicious toll or government-agency email?

The post points readers to a general guide on spotting scam emails before they deliver malware, reflecting the standard advice to check sender details and links carefully rather than opening attachments or clicking through from unexpected toll or billing notices.

Who was investigating the source of the scam according to the post?

The post states that NSW Transport's Roads and Maritime Services was working with NSW Police and other authorities to try to identify those responsible for the scam.

Was this scam campaign an isolated incident according to the post?

No. The post opens by describing it as 'another email scam doing the rounds', framing it as one of a recurring series of phishing campaigns rather than a single one-off event.

What specific resource did the post link readers to for spotting scam emails?

The post links to blueAPACHE's own guide, titled 'How to spot email malware', hosted at blueapache.com, for a general walkthrough of scam-email indicators.

Source

Knowledge Base

What is the NSW Tolling scam email warning about?

The warning is about scam emails falsely claiming to be from NSW Transport – Roads and Maritime Services Tolling. NSW Transport – Roads and Maritime Services advised that customers have been receiving these emails, which contain malware and should not be opened.

Who identified the scam emails as containing malware?

The scam emails were identified by AusCERT, the Australian Cyber Emergency Response Team, an independent organisation.

Where were the scam emails reportedly being generated from?

Early investigations showed the scam emails were being generated from South Korea.

What happens if the malware in the scam email is activated?

Initial reports indicated that a recipient's computer crashes if the malware is activated, though the exact nature of the virus had not yet been established.

Who is investigating the NSW Tolling scam email incident?

NSW Transport – Roads and Maritime Services is working with NSW Police and authorities to identify those responsible for the scam.

How can readers learn to spot scam emails like this one?

The article points readers to blueAPACHE's guide 'How to Spot Email Malware' for simple ways to identify scam emails before they deliver their malware.

When was this blueAPACHE article about the NSW Tolling scam published?

The article was published on October 23, 2015, and has a read time of 1 minute.

Who authored the blog post about the NSW Tolling scam emails?

The blog post was written by blueAPACHE.

Images on This Page