Has NRMA Had a Data Breach That They've Yet to Disclose?

Like many Ozbargainers, I signed up for NRMA for free a few years ago and have enjoyed free membership since.

Starting a few weeks ago, I've began to receive phishing emails impersonating NRMA. I've raised the question with NRMA directly but have yet to receive a response.

Has anyone else had their spam folder filled with these NRMA scam emails?

Related Stores

NRMA Insurance
NRMA Insurance

Comments

  • +18

    You are probably incorrectly associating your membership with receiving these emails.

    Most likely they are just spamming this scam attempt in the hopes that someone receiving it has an NRMA account and clicks on the links.

    Same with the toll SMS scams. They don't know you have a toll account, but are just hoping you do and click on it.

    • -6

      Don't get me wrong, I understand the difference between phishing and spear phishing. These emails feel like they're part of a spear fishing attack, but I could be wrong. That's why I've asked the question to see if other members are experiencing the same thing or not.

      • +7

        I get emails about my Telstra account all the time, even though I don't have one. I also get spam phone calls about my Amazon parcel being stuck in customs and also Australian Immigration Dept, apparently there is some problem with my student visa.

        FYI, I have a current NRMA membership, I haven't received any phishing email in my spam folder.

      • -1

        I am an NRMA member and no.

        It's very unlikely you are ahead of the curve and picked up on an undisclosed data leak by NRMA.

        This is like when people get ads for diabetes medication and swear their google home is listening to them beacuse they mentioned it earlier at home. You're creating links that aren't there.

        • texas sharpshooter I believe?

  • -2

    It's pretty clear by the hits I got, you didn't do a decent (if any) search.

    • -2

      I searched Google and OzBargain, is there another place or way of searching that meets your benchmark?

      • -1

        Well the list I saw with that search had 2 FB book pages mentioning emls and recent dates. What did Google tell you and what search term did you use?

  • Has NRMA had a data breach that they've yet to disclose?

    If they have, and it's undisclosed, how would we know?

    If an OzBargainer works for the NRMA and disclosed such information, their employment would be terminated very quickly, so the chance of them answering in the affirmative would be zero.

    • Has anyone else had their spam folder filled with these NRMA scam emails?

  • +1

    Checked https://haveibeenpwned.com/ ?

    Impersonation emails aren't generally linked to the company. It's normally a breach elsewhere and whoever has the email sets up well known companies templates and goes from there.

    I was affected by Shopback's data breach but I haven't gotten a single email claiming anything wrong with my Shopback account (which I deleted.) But pretty much I have apparently win a prize from every Australian business on a daily basis for the past several months. I get anywhere from 1 to 4 emails daily claiming to be from Coles/Woolworths/Chemist Warehouse/Supercheap Auto/Priceline/NRMA/some tire company in Sydney.
    They all contain the exact same email format go to the same link.
    With a "You have won a prize for being the best customer. Just fill out the survey use the promo code Coles23 for example and pay for postage and the prize is yours."

    I set up a filter to auto delete them. So all I see is yep got 2 today and it was Coles and Priceline and now they are gone type of thing. :)

  • Has anyone else had their spam folder filled with these NRMA scam emails?

    I've been getting lots of Microsoft ones in recent weeks.

  • +1

    You have zero evidence.

    If you were using the Gmail + trick I might support you, but your post has no argument

  • +2

    How have you managed to get free NRMA for a number of years?

    • +1

      haha my thoughts exactly

  • +1

    OP my advice would be to change your password and move on.

    And if it does turn out they really did have a breach, be sure to come back here and rub our faces in it :)

  • +4

    Yes, and they were sent to my email aliases which were used for my Tangerine accounts.
    I usually create unique aliases for each service. I haven't received any spam for my NRMA alias.

  • I have been getting a huge (for me) number of phishing emails starting from a couple of months ago. Mainly purporting to be from Microsoft and Google saying my account is going to be shut down, or I have viruses. But there have also been ones purporting to be from NRMA saying I've won a car kit, except the address in the email is a British one!

    Also today for the first time I just received one purporting to be from Woolies saying I've won "an 36 piece" Tupperware set.

  • I renewed my car insurance with NRMA a couple of weeks ago. Since then I receive daily NRMA spam.

  • I have received multiple fake NRMA emails recently and have never been a NRMA member.

  • Yes I am a regular winner of an nrma car tool kit. No idea what I did suddenly getting them daily and heaps of 'microsoft' and 'google' warning'. Reporting them all as junk and blocking but more come.

  • I last held an NRMA policy about ten years ago. Have been recently receiving spam emails pretending to be from NRMA but they don't come to the email address I used with NRMA. Apparently I've won a number of car emergency kits :-)

Login or Join to leave a comment