SIMON SMITH

ALIAS
"eVestigator" · self-described "world renowned cybersecurity expert with 21 years of experience" — his description, as reported SELF-DESCRIBED [2]
OPERATION
eVestigator, a computer-forensics consultancy, Melbourne · evestigator.com.au · mobile apps on the Apple and Google marketplaces
HABITAT
Twitter, LinkedIn, and the Personal Safety Intervention Order dockets of the state of Victoria
RECORD
Applied for restraining orders against three men — two of them working in cybersecurity — from Aug 2017 FACT [2]
DISPOSITION
His PSIO application against George Stewart: withdrawn after consideration by the court, Nov 2017 ADJUDICATED
STATUS
STILL OPERATING — the practice site is live, offering digital-forensics and expert-witness services FACT
A world renown leading Cybercrime White Hat Hacking Master Programmer and Cyber Security expert… a child genius at the age of 11 years old, inventing and programming.

Simon Smith (“eVestigator”), describing himself on his own site. When Australian infosec analysts questioned the credentials, BankInfoSecurity reported he pursued restraining orders against them. The self-assessment is his; you weigh it. His own site.

The specimen, observed 2016–2017 across Twitter, LinkedIn, and the courts of Victoria, describing itself as world-renowned. The field submitted bug reports. The specimen submitted paperwork.

What you are about to observe is a territorial response of unusual speed. Most organisms in this ecosystem, when a researcher points at a flaw in their construction, repair the construction. This one reached for the filing window. The interval between bug report and legal threat, in the best-documented instance, was a single day.

It is impossible for a normal functioning human to keep track of who was served what. That is why the archive exists. Every event below carries its receipt. Both sides get the microphone.

the drama timeline

ACT I — THE SELF-STYLING (2016–2017)

The display precedes the contest. Watch the plumage assemble: a brand with a registered mark, a superlative, a storefront on two app marketplaces.

  1. 2016–2017

    The eVestigator brand

    Smith runs a Melbourne computer-forensics consultancy under the "eVestigator" brand and describes himself as a "world renowned cybersecurity expert with 21 years of experience," investigating fraud, dating scams, and stalking. He is very active on Twitter and LinkedIn, and his posts begin to draw broader attention within the information security community — which digs into his background and starts pulling apart the mobile apps he published to Apple's and Google's marketplaces. The counter-file that becomes the attrition.org dossier opens with the field's question: elaborate troll, or a person doing business in the security industry?

ACT II — THE DISCLOSURES (JUN–JUL 2017)

Then the field does what the field does to any loud new display: it takes samples.

  1. JUN 22 2017

    Ellis publishes the authentication findings

    Geoff Ellis, a Brisbane network administrator, posts an article on LinkedIn reporting two security vulnerabilities and a potential personal-information leak across three of Smith's apps: eVestigator Forensic PenTester, SKILLS.com.au Industry App, and Virtual Postage Australia. His account of what followed: "I posted an article regarding these vulnerabilities, and a month later he started sending me legal threats."

  2. JUN 25–26 2017

    One day, notification to threat

    A penetration tester posting as @InterN0T notifies Smith of a remote code execution via man-in-the-middle vulnerability in eVestigator Forensic PenTester — and, per the bug report, receives "several threats of prosecution" the same day. The app is pulled from Google Play the next day. The researcher publishes within days instead of the customary 30, citing the threats; he tells ISMG he stands by the report: "These vulnerabilities are quite common."

    Standard practice in this ecosystem allots thirty days for repair. The specimen compressed the entire disclosure lifecycle into one afternoon, skipping only the repair.

  3. JUL 3 2017

    The Register publishes — then unpublishes

    The Register runs a story on the findings. The story is later taken offline; contacted by ISMG, The Register declined to say why.

ACT III — THE ORDERS (AUG–NOV 2017)

Cornered organisms choose fight or flight. This one chose the Magistrates' filing window — where applying is free and defending runs into the thousands.

  1. AUG 2017

    The demand letter

    Bryan Onel, an Amsterdam-based penetration tester who reported a cross-site scripting flaw in Smith's website, gets a reply asserting he is in breach of the Australian Crimes Act of 1958 — then a letter from Sydney firm Neat Law demanding AU$14,500 for reputational damage and legal costs. Neat Law confirms it sent the letter. Onel doesn't pay: "It became very obvious quite quickly that anyone who engages against Simon, Simon retaliates against." Smith's position on Onel, verbatim: "He's off to jail. Bryan is probably the worst criminal I have ever met in my entire life. That's not me saying it. That's fact." No court in the record we hold has convicted Onel of anything.

  2. SEP 2017

    The intervention orders land

    Ellis is served with an interim Personal Safety Intervention Order in mid-September — the order is reproduced in ISMG's report. A PSIO against George Stewart, a Canberra consultant who had mocked Smith's handling of the vulnerability report, is approved the same month. On September 10, Troy Hunt receives two tweets from Smith — one saying he'd "crossed the line," another advising that he and four others had been sent a summons. Both tweets are later deleted. Hunt: "I'm perplexed as to how I've been dragged into this. I've never had any interaction with Simon either before that threat or since." Smith says he doesn't remember what prompted the tweets.

    Note the economics of this maneuver, as the local guides explain them: the application is free. The defense retains counsel. There is very little downside for the party at the window.

  3. NOV 15 2017

    One order withdrawn; the field goes on record

    Smith's PSIO application against Stewart is withdrawn after consideration by the court. Stewart, who denies stalking or harassing Smith and whose costs ran into the thousands: "I'm glad it's over and I hope this can be the end of it." The same day, Jeremy Kirk's investigation runs on Bank Info Security. Jake Williams — SANS instructor, former NSA Tailored Access Operations — goes on record: "You've crossed a different line when you take it to court… He's hurting the infosec field, and that's where I draw the line."

  4. EPILOGUE

    The file stays open

    Attrition.org adds Smith to the Charlatan List — the errata project's file cites the restraining-order reporting and the critic archive. The research file's status column reads: unknown. His practice site remains live today, offering digital-forensics and expert-witness services. The archive keeps the tape running.

both sides, on the record

The researchers' findings (theirs, not ours): authentication problems and a potential personal-information leak in three apps; remote code execution via man-in-the-middle in eVestigator Forensic PenTester. The app left Google Play the day after notification [2].

The documented response: "several threats of prosecution" the same day, per the bug report; legal threats to Ellis, per Ellis; a Crimes Act claim and a confirmed AU$14,500 demand letter to Onel; PSIO applications against three men, two of them cybersecurity professionals [2].

The adjudicated item: the one application contested through to the court's consideration — Stewart's — was withdrawn [2]. And the field's own characterization, on the record: "He's hurting the infosec field" [2]; "arguably one of InfoSec's most prominent charlatans to appear in 2016/2017" [1] [3].

Smith says he is the victim. He contends he has been harassed and stalked by a group he terms "criminals" seeking to belittle him and damage his reputation: "I have a right to defend myself. I don't deserve what they're doing to me. It's immature and disgusting" [2].

And the mockery was real. As his postings drew attention he became a target for memes — one posted photo defaced with crude genitalia, another likening him to Hitler — personal, ugly, and reported in the same article that reports everything above [2]. He denies attacking anyone over mere disagreement: "Never ever do I care if anyone disagrees with me. I only care if they attack me."

He contests the findings. The apps, he says, were just prototypes, and he disputes the RCE report outright — "InterN0T is a [expletive] liar" [2].

Scope of the record: a PSIO is a lawful civil remedy open to anyone, and a magistrate initially granted the Stewart order before it was withdrawn. Nothing here is a finding against Smith — no court has ruled his expertise claims false, no vulnerability report has been adjudicated, and he has been convicted of nothing in the record we hold. His practice operates today [4].

YOU DECIDE

Scoped to the claims, never the man. The claim "world renowned cybersecurity expert" rests on its bearer's word. Weigh it against the documented data points: a bug report answered with same-day prosecution threats, an app off Google Play within twenty-four hours, restraining-order applications against the researchers — and the one application tested before a court, withdrawn.

Weigh the costly signals: Stewart paid thousands to contest an application that cost nothing to file. The researchers published under threat and stood by their findings. Smith's practice never stopped trading.

The archive does not judge. The archive merely keeps the tape running.

evidence locker

PRIMARY RECORD

  1. Attrition.org — Simon Smith charlatan file FACT — the errata project's entry: the field's characterization, the dated index, the pointers to the reporting and the critic archive. attrition.org/errata/charlatan/simon_smith/
  2. Bank Info Security — "Australian InfoSec Analysts Hit With Restraining Orders" (Jeremy Kirk, Nov 15, 2017) ATTRIBUTED — the load-bearing investigation: the PSIOs, the vulnerability reports, the demand letter, and Smith's own side, quoted at length. bankinfosecurity.com/australian-infosec-analysts-hit-restraining-orders-a-10455

THE CRITICS' ARCHIVE

  1. eVestigatorsucks.com — pseudonymous critic archive ATTRIBUTED — the tracking site cited by the attrition file and named in ISMG's reporting; its characterizations are its own, adopted by no one here. evestigatorsucks.com

SUBJECT'S OWN CHANNELS — THE SPECIMEN, UNEDITED

  1. evestigator.com.au — "Simon Smith: Australian Digital Forensic IT, Cybercrime and Expert Witness Practice Hub" SELF-PUBLISHED — the operation, in its own words, still open for business. evestigator.com.au
  2. X — live search: "eVestigator" "Simon Smith" LIVE SEARCH — the discourse, ongoing. Account-level and search links only; no fabricated permalinks, and the deleted tweets are not linked. x.com/search?q=%22eVestigator%22%20%22Simon%20Smith%22
The standard. Everything above is sourced to named press reporting, the attrition.org documentary file, and the subject's own published material. Facts are stated as facts; accusations are stated as accusations and wear their accuser. The vulnerability findings belong to the researchers who published them, not to a court, and Smith's rebuttals run at full strength — including the mockery he faced, which was real. No motive is asserted, no private character diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.