Between 17 August and 1 September, a group that had posted its first victim on 7 August listed six Australian businesses on its leak site. Westco Motors in Cairns. Ramsey Bros, a farm machinery dealer in Cleve, South Australia. Penfold Motors in Victoria. Sharp Motor Group in Tweed Heads. Agrimac in Warrnambool. Macquarrie Corporation, a machinery management business, also in Victoria.
Car dealers and machinery suppliers, one after another, across four states. That is not six separate intrusions. That is one.
On 15 September, Auto-IT confirmed it. The Australian company makes dealer management software for the automotive, agriculture, trucking and construction trades. It told Cyber Daily that a small number of its customer environments had been compromised through unauthorised access to a third-party remote monitoring and management tool, and that it had engaged the and the affected customers directly.
What the dealerships said
Three of the six have confirmed an incident tied to an outside provider. Penfold Motors described an unauthorised party gaining access to Penfold data "stored in the software provider's system", said the information was "limited to basic contact details and vehicle and servicing information", and said it had notified the people involved, the ACSC and the . Sharp Motor Group confirmed its third-party IT provider was involved in a cyber incident. Macquarrie is investigating.
The others have not commented publicly, and Storm's claims about them stand unverified. Storm does not publish how much it took or what it wants. It publishes a dozen or so documents as proof and lets the reader draw conclusions. The samples so far have included payroll data, customer invoices, vehicle identification numbers, driver details, and in one case scans of staff passports and driver's licences.
The part that applies to you
Most businesses have at least one vendor with standing remote access to their systems. The practice management platform. The dealer system. The payroll provider. The managed service provider, which is a category we sit in ourselves. Each of those runs a remote monitoring and management tool, because that is how support works at any scale, and each of those tools is a door into every customer the vendor has.
When that door is forced, the vendor's incident becomes yours. Your customers' details are on a leak site under your name, the notification obligation under the sits with you as much as with the supplier, and the customers ringing your front desk have never heard of Auto-IT.
The dealerships in this story did nothing unusual. They bought industry-standard software from an established vendor. That is what makes it worth writing about. We said last month that ransomware affiliates scan for a weakness, not for a company. A vendor's support tool is a weakness with thirty companies behind it.
Questions worth asking this week
Ask each vendor with remote access how that access works. Which tool, who at the vendor can use it, whether it needs , and whether it is on all the time or opened per session. A vendor who cannot answer within a day is telling you something.
Ask what you would see if the vendor's access were being misused. In most environments the answer is nothing, because the vendor's tool is trusted by design and its activity is not logged anywhere you look. That is the gap an attacker with the vendor's credentials walks through, and it is the reason monitoring has to cover the trusted paths as well as the obvious ones.
The contract matters too. Ask what it says about notification. Penfold disclosed on 7 September, three weeks after its name went up on the leak site on 17 August. Some of that gap is investigation. Some of it is the time it takes to find out from a supplier what happened to your data. You want that timeline in writing before you need it.
And ask who owns the response when the intrusion was not on your network. Restoring systems is the vendor's job. Working out which of your customers are affected, what to tell them, and whether you have a reporting obligation is yours. The dealerships that handled this well were the ones that "activated our ", to use Penfold's words, rather than waiting for the vendor to tell them what to do. If you do not have a plan for a breach that starts somewhere else, that is the one to write.
Storm has been listing victims since 7 August. It will not be the last group to find that the shortest route into thirty businesses is the one company they all pay a subscription to. The listings, as they are confirmed or corrected, are on the Australian Data Breach Tracker.
If a vendor is breached, do we still have to notify?
Yes, if you hold was involved and the breach is likely to result in serious harm. The scheme applies to the entity that holds the information. A contract with a supplier does not move that obligation.
Should we cut off vendor remote access?
No, but you should know exactly what it is and be able to switch it off in an hour. Per-session access with multi-factor authentication and logging is the standard to ask for.



