Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Exclusive: Aussie software firm Auto IT confirms customers compromised by Storm ransomware attack

Maker of dealer management software responds to darkweb hacking claims, says “small number of Auto-IT customer environments” impacted by an unauthorised external party.

Tue, 15 Sep 2026
Exclusive: Aussie software firm Auto IT confirms customers compromised by Storm ransomware attack

The Storm ransomware group has caused a trail of destruction across the country, claiming to have compromised more than a half dozen car dealerships and heavy machinery suppliers over the last month.

Several of the dealers in question have alluded to the compromise of a third-party IT supplier being the source of the compromise, which Cyber Daily can now reveal was Australian software company Auto IT.

“We can confirm that a small number of Auto-IT customers were named by an unauthorised external party on a dark web listing site, in which the external party claims to have accessed data relating to their businesses,” an Auto IT spokesperson told Cyber Daily.

 
 

“This relates to a security incident that affected a small number of Auto-IT customer environments, and involved the unauthorised use of a third-party remote monitoring and management tool. As soon as we became aware of the incident, we engaged independent cyber security and forensic specialists to investigate, and worked closely with affected customers.”

The company said the incident has been contained and its customers' environments “remain secure and fully operational”.

“We engaged directly with each of the customers who have been named, and provided support as they consider their own response. Out of respect for the privacy of our customers, we are not able to comment on the specific circumstances of any individual business.

Auto IT said it has been working with the Australian Cyber Security Centre and impacted customers.

“We apologise for the concern and disruption this incident has caused,” Auto IT said.

“The security of our customers' systems and data is something we take extremely seriously, and we continue to do everything we can to support those affected and keep our systems safe.”

What happened?

The Storm ransomware group posted details of its first victim on August 7, and shared several more over the coming weeks.

However, on August 18 the group started listing Australian car dealerships and auto & machinery suppliers. Among the first of these was Westco Motors Cairns, alongside Ramsey Bros and Penfold Motors. The Sharp Motor Group, Agrimac, and Macquarrie followed.

The Sharp Motor Group, Penfold Motors, and Macquarrie have all confirmed their incidents were linked to a third-party cyber incident, which Cyber Daily understands was the one just disclosed by Auto IT.

Auto IT has not yet been listed by the threat actor.

Who is Auto IT?

Based in Australia, Auto IT describes itself as one of the country’s largest DMS companies.

On its website, the company says “You’ll find our systems throughout Australia and New Zealand, plus the USA, Canada, South East Asia, Africa, Fiji and Mexico. Our offices are in Melbourne, Sydney, Kuala Lumpur, Bangkok, Bangalore and Wellington, plus channel partners in South Africa and Mexico”.

Auto IT supplies its software to the automotive, agriculture, trucking, and construction industries. The Perseus Operating Group of Constellation Software acquired the Auto-IT Group in March 2024.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: