A Vendor Got Hit by Ransomware, and So Did Its Customers
Storm ransomware just breached at least six Australian dealerships and equipment suppliers, and none of them were hacked directly. Attackers got in through a hijacked remote access tool at their shared software vendor, Auto-IT.
Storm compromised Auto-IT, the company behind one of Australia's largest dealer management systems, by misusing a third-party remote monitoring and management (RMM) tool connected to customer systems. Westco Motors Cairns, Penfold Motors and Sharp Motor Group are among the businesses that ended up on Storm's leak site, according to Cyber Daily. Auto-IT has engaged forensic specialists and the ACSC and is working through affected accounts, but the damage was done before anyone at those dealerships clicked a thing.
This is the same weak point we see across every industry we support: your IT provider, POS vendor or software partner usually has standing remote access into your systems, and that access is only as safe as their controls around it. All IT runs RMM tools for our own managed clients every day, which is why we push people to ask hard questions about it: is remote access protected by MFA, is it logged and reviewed, and what's the plan if one of their own vendors gets breached.
Written by Dan Briggs, Head of Client Partnerships, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across Australia.
Frequently Asked Questions
Know Who Has the Keys to Your Systems
If you can't answer those three questions about your own IT provider, we can help you find out, and close the gap before it becomes a problem.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
