Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

A vendor breach hit six Australian businesses — third-party remote access, what to ask your IT provider

A Vendor Got Hit by Ransomware, and So Did Its Customers

Storm ransomware just breached at least six Australian dealerships and equipment suppliers, and none of them were hacked directly. Attackers got in through a hijacked remote access tool at their shared software vendor, Auto-IT.

Storm compromised Auto-IT, the company behind one of Australia's largest dealer management systems, by misusing a third-party remote monitoring and management (RMM) tool connected to customer systems. Westco Motors Cairns, Penfold Motors and Sharp Motor Group are among the businesses that ended up on Storm's leak site, according to Cyber Daily. Auto-IT has engaged forensic specialists and the ACSC and is working through affected accounts, but the damage was done before anyone at those dealerships clicked a thing.

This is the same weak point we see across every industry we support: your IT provider, POS vendor or software partner usually has standing remote access into your systems, and that access is only as safe as their controls around it. All IT runs RMM tools for our own managed clients every day, which is why we push people to ask hard questions about it: is remote access protected by MFA, is it logged and reviewed, and what's the plan if one of their own vendors gets breached.

Written by Dan Briggs, Head of Client Partnerships, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across Australia.


Frequently Asked Questions

The Storm ransomware group misused a third-party remote access tool connected to Auto-IT, an Australian dealer management software vendor, to reach a small number of its customers' systems.
Storm publicly listed at least six Australian dealerships and equipment suppliers, including Westco Motors Cairns, Penfold Motors and Sharp Motor Group, none of which were breached directly.
Yes. The same method, hijacking a vendor's remote access tool, works against any IT provider or software vendor with ongoing access to your systems.
Ask whether remote access to your systems is protected by multi-factor authentication, whether it's logged and reviewed, and what their plan is if one of their own vendors is compromised.

Know Who Has the Keys to Your Systems

If you can't answer those three questions about your own IT provider, we can help you find out, and close the gap before it becomes a problem.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →