A 20-person engineering company in Port Melbourne is the latest business to find that a ransomware attack does not need to enter through its own systems.
Macquarrie Corporation, which provides diesel engine and machinery management services across Australia and New Zealand, was listed on the Storm ransomware group’s leak site on September 1, according to Cyber Daily. Storm set a September 16 publication deadline – the standard pressure tactic used before stolen data is released publicly.
The entry point was not inside Macquarrie’s own network.
“Macquarrie Corporation is aware of a cyber security incident involving one of its external technology providers, resulting in unauthorised access to certain systems used by the business,” a company spokesperson told Cyber Daily.
The company said it acted immediately. “When the incident was identified, we immediately secured the affected systems, engaged independent cyber security specialists, and commenced work to restore operations through alternative arrangements independent of the affected provider,” the spokesperson said.
Data had already reached the dark web by then. Storm published an employee passport scan, a death certificate, company correspondence, customer data, and credit listings as proof of the breach. The group does not disclose the total volume of data taken but routinely publishes samples to establish credibility with victims.
Macquarrie confirmed it is notifying those affected. “With the assistance of our external legal and cyber security advisers, we have reviewed the material currently known to be involved and are in the process of notifying those whose information has been identified as affected. We are committed to providing appropriate guidance and support,” its spokesperson said.
The company is also engaging regulators. “We are actively managing our legal and regulatory obligations in connection with the incident and liaising with relevant government and regulatory authorities, including the Australian Cyber Security Centre and Office of the Australian Information Commissioner,” the spokesperson told Cyber Daily.
Storm only emerged in August 2026 but has listed 49 alleged victims since it began – more than one per day, according to Cyber Daily. Most of its identified Australian targets have been in the automotive and farm machinery dealer sectors.
Sharp Motor Group confirmed in late August that it had also been compromised through a third-party IT provider. “Sharp Motor Group is aware that our third-party IT provider has been involved in a cyber incident,” a company spokesperson told Cyber Daily. Few of Storm’s other victims have commented publicly, making it difficult to determine how consistently the group uses this attack vector.
Macquarrie's profile – a small business reliant on external technology, operating in an industrial sector – is common across the Australian SME market. It is also the profile where coverage gaps are most likely to surface at claim time rather than at policy inception.
Joerg Schmitz, Aon’s cyber risk quantification and analytics leader for APAC, made the stakes clear in Aon’s 2025 Cyber Risk Report. “Organisations must start treating their vendors as part of their own attack surface. The most lucrative attacks are those that can be scaled across multiple targets through a single compromised supplier. This is a wake-up call for Australian businesses to reassess how they manage third-party risk,” Schmitz said.
Broker Gallagher has flagged the same issue directly to clients: “If your suppliers or technology partners are exposed, so is your business. In an interconnected environment, their security standards matter just as much as your own.”
The insurance implication is direct. Some cyber policies expressly include third-party networks within the definition of the insured’s computer system. Others do not – and coverage gaps arise where policy language does not clearly extend to outsourced or off-premises infrastructure, a distinction documented in MinterEllison’s Perspectives on Cyber Risk report. For a vendor-originated breach, that is not a peripheral issue. It is the central coverage question.
Verizon’s 2026 Data Breach Investigations Report – covering more than 22,000 confirmed breaches across 145 countries – found third-party involvement now accounts for 48% of all breaches, a 60% jump on the prior year’s 30%.
Locally, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) responded to over 1,200 cyber security incidents in FY2024-25, an 11% increase year on year. It handled 138 ransomware incidents, 39% of which the ACSC itself identified before the affected organisation was aware.
The Office of the Australian Information Commissioner (OAIC) recorded 1,205 data breach notifications in the 2025 calendar year – the highest annual total since mandatory reporting commenced in 2018 and an 8% increase on 2024.
Under the Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme, notification obligations sit with the data controller regardless of where a breach originated. A mandatory ransomware reporting regime, which commenced on May 30, 2025, under the Cyber Security Act 2024, now also applies to businesses with annual turnovers exceeding $3 million. Non-compliance carries a civil penalty of up to $19,800.
The February 2026 youX incident illustrated how quickly vendor exposure cascades. A single compromised platform generated notification obligations across close to 800 broker organisations and more than 90 lenders.
For brokers with clients in machinery, industrial trades, or any sector dependent on shared or outsourced IT platforms, the Macquarrie incident is a prompt to revisit three questions before the next renewal: Does the policy respond when the breach originates at a vendor? Do vendor contracts include liability and indemnification terms? Does the client understand that notification obligations remain theirs even when someone else’s system was the entry point?