A ransomware attack on an Australian software provider has exposed at least six businesses across two industries – none of which were directly targeted. For brokers with clients in automotive, agriculture, or construction, the incident raises a coverage question that cannot wait for the next renewal.
Auto-IT, which describes itself as one of Australia’s largest dealership management system (DMS) companies, confirmed this month that a number of its customers were compromised following activity by the Storm ransomware group.
The breach did not originate in Auto-IT’s core platform. The entry point was a third-party remote monitoring and management (RMM) tool – software that vendors use to remotely access and manage client systems.
“We can confirm that a small number of Auto-IT customers were named by an unauthorised external party on a dark web listing site, in which the external party claims to have accessed data relating to their businesses. This relates to a security incident that affected a small number of Auto-IT customer environments and involved the unauthorised use of a third-party remote monitoring and management tool,” an Auto-IT spokesperson told Cyber Daily.
Auto-IT said it engaged independent cyber security and forensic specialists, notified the Australian Cyber Security Centre (ACSC), and worked with each named customer. The company says the incident is contained and customer environments “remain secure and fully operational.”
Read next: Education clients face broader cyber exposure after Perth school breach
Storm began posting victims on August 7, 2026. From August 18, it listed a series of Australian automotive and machinery businesses: Westco Motors Cairns, Ramsey Bros, Penfold Motors, the Sharp Motor Group, Agrimac, and Macquarrie, according to Cyber Daily’s reporting.
The Sharp Motor Group, Penfold Motors, and Macquarrie have each confirmed their incidents were linked to a third-party cyber event – identified by Cyber Daily as the Auto-IT breach. Auto-IT has not been listed as a direct Storm victim.
Auto-IT supplies software to the automotive, agriculture, trucking, and construction industries. The Perseus Operating Group of Constellation Software acquired the company in March 2024.
The Auto-IT incident follows a pattern now established in the Australian market: one vendor is compromised, and losses fall on client businesses that had no visibility into the attack and no means to prevent it.
February’s youX breach made the same point at scale. The Sydney-based fintech, which processes loan applications for brokers and lenders, confirmed that a threat actor accessed its systems and published data linked to 797 broker organisations and more than 90 downstream lenders, according to Cyber Daily. Those brokers and lenders were not directly attacked – they were downstream of someone else’s failure.
Both incidents expose the same gap in cyber policy coverage. Some policies include third-party networks within the definition of the insured’s computer system. Others do not – and where a policy does not clearly extend to outsourced infrastructure, a client caught in a supply chain breach may find their coverage does not respond, even where their data, systems, and trading continuity were all affected.
For an SME in automotive or agriculture, that distinction means the difference between a paid claim and absorbing the full cost of forensics, legal advice, regulatory notification, and lost revenue.
The mechanism behind the Auto-IT breach is not unusual. Arctic Wolf’s 2026 Threat Report, which analysed hundreds of real-world incident response engagements from 2025, found that 65% of non-business email compromise (BEC) intrusions stemmed from abuse of remote access technologies – including RDP, VPN, and RMM tools.
“Attackers continue to rely on operational efficiency – logging in instead of breaking in, stealing data instead of encrypting it, and exploiting trusted tools rather than complex vulnerabilities,” said Ismael Valenzuela, vice president, Labs, Threat Research & Intelligence, at Arctic Wolf.
For brokers, the implication is direct: clients in sectors reliant on managed software platforms carry vendor-side risk that their own security posture cannot reduce. If the vendor’s remote access tool is the entry point, the client’s own controls offer no protection.
Businesses caught in the Auto-IT breach may also face obligations under the Privacy Act 1988 (Cth). Australia recorded 1,205 notifiable data breach notifications in 2025 – the highest annual total since the scheme began in 2018, an 8% increase on 2024, according to the Office of the Australian Information Commissioner (OAIC).
The cost of a slow response has been made concrete. In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties – the first under the Privacy Act – covering failures including delayed breach assessment and delayed OAIC notification, according to law firm Gadens.
A breach originating with a third party does not automatically remove the affected business’s notification obligations if personal information was accessed through its environment. Brokers whose clients face that question need to confirm whether their policy includes incident response support – not just indemnity – to cover the legal and forensic costs of making that determination.
Read next: Ransomware attack reaches Victorian business through external technology provider
Auto-IT said it engaged directly with each named customer. “We apologise for the concern and disruption this incident has caused. The security of our customers’ systems and data is something we take extremely seriously, and we continue to do everything we can to support those affected and keep our systems safe,” the company said.
Whether those businesses’ policies respond is a separate question – one brokers need to answer independently.
For any broker with clients running managed software in automotive, agriculture, transport, or construction: if the vendor is breached, does your client’s policy pay?