A support tool built by one company became the doorway into dealership systems run by another, and the vendor at the centre of it has now confirmed a limited intrusion.
Auto-IT responded this week to dark web claims from the Storm ransomware group, which has listed more than half a dozen Australian car dealerships and heavy machinery suppliers since August 18. Several of those businesses have pointed at a third-party technology supplier as the source of their trouble.
Auto-IT’s own account, given to Cyber Daily, is narrower. It describes a security incident in a small number of customer environments, where an intruder misused a remote monitoring tool belonging to another firm. That class of software is the plumbing that lets an outside IT provider reach a client’s machines; stolen credentials for that layer hand an attacker a legitimate path into every client it touches.
The company said a small number of customer businesses were named on a dark web listing, that the incident had been contained, and that affected environments remain secure and fully operational. Independent forensic specialists were engaged, impacted dealers were contacted directly, and the matter was referred to the Australian Cyber Security Centre.
Auto-IT is careful not to call this its own breach. The distinction matters commercially, and it will not comfort dealers who buy software precisely because they cannot staff a security team of their own.
A franchise store holds licence scans, finance applications and service histories. A single supplier-side credential is enough to reach all of it at once.