A potential compromise involving dealer management software provider Auto-IT is being investigated following ransomware claims against a number of Australian automotive and agricultural businesses.
Auto-IT, one of the largest Dealer Management Software (DMS) providers operating across Australasia, has been linked to a series of cyber security incidents involving Australian automotive and agricultural dealers that have subsequently been claimed by the Storm ransomware group.
The development is potentially significant for both Australia and New Zealand given the widespread use of Auto-IT’s dealer management platforms across the automotive, trucking, agricultural and construction equipment sectors.
What happened?
According to information provided by Auto-IT, the incident involved the unauthorised use of third-party remote monitoring and management (RMM) software.
Auto-IT has stated that it is working with affected customers and the Australian Cyber Security Centre (ACSC) as part of its response.
The precise scope and method of the compromise have not been publicly established. However, the timing and apparent links between the Auto-IT environment and several organisations subsequently listed by the Storm ransomware group have raised concerns that the incident may have resulted in downstream impacts to Auto-IT customers.
Organisations believed to have been impacted include:
| Organisation | Sector / Industry |
|---|---|
| Westo Motors Cairns | Automotive |
| Sharp Motor Group | Automotive |
| Macquarrie | Automotive / Dealer |
| Agrimac | Agricultural machinery |
| Ramsey Bros | Agricultural machinery |
| Penfold Motors | Automotive |
Importantly, the relationship between the Auto-IT incident and each individual ransomware claim has not been independently confirmed. The appearance of an organisation on a ransomware group’s leak site does not, by itself, establish how the organisation was compromised or whether data was actually obtained.
Why a DMS compromise matters
Dealer management systems sit at the heart of many dealership operations.
Depending on the particular implementation, DMS platforms can be involved in areas such as:
- Customer and prospect information
- Vehicle and equipment sales
- Finance and insurance processes
- Service and workshop operations
- Parts management
- Inventory
- Supplier and manufacturer interactions
- Employee and dealership information
- Financial and transactional records
This makes a compromise of a DMS provider or a technology provider with privileged access potentially more significant than an isolated compromise of an individual dealership.
The use of third-party remote management software is particularly relevant. RMM platforms are designed to provide legitimate remote access and administrative capabilities, but those same capabilities can make them attractive to attackers if credentials, configurations or access controls are compromised.
The supply-chain question
The incident also highlights a familiar challenge for organisations using managed technology providers.
A dealership may have strong controls around its own internet-facing infrastructure while still depending on a third party that has privileged access to its systems.
This creates an additional layer of risk:
Supplier compromise → privileged access → customer environment → downstream compromise
Determining exactly where an attack began, what access was obtained and which customer environments were subsequently affected can therefore be difficult.
For organisations using DMS, MSP, RMM or other technology providers, the incident is a reminder that supplier security should be considered part of the organisation’s own attack surface.
What about New Zealand?
Auto-IT has offices in Melbourne, Sydney, Kuala Lumpur, Bangkok, Bangalore and Wellington, and has substantial links to the New Zealand automotive and equipment dealer market.
At this stage, however, it is unclear whether any New Zealand organisations have been impacted by the incident.
The presence of Auto-IT operations in New Zealand does not in itself indicate that New Zealand customers have been compromised.
New Zealand organisations using Auto-IT or other systems managed through the affected third-party technology should nevertheless establish whether they were within the scope of the incident and whether any remote management access to their environments was involved.
What organisations should be asking
For organisations that use Auto-IT or have other technology dependencies involving third-party remote access, some immediate questions include:
- Was our environment accessible through the affected RMM platform?
- Were any RMM accounts or credentials associated with our organisation compromised?
- What systems did the third party have administrative or remote access to?
- Has that access been revoked or rotated?
- Were any unexpected accounts, services or scheduled tasks created?
- Have logs been reviewed for unusual remote access?
- Has the organisation received confirmation of whether it is within the affected customer population?
- Is there evidence of data access or exfiltration?
Organisations should also consider reviewing authentication logs, endpoint telemetry, privileged account activity and RMM activity around the period of the suspected compromise.
A developing story
The potential Auto-IT connection to multiple Storm ransomware claims illustrates how a compromise of a technology provider can potentially have consequences across multiple downstream organisations.
At present, the full scope of the incident remains unclear, and the connection between the reported Auto-IT compromise and individual Storm claims should be treated as unconfirmed unless independently established.
For Australian and New Zealand organisations, the key issue is not simply whether their own systems were directly attacked, but whether a trusted technology provider had access that could have provided a pathway into their environment.
As investigations involving Auto-IT, affected customers and the ACSC continue, further information may clarify the extent of the incident and whether any New Zealand organisations were affected.