A newly emerged ransomware operation known as Storm has quickly established itself as a threat to organisations across a small number of countries, including Australia.
Storm first appeared in early August 2026 and has rapidly accumulated victim claims. Current threat-intelligence tracking records Storm as having claimed victims across five countries, with Australia emerging as one of its more significant target locations. Some trackers now record almost 50 victims globally since the group’s emergence.
Of particular interest is the number of Australian organisations appearing on the group’s leak site. At least seven Australian organisations have been claimed by Storm since mid-August, with several operating in the automotive, agricultural machinery, industrial and related sectors.
A new ransomware operation
Storms activity has been characterised by the publication of alleged victims on a ransomware leak site, with the group reportedly using a double-extortion model.
Under this model, attackers seek to both:
- Encrypt systems and data belonging to the victim.
- Steal sensitive information before encryption.
- Use the threat of publishing the stolen information to pressure the victim into paying a ransom.
The use of data exfiltration means that restoring systems from backups may not be sufficient to resolve the incident. Even if an organisation can recover its systems without paying a ransom, the attackers can continue to threaten publication of the allegedly stolen information.
A geographically selective target set
Storm’s victim profile is particularly interesting because of the relatively small number of countries represented.
The group has stated that it does not target organisations in certain countries associated with the Commonwealth of Independent States (CIS). This has led some observers to assess that the operators may have links to, or be operating from, the broader CIS region.
The group’s claimed victims have predominantly been located in:
- United States
- United Kingdom
- Germany
- Australia
- Canada
This does not prove the operators’ nationality or physical location. However, the apparent geographic exclusion, combined with the concentration of victims in Western countries, is consistent with targeting decisions seen from some ransomware groups operating from Eastern Europe or the broader CIS region.
Australian organisations increasingly appearing on the leak site
Australia has accounted for a notable proportion of Storm’s claimed victims during its first weeks of activity.
The Australian victims identified so far include:
| Organisation | Claimed date | Industry / sector |
|---|---|---|
| Macquarrie | 3 September 2026 | Industrial / engineering |
| Agrimac | 27 August 2026 | Agriculture / agricultural machinery |
| Sharp Motor Group | 24 August 2026 | Automotive |
| Westco Motors Cairns | 18 August 2026 | Automotive |
| Penfold | 17 August 2026 | Technology |
| Ramsey Bros | 18 August 2026 | Agriculture / farm machinery |
| 3-point Australia | 14 August 2026 | Industrial / equipment |
Independent ransomware tracking services also record these organisations as Storm listings.
The pattern is noteworthy. During the past several weeks, a significant proportion of Storm’s victims (including the Australian ones) have been associated with automotive, agricultural machinery, construction, industrial equipment or related businesses.
Six of the seven Australian organisations identified above fall broadly within this equipment, automotive, agricultural or industrial grouping.
Why these industries?
The concentration of victims in these sectors may be more than coincidence.
Organisations involved in automotive and agricultural equipment often maintain a combination of valuable corporate information, customer records, financial information and operational systems. They can also depend heavily on IT systems to support sales, servicing, logistics, inventory and business operations. The two Australian car sales organisations use the same website theme and chat assistant, although this is not unusual in automotive sales websites.
For a ransomware operator, disruption to these systems can create significant pressure on the victim to restore operations quickly.
There is also the potential for these organisations to hold sensitive information relating to customers, employees, suppliers and business partners, providing an additional incentive for attackers to pursue a double-extortion strategy.
Sharp Motor Group claim illustrates the potential impact
Storm’s claim against Sharp Motor Group provides an example of the type of information the group says it has obtained.
Reporting has indicated that Storm published documents allegedly including employee passport and driver’s licence scans, financial information, customer invoices, passwords and user IDs. Sharp Motor Group has acknowledged that it is investigating a cyber incident involving a third-party IT provider, although the full scope of the attacker’s claims has not been independently established.
This is particularly significant because it demonstrates why ransomware incidents should not be viewed solely as an availability problem.
The compromise of identity documents, credentials and customer information can create a much longer-term security and privacy risk after the ransomware incident itself has been contained.
Australian and New Zealand organisations should treat the activity seriously
The rapid appearance of multiple Australian organisations on Storm’s leak site should be a warning for organisations operating in the sectors currently being targeted.
Security teams should consider:
- Reviewing externally exposed systems and remote-access services.
- Ensuring multi-factor authentication is enabled, particularly for privileged and remote access.
- Monitoring for unusual authentication activity.
- Reviewing privileged accounts and service accounts.
- Testing offline and immutable backups.
- Ensuring endpoint detection and response coverage is comprehensive.
- Monitoring for abnormal data transfers and potential exfiltration.
- Reviewing third-party access into corporate environments.
- Ensuring incident-response plans specifically address ransomware and data theft.
- Monitoring threat-intelligence sources for indications that the organisation has been targeted.
Particular attention should be paid to third-party IT providers and suppliers, given the involvement of a third-party provider in the Sharp Motor Group incident reported to date.
A warning about Storm’s victim claims
It is important not to automatically equate a listing on Storm’s leak site with a confirmed ransomware attack.
Ransomware groups have a financial incentive to exaggerate their success, and threat-intelligence researchers have warned that ransomware leak sites can contain fabricated, automated, recycled or otherwise unconfirmed claims.
For example, independent trackers currently label several Storm-related Australian incidents as claimed, alleged or unconfirmed.
Consequently, the organisations listed in this article should not be described as confirmed victims unless the organisation itself or another authoritative source confirms the incident.
The presence of an organisation’s name on a ransomware leak site establishes that the threat actor is making a claim. It does not, by itself, establish that the claimed intrusion occurred, that ransomware was deployed, or that the data displayed by the attacker was obtained from that organisation.
What to watch next
Storm is still a very young ransomware operation, having appeared only in August 2026. Its relatively rapid accumulation of victim claims makes it a group worth monitoring.
The most important question will be whether its current targeting pattern continues.
If Storm continues concentrating on automotive, agriculture, industrial equipment and related organisations, Australian businesses in these sectors should consider the group a relevant threat rather than simply another entry in the growing ransomware ecosystem.
For now, however, the distinction between a ransomware claim and a confirmed compromise remains critical.
Storm is clearly claiming Australian victims and New Zealand is only a small step away. Whether every claim represents a genuine compromise remains an open question.