Westco Motors Cairns, Ramsey Bros, Sharp Motor Group and Sharp Motor Group's third-party IT provider: Exclusive: Sharp Motor Group confirms third-party cyber incident in wake of ransomware claims

Westco Motors Cairns, Ramsey Bros, Sharp Motor Group and Sharp Motor Group's third-party IT provider: Exclusive: Sharp Motor Group confirms third-party cyber incident in wake of ransomware claims

Storm Ransomware Group Strikes Again, Targets Fourth Australian Automotive Dealer

The Storm ransomware group has claimed its fourth Australian victim, listing the Sharp Motor Group on its leak site on 23 August. While the full extent of the stolen data remains undisclosed, the hackers have released samples as proof, including employee passport and driver’s license scans, financial records, customer invoices, and login credentials. Storm has threatened to publish the entire dataset on 14 September if demands are not met.

Sharp Motor Group, which operates dealerships in Tweed Heads, NSW, confirmed the incident, stating that its third-party IT provider was compromised. The company is working with independent cybersecurity experts and authorities, including the Office of the Australian Information Commissioner (OAIC), to investigate. A spokesperson emphasized that customer and staff privacy remains the top priority.

Storm, a relatively new ransomware operation, has rapidly expanded its victim list, claiming 26 targets since its emergence this month four of them Australian, including Ramsey Bros and Westco Motors Cairns. The group positions itself as a "premier, results-driven firm" and actively recruits affiliates, while avoiding attacks on organizations within the Commonwealth of Independent States (CIS).

Sharp Motor Group, known for its new and used vehicle sales, trade-ins, and financing services, serves customers in Tweed Heads, the Northern Rivers, and the Gold Coast. The breach highlights the growing risk of supply chain attacks, where cybercriminals exploit vulnerabilities in third-party vendors to gain access to larger targets.

Source: https://www.cyberdaily.au/security/14111-exclusive-sharp-motor-group-confirms-third-party-cyber-incident-in-wake-of-ransomware-claims

Westco Motors cybersecurity rating report: https://www.rankiteo.com/company/westco-motors

Sharp Corporation of Australia cybersecurity rating report: https://www.rankiteo.com/company/sharp-corporation-of-australia

Ramsey Bros cybersecurity rating report: https://www.rankiteo.com/company/ramseybros

Sharp Motor Group cybersecurity rating report: https://www.rankiteo.com/company/sharp-motor-group

"id": "WESSHARAMSHA1787891249",
"linkid": "westco-motors, sharp-corporation-of-australia, ramseybros, sharp-motor-group",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Automotive',
                        'location': 'Tweed Heads, NSW, Australia',
                        'name': 'Sharp Motor Group',
                        'type': 'Automotive dealer'}],
 'attack_vector': 'Supply chain attack via third-party IT provider',
 'customer_advisories': 'Public statement regarding the incident and '
                        'prioritization of privacy',
 'data_breach': {'data_exfiltration': 'Yes',
                 'file_types_exposed': ['Passport scans',
                                        "Driver's license scans",
                                        'Invoices',
                                        'Credentials'],
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Employee personal documents',
                                              'Financial records',
                                              'Customer invoices',
                                              'Login credentials']},
 'date_publicly_disclosed': '2024-08-23',
 'description': 'The Storm ransomware group has claimed Sharp Motor Group as '
                'its fourth Australian victim, listing it on its leak site on '
                '23 August. The group has released samples of stolen data, '
                "including employee passport and driver's license scans, "
                'financial records, customer invoices, and login credentials, '
                'with a threat to publish the entire dataset on 14 September '
                'if demands are not met.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage',
            'data_compromised': "Employee passport and driver's license scans, "
                                'financial records, customer invoices, login '
                                'credentials',
            'identity_theft_risk': 'High'},
 'initial_access_broker': {'entry_point': 'Third-party IT provider'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain',
 'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Storm'},
 'references': [{'date_accessed': '2024-08-23',
                 'source': 'Storm ransomware group leak site'}],
 'regulatory_compliance': {'regulatory_notifications': 'Office of the '
                                                       'Australian Information '
                                                       'Commissioner (OAIC)'},
 'response': {'communication_strategy': 'Public statement emphasizing customer '
                                        'and staff privacy as top priority',
              'law_enforcement_notified': 'Office of the Australian '
                                          'Information Commissioner (OAIC)',
              'third_party_assistance': 'Independent cybersecurity experts'},
 'threat_actor': 'Storm ransomware group',
 'title': 'Storm Ransomware Group Targets Sharp Motor Group',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.