Penfold Motors (Vic): Storm ransomware via third-party software; customers notified
Cyber Daily (14 September 2026) reports Victorian dealership Penfold Motors (Peter Warren Automotive Group; six Vic sites) is contacting customers after Storm ransomware operators listed the firm (listing dated 17 August; early leak post mis-attributed a similarly named UK organisation before correction). Company statement dated 7 September: contained incident involving an external software provider that stored some Penfold data; systems restored and dealerships operating; investigation with the provider and forensic specialists ongoing. Impact described as basic contact details plus vehicle and servicing information (VINs and tax invoices appeared in published samples per Cyber Daily); Penfold said there was no evidence identity documents or bank-account data were involved, and that it notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. Cyber Daily also notes Sharp Motor Group and Macquarrie as other recent Australian automotive/machinery victims tied to third-party supplier incidents in the same Storm wave (Macquarrie desk card updated separately). UPDATE 15 Sep 2026: Cyber Daily names Auto-IT as that third-party software firm (see auto-it-storm-20260915). Primary: Cyber Daily exclusive with company quotes.
- Exploited in Australia?
- yes
Primary: Cyber Daily — Penfold Motors / Storm (14 Sep 2026) · Webber Insurance AU data-breaches list (September 2026 entry)
