Quick Summary
AllegedExecutive Summary
Macquarrie, an Australian financial services firm operating under the domain macquarrie[.]com.au, was listed on the Storm ransomware group’s dark web portal on September 3, 2026. This listing was detected by SOCRadar’s Dark Web Monitoring. The company has not confirmed the breach. The financial services sector, along with manufacturing and healthcare, are consistently targeted by the Storm group, making Macquarrie a potential target due to its industry. Australia has been identified as a consistent secondary market for this threat actor. In the 60 days preceding this listing, Storm claimed 41 victims. The group’s primary targets are located in the U.S., followed by Australia and Canada. Macquarrie represents Storm’s third claimed Australian victim within this timeframe. Previous Australian victims include Sharp Motor Group in the transportation sector and Agrimac in agriculture. The consistent targeting of Australian entities by Storm highlights their strategic focus on this region.
Technical Analysis
A query against macquarrie[.]com.au returned no records within the sampled dataset. It is important to note that this dataset is paginated and its coverage is incomplete. Therefore, the absence of records does not rule out the possibility of compromised credentials associated with alternate corporate domains or personal email aliases used by Macquarrie. A null result in this context indicates no positive signal was detected within the specific queried data. The potential for compromised credentials, even without direct evidence in the sampled dataset, remains a concern. Infostealer-harvested credentials can be valuable to ransomware operators as they may provide a pathway for initial access or lateral movement within a victim’s network. This could involve accessing corporate accounts, Microsoft 365 environments, VPNs, or remote-access portals, ultimately facilitating ransomware deployment. Continued monitoring of dark web and stealer-log feeds for any new or previously undiscovered records related to Macquarrie is recommended. Proactive credential hygiene checks, including password rotation and multi-factor authentication review, across all corporate assets, Microsoft 365, VPNs, and remote-access services, should be prioritized. Monitoring for activity under any alternate corporate domains is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.