MotorCycle Holdings
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
MotorCycle Holdings, which also operates under the aliases Sherco and Lambretta, is headquartered in Australia. The company functions as a distributor of motorcycles, specifically supplying models branded as Sherco and Lambretta to the market. Its shares are listed on the Australian Securities Exchange, classifying it as an ASX‑listed motorcycle distributor. This listing places the organisation within the publicly traded sector of the Australian automotive industry.
As an ASX‑listed entity, MotorCycle Holdings is accountable to a broad base of shareholders and must comply with the exchange’s listing rules. The company’s public status provides a level of transparency regarding its financial and operational performance. It maintains a subsidiary named MOJO Motorcycles, which supports certain aspects of its business operations. The existence of this subsidiary is reflected in the description of the cyber incident that affected its third‑party web infrastructure.
MotorCycle Holdings distinguishes itself by focusing on the distribution of two specific motorcycle marques, Sherco and Lambretta, rather than a broad portfolio of brands. Its online presence for these brands is hosted on third‑party web servers, a model that was highlighted during the April 2024 cyber incident. During that incident, malicious code was injected into the third‑party server, enabling unauthorized access to customer personal data such as names, addresses, email addresses and phone numbers. The breach also exposed stored responses submitted through web forms on the Sherco and Lambretta sites, while the company affirmed that its internal systems remained secure and unaffected. MotorCycle Holdings stated that only customers whose data were compromised would be notified directly, and that investigations into the breach were ongoing.
The cyber attack was specifically confined to the third‑party infrastructure that supports the MOJO Motorcycles subsidiary, indicating a clear operational separation between the subsidiary’s web presence and the parent’s core systems. This structural detail underscores that while the subsidiary’s online platforms were impacted, MotorCycle Holdings’ internal networks were not breached. No further information about parent‑company ownership or additional subsidiaries is provided in the available sources. Consequently, the organisational profile is limited to the confirmed facts regarding its headquarters, listing status, brand focus, subsidiary relationship and the disclosed security event.
Incidents
1 incident linked to this organisation.