Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptionransomware-group-operationcritical-infrastructure-threat

Jaguar Land Rover Operational Disruption Following Major Cyberattack

Updated 3mo agoFirst seen Oct 3, 20252 sources

Jaguar Land Rover (JLR), the luxury automotive manufacturer and subsidiary of Tata Motors, experienced a significant operational outage due to a major cyberattack that forced the company to shut down its manufacturing systems. The incident led to a month-long disruption, with JLR initiating a controlled, phased restart of its manufacturing operations only after extensive downtime. Initially, the company stated that customer data did not appear to be compromised, but this position was revised a week later, indicating evolving understanding of the breach’s impact. Financially, the attack was devastating, with estimated losses ranging from $50 million to $70 million per week, and the total cost projected between $1.7 billion and $2.4 billion. The attack not only halted production but also highlighted the vulnerability of even large, resource-rich corporations to operationally crippling cyber incidents. Industry experts noted that this event went far beyond typical data theft, resulting in a complete operational outage that severely impacted JLR’s supply chain and business continuity. The British government responded by guaranteeing a £1.5 billion (approximately $2 billion) commercial bank loan to JLR, providing financial support as the company and its suppliers worked to recover from the disruption. This government-backed loan is structured so that JLR is responsible for repayment, but the lender is protected by the government guarantee in case of default. The incident has been cited as a case study in the high costs and business risks associated with ransomware and other forms of cyberattacks targeting critical manufacturing operations. Experts warn that automakers are increasingly attractive targets for ransomware gangs, as operational outages can pressure companies into paying ransoms quickly. Historical context shows that other major automakers, such as Honda, have also suffered significant outages due to cyberattacks, underscoring the sector’s susceptibility. The JLR attack has prompted renewed calls for robust incident response planning, improved cyber resilience, and greater investment in cybersecurity for operational technology environments. The event also demonstrates the potential for cyber incidents to have cascading effects across national economies, prompting government intervention to stabilize affected industries. As JLR resumes operations, the long-term impact on its reputation, supply chain relationships, and financial health remains under close scrutiny by industry observers and stakeholders.

Share:
Jaguar Land Rover Operational Disruption Following Major Cyberattack
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Oct 3, 20259mo ago

JLR works with UK NCSC and law enforcement to restore operations

Following the attack, Jaguar Land Rover worked with the UK National Cyber Security Centre, law enforcement, and cybersecurity specialists to restore operations safely. The response focused on recovery after the prolonged manufacturing disruption.

Scattered Lapsus$ Hunters claims responsibility for JLR attack

A group calling itself 'Scattered Lapsus$ Hunters' reportedly claimed the cyberattack against Jaguar Land Rover. Reporting indicated the attackers demonstrated deep knowledge of JLR's network and timing.

Sep 1, 202510mo ago

Cyberattack forces Jaguar Land Rover to shut manufacturing systems

Jaguar Land Rover suffered a major cyberattack that caused a month-long operational outage and forced the company to shut down manufacturing systems. The attack disrupted both IT and OT environments and was later linked to estimated losses of $1.7 billion to $2.4 billion.

Mar 1, 20251y ago

HELLCAT leaks internal Jaguar Land Rover documents

In March 2025, the HELLCAT ransomware group leaked internal Jaguar Land Rover documents in a prior breach. Later reporting suggested attackers may have retained persistent access from this earlier compromise.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Malware
1 linked
Organizations
14 linked
HondaNational Cyber Security CentreTata MotorsScattered Lapsus$ HuntersTeslaSchneider ElectricJaguar Land RoverHellcatCYFIRMANucorBoeingForum of Incident Response and Security TeamsVisser PrecisionSpaceX
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.