Don’t do SECURITY. Do business SECURELY.

Cyber attack halts production at Jaguar Land Rover

A cyber attack forces Jaguar Land Rover to shut down its IT systems and stop car production for more than five weeks, hitting its UK supply chain.

Jaguar Land Rover (JLR) said a cyber incident had severely disrupted its retail and production activities after it shut down its systems at the end of August. Its factories stayed closed for more than five weeks, with knock-on effects for thousands of businesses in its supply chain.

What happened

  • JLR extended the production pause several times before beginning a phased restart of manufacturing on 8 October 2025.
  • A group calling itself Scattered Lapsus$ Hunters claimed responsibility on Telegram.
  • On 28 September the UK government announced a £1.5bn loan guarantee to bolster JLR’s cash reserves so it could support its suppliers.
  • JLR reported £196m of direct costs from the incident in its July to September quarter, and the Cyber Monitoring Centre estimated the cost to the UK economy at around £1.9bn.

Why it mattered

The Cyber Monitoring Centre described it as the most economically damaging cyber event to hit the UK, and it showed how an attack on one manufacturer can ripple through a national supply chain.

Lessons for organisations

Plan for extended outages of core systems, including how to pay suppliers and keep essential functions running. Segment manufacturing and corporate networks, and make sure backups and recovery have been tested at scale.

Sources: BleepingComputer, Computer Weekly

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights