What is the Jaguar Land Rover cyberattack?

The Jaguar Land Rover (JLR) cyberattack is the cyber incident of late August 2025 that led the British carmaker to shut down its IT systems worldwide, halting production at all its plants for roughly five weeks. The UK’s Cyber Monitoring Centre estimates the cost to the British economy at around £1.9 billion, which in the centre’s view makes it the most economically damaging cyber event ever to hit the UK. For OT convergence the case is a textbook example: there is no public evidence that the factory control systems themselves were hit, yet every production line stood still.


🗓️ How did the attack unfold?

JLR is the United Kingdom’s largest carmaker and part of India’s Tata Group. In normal times it builds around 1,000 vehicles a day.

Date Event
31 August 2025 Attackers strike inside the JLR network; the earliest publicly known date of the attack
1 September 2025 JLR shuts down its global systems; production stops
2 September 2025 JLR announces that production and retail are “severely disrupted”
10 September 2025 JLR says “some data” has been affected and informs regulators
23 September 2025 The production pause is extended to at least 1 October
28 September 2025 UK government guarantees a £1.5 billion loan
8 October 2025 Phased restart, starting with engine and battery plants
16 October 2025 Vehicle production at Halewood resumes
22 October 2025 Cyber Monitoring Centre rates the incident Category 3
Mid-November 2025 Production back at normal levels

🧠 What exactly happened?

On 1 September 2025 JLR took almost all of its IT systems offline as a precaution. That removed not only office applications but also the wholesale systems, the global parts logistics centre and the systems that drive production. The plants at Solihull, Halewood and Wolverhampton stopped, and sites in Slovakia, China and India also paused. Tens of thousands of employees were sent home.

A group calling itself Scattered Lapsus$ Hunters claimed the attack on Telegram. That picture was later revised. According to a New York Times investigation published in June 2026, investigators from organisations including the National Crime Agency, the NCSC, the FBI and Mandiant point to Russian hackers. Whether they acted on behalf of the Russian state has not been established. According to that reconstruction no ransom was ever demanded, which suggests sabotage rather than extortion with ransomware.

Reports on how the attackers got in conflict. Many security vendors cited a phone attack on the service desk (social engineering), but JLR’s chief information security officer at the time said no social engineering was involved. A vulnerability in SAP NetWeaver was mentioned only by the group claiming the attack. The same reconstruction says the attackers entered through normal authentication flows and then used lateral movement to spread across the network. Earlier in 2025, JLR data had already leaked through stolen credentials for a Jira server, a separate incident.


🏭 Why does an IT outage stop a car plant?

Production stopped because the factory could not run without its IT, not because robots or PLCs had been hacked. There is no public evidence that attackers reached PLCs, HMIs or process networks. The Cyber Monitoring Centre called the impact on operational technology uncertain but probably limited, given the restart in October.

A modern car plant depends on a chain of systems:

  • ERP — orders, material planning and payments to suppliers
  • MES — production sequence, work instructions and per-vehicle records
  • Just-in-sequence logistics — parts arrive hours before assembly, in the order of the line
  • Quality and traceability systems — every vehicle must be demonstrably built to specification

Without that layer the line does not know what to build, and a finished car cannot be released. There is a second reason: JLR could not quickly prove that the production environment was clean and separated from the compromised corporate network. Without a hard boundary along the lines of the Purdue model, switching everything off is the only safe choice. The same pattern appeared earlier with NotPetya in 2017 and with Colonial Pipeline in 2021, where the pipeline was shut down as a precaution although only IT had been hit.


💸 How large was the damage?

Indicator Value
Production halt About five weeks, followed by a restart lasting several weeks
Lost output About 5,000 vehicles per week (CMC estimate)
Cost to the UK economy £1.9 billion (range £1.6–2.1 billion)
UK organisations affected More than 5,000
Direct incident costs for JLR £196 million in the second quarter of fiscal year 2025/26
JLR revenue that quarter £4.9 billion, 24% lower than a year earlier
Wholesale volume, third quarter 59,200 vehicles, down 43%
Government support £1.5 billion loan guarantee via UK Export Finance

The heaviest blow fell on the supply chain. Smaller suppliers in the West Midlands rely almost entirely on JLR volumes and had no buffer. Temporary layoffs followed, and the Unite union warned of insolvencies. During the outage JLR paid suppliers manually, and at the restart it set up a financing scheme that paid suppliers upfront instead of sixty days after invoice. The government guarantee, provided through an Export Development Guarantee, backs a commercial bank loan repayable over five years, and was the first time a UK company received direct state support because of a cyberattack.

According to Reuters, JLR was still negotiating a cyber insurance policy through a broker when it was attacked, and the policy had not been finalised. JLR declined to comment on the report.


🔐 What lessons can manufacturers draw from it?

  1. Design for OT autonomy — decide which lines can run for hours or days without ERP and MES, using locally cached orders and work instructions (island mode).
  2. Make separation provable — network segmentation with an IDMZ between IT and OT, plus a documented way to break the connection in a controlled manner. Then an IT incident does not force you to stop the entire plant as a precaution.
  3. Protect your ability to recover — keep immutable backups of ERP, MES and domain controllers, and rehearse a full rebuild.
  4. Include the supply chain — map which suppliers depend on you and which ones you need, and agree emergency payment and communication arrangements in advance in your business continuity plan.
  5. Rehearse the shutdown decision — who may disconnect IT from OT, and how do you start up again? Record this in an incident response plan.
  6. Sort out insurance and reporting — check whether your policy covers business interruption caused by a cyber incident, and know your reporting deadlines.

In the Netherlands a carmaker like JLR falls under the Cyberbeveiligingswet, the Dutch implementation of NIS2: manufacture of motor vehicles (NACE C29) is part of the manufacturing sector. Since 15 August 2026 such a company, provided it is medium-sized or large, must take appropriate measures, including for OT and its suppliers, and issue an early warning of a significant incident within 24 hours under the reporting obligation. The Dutch Authority for Digital Infrastructure (RDI) supervises compliance.


❓ Frequently asked questions

When did the Jaguar Land Rover cyberattack happen?

The Jaguar Land Rover cyberattack began on 31 August 2025, after which JLR shut down its systems and stopped production on 1 September. A phased restart followed from 8 October 2025. By mid-November 2025 production was back at normal levels.

Who was behind the Jaguar Land Rover cyberattack?

The group Scattered Lapsus$ Hunters claimed the Jaguar Land Rover cyberattack, but investigators do not regard that group as the actual perpetrator. According to a New York Times reconstruction from June 2026, the investigation points to Russian hackers. Whether they worked on behalf of the Russian state has not been established.

Was the Jaguar Land Rover cyberattack a ransomware attack?

The Jaguar Land Rover cyberattack is often described as a ransomware attack, but later reporting says no ransom was ever demanded. That points to sabotage rather than extortion. For the consequences it made little difference: the systems were unusable and had to be restored.

Were JLR’s factory control systems hacked?

There is no public evidence that the attackers reached the PLCs, HMIs or process networks of Jaguar Land Rover. Production stopped because the plants depended on IT systems such as ERP, MES and logistics, and because JLR could not quickly prove that its OT environment was safe. It was therefore mainly an IT incident with OT consequences.

How much did the Jaguar Land Rover cyberattack cost?

The Cyber Monitoring Centre estimates that the Jaguar Land Rover cyberattack cost the UK economy around £1.9 billion, within a range of £1.6 to £2.1 billion. JLR itself booked £196 million in direct incident costs in a single quarter. More than 5,000 UK organisations were affected.

Could a similar attack stop a European factory?

Yes, any factory whose production depends on central ERP and MES systems faces the same risk as Jaguar Land Rover. Network segmentation, the ability to run lines independently for a while, and rehearsed recovery procedures limit the damage. For medium-sized and large Dutch manufacturers in sectors covered by the Cyberbeveiligingswet, such as vehicle manufacturing, appropriate security has also been a legal duty since 15 August 2026.


📌 In summary

The Jaguar Land Rover cyberattack halted all car production for about five weeks in 2025 and cost the UK economy an estimated £1.9 billion, without public evidence that the factory control systems themselves were hit. The lesson for manufacturers: a plant that cannot run without its IT, and cannot prove that its OT is separated, stops whenever a major IT incident strikes.