Jaguar Land Rover (JLR), one of the United Kingdom's most prominent car manufacturers, suffered a significant cyberattack that brought its production lines to a halt across multiple sites, including Solihull, Wolverhampton, and Halewood. The attack, attributed to a group known as Scattered Lapsus$ Hunters, effectively took control of JLR’s manufacturing operations, resulting in a complete production stoppage for nearly a month. This disruption led to estimated financial losses of approximately £50 million per week, severely impacting not only JLR but also its extensive supply chain, which was pushed to the brink of bankruptcy. The scale and duration of the attack highlighted critical vulnerabilities in JLR’s cybersecurity posture, raising questions about the adequacy of its cyber risk management and preparedness. In response to the escalating crisis and the potential for widespread economic fallout, the UK government intervened with an unprecedented £1.5 billion loan guarantee to support the company. This move was justified by officials as necessary to protect jobs and stabilize the broader manufacturing sector, given JLR’s role in supporting over 800,000 jobs nationwide. The government’s intervention marked the first time a UK company received such substantial financial support specifically due to a cyber incident, setting a new precedent in the intersection of national economic security and cybersecurity. The bailout sparked debate over whether such government action might inadvertently encourage lax cybersecurity practices among large firms, knowing that public funds could be used as a safety net. The incident also brought to light the broader issue of cyberattack frequency and severity affecting UK businesses, with many organizations facing similar threats due to weak security controls and insufficient investment in cyber defense. The JLR case underscored the potential for cyberattacks to cause not only direct financial losses but also systemic risks to national industries and employment. It prompted calls for stronger regulatory oversight and more robust cybersecurity requirements for critical sectors. The event also served as a wake-up call for other UK businesses to reassess their cyber resilience and incident response capabilities. The government’s decision was framed as a measure to protect livelihoods, but it also raised concerns about the long-term implications for public policy and corporate accountability. The attack and subsequent bailout have become a focal point for discussions on the true extent of cyber threats facing UK businesses and the adequacy of current defenses. The situation has led to increased scrutiny of both private sector cybersecurity practices and the role of government in mitigating the fallout from major cyber incidents. As the dust settles, the JLR cyberattack is likely to influence future approaches to cyber risk management, public-private collaboration, and the allocation of responsibility for cybersecurity failures.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
On October 6, 2025, Jaguar Land Rover started bringing operations back online after about a month of disruption. The restart began with the Wolverhampton engine factory, with other assembly lines scheduled to return in phases.
Amid concern over job losses and supply-chain damage, the U.K. government guaranteed a £1.5 billion loan to Jaguar Land Rover, repayable over five years. Unions and industry groups warned the support might still be insufficient for a full recovery, and some suppliers said funds had not reached beyond first-tier firms.
Aston Martin said a cyber incident at a major U.K. automotive manufacturer contributed to reduced Q3 wholesale volume projections. The statement showed the Jaguar Land Rover disruption had spilled over into the wider automotive supply chain.
A group calling itself "Scattered Lapsus$ Hunters" claimed responsibility for the Jaguar Land Rover attack. The group later said in mid-September that it was shutting down, though that closure was described as disputed.
On September 1, 2025, a cyberattack hit Jaguar Land Rover and triggered widespread disruption across multiple countries. Manufacturing and dealership operations were affected, and the company reportedly could not book sales from that point.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
bbc.com
Open sourcebankinfosecurity.com
Open sourceinfosecwriteups.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.