Jaguar Land Rover (JLR) suffered a major cyberattack in August that not only halted its manufacturing operations for over a month but also resulted in the theft of sensitive payroll data belonging to current and former employees, as well as contractors. The compromised information includes bank account details, tax codes, and other personal data used for payroll, benefits, and staff schemes. JLR has notified affected individuals and is working with regulators, while also providing support such as credit and identity monitoring services. The company has stated there is no evidence of misuse of the stolen data so far, but has advised vigilance against potential fraud and phishing attempts.
The financial impact of the breach has been severe, with JLR reporting a £1.5 billion drop in sales and an additional £196 million in exceptional losses linked to the incident. The disruption extended beyond JLR, affecting its supply chain and prompting government intervention to secure the company's financial stability. The attack has been described as one of the most costly in UK history, with significant repercussions for the broader UK economy, including a measurable effect on GDP growth and thousands of jobs at risk.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
On or before December 15, 2025, JLR publicly confirmed that the August cyberattack compromised data belonging to current and former employees and contractors. The company said it had notified regulators and affected individuals and was offering support services including credit and identity monitoring.
After the shutdown's wider economic effects became clear, the British government intervened with a loan to support JLR's suppliers. The disruption was estimated to have affected more than 5,000 organizations and imposed a multibillion-pound impact on the UK economy.
By late September 2025, JLR had restored operations after the prolonged shutdown caused by the cyberattack. The recovery followed weeks of manufacturing disruption and ongoing forensic investigation.
During the August 2025 incident, attackers stole sensitive data belonging to current and former employees and contractors. Reported exposed information included payroll and HR records such as bank account details, tax codes, salaries, addresses, and National Insurance numbers.
In August 2025, Jaguar Land Rover suffered a major cyberattack that forced production stoppages across multiple UK plants. The disruption lasted for more than a month and delayed vehicle deliveries across the company's supply chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetherecord.media
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.