Investigators have linked the main breach in Jaguar Land Rover's major cyberattack to Russian hackers, according to reporting citing people close to the case. The attack halted production for months and triggered a broad investigation involving Microsoft, the FBI, the U.K. National Crime Agency, the National Cyber Security Centre, Google Mandiant, and Palo Alto Networks. Microsoft reportedly tracked the Russian group and warned JLR, while investigators said it remains unclear whether the operators were state-directed, criminal, or criminals tolerated by the Russian government. The inquiry also found that a separate Jordanian hacker using the alias Rey had compromised parts of JLR's network, making the incident a multi-actor intrusion.
The Cyber Monitoring Centre estimated the disruption caused £1.9 billion in damage to the U.K. economy, or about $2.5 billion, with effects spreading to more than 5,000 businesses. The fallout reportedly drove U.K. car production down to levels not seen since 1952, and the Bank of England cited the damage in its economic outlook, underscoring how the attack's impact extended far beyond Jaguar Land Rover's own operations.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Investigators found that a separate Jordanian hacker using the alias Rey had also breached some Jaguar Land Rover networks. This established the incident as a multi-actor compromise rather than a single-actor intrusion.
Investigators concluded that Russian hackers were behind the main Jaguar Land Rover breach, though it remained unclear whether they were state operators, criminals, or criminals tolerated by the Russian government. This attribution was reported by The New York Times based on people close to the investigation.
Microsoft reportedly tracked the Russian threat group tied to the main Jaguar Land Rover breach and alerted the company. The subsequent investigation also involved the FBI, the U.K. National Crime Agency, the National Cyber Security Centre, Google Mandiant, and Palo Alto Networks.
Jaguar Land Rover suffered a major cyberattack last year that halted production for months. The Cyber Monitoring Centre later estimated the incident caused £1.9 billion ($2.5 billion) in damage to the UK economy and affected more than 5,000 businesses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcemalware.news
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.