Jaguar Land Rover (JLR) suffered a major ransomware attack attributed to the HellCat group, which began on August 31 and resulted in the shutdown of production lines at all of its factories worldwide. The attack crippled critical systems, including computer-aided design (CAD), engineering software, product life-cycle management, payments tracking, and customer car delivery platforms, severely impacting the company’s ability to operate. As a result, JLR halted all vehicle manufacturing, and the disruption extended to its extensive supply chain, affecting hundreds of small companies that provide parts and services. Many of these suppliers faced severe financial distress, with some on the brink of bankruptcy due to the sudden loss of business and cash flow. The economic impact of the attack was significant, with JLR reportedly losing an estimated £50 million per week and the broader supply chain, employing around 150,000 people across 700 British firms, also suffering. In response to the crisis, the UK government agreed to underwrite a £1.5 billion loan to JLR through the Export Development Guarantee (EDG) program, aiming to stabilize the company and protect jobs throughout the supply chain. The loan, issued by a commercial bank and guaranteed by the government, is intended to help JLR support its suppliers and maintain skilled employment in key regions such as the West Midlands and Merseyside. UK Business Secretary Peter Kyle and Chancellor Rachel Reeves both emphasized the importance of the loan in safeguarding the British automotive sector. The Unite union, representing thousands of workers at JLR and its suppliers, welcomed the government’s intervention as a crucial step. JLR began restoring some IT systems in late September, enabling partial resumption of payment processing to suppliers, but full production was not expected to resume until at least October 1. The company’s lack of cyber insurance reportedly exacerbated the financial fallout. The attack not only disrupted JLR’s internal operations but also created significant challenges for retailers and parts ordering, further amplifying the economic consequences. The incident highlighted the vulnerability of complex manufacturing supply chains to cyber threats and underscored the need for robust cybersecurity and contingency planning. The UK government’s swift action to guarantee the loan was seen as essential to preventing further economic damage and supporting the recovery of both JLR and its network of suppliers. The event has raised concerns about the resilience of critical industries to ransomware attacks and the broader implications for national economic stability. JLR’s experience serves as a stark reminder of the far-reaching impact a single cyber incident can have on a major manufacturer and its ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Reporting said JLR was preparing a phased restart of affected production lines after the cyberattack. The restart was reportedly scheduled to begin on 2025-10-06.
In late September 2025, the UK government announced it would guarantee a £1.5 billion commercial loan for Jaguar Land Rover through UK Export Finance's Export Development Guarantee. Officials said the measure was intended to stabilize JLR's cash reserves, protect jobs, and limit wider supply-chain and economic disruption caused by the cyberattack.
Following the intrusion, a group calling itself "Scattered Lapsus$ Hunters" claimed responsibility, with reporting linking it to the broader Scattered Spider ecosystem. Security researchers also reported that actors including "Rey" and "APTS" leaked large volumes of JLR data on criminal forums, and initial access may have involved stolen Jira credentials obtained via infostealer malware.
Jaguar Land Rover detected a cyberattack on 2025-09-01. The incident disrupted operations and triggered shutdowns of production lines across the UK, Slovakia, Brazil, and India.
11 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcego.theregister.com
Open sourcebankinfosecurity.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcenews.risky.biz
Open sourceautocar.co.uk
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.