Skip to content
Thursday 13 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,833.15
-0.10%
DAX
26,331.07
-0.23%
CAC 40
8,674.94
-0.46%
STOXX 50
6,533.99
-0.26%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Friday 05 September 2025 10:14 am

JLR staff told to stay at home amid massive cyber attack disruption

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
The government loan has skidded to a halt prompting £500m to be supplied by bosses
The shutdown has been estimated to have cost the company around £120m

Thousands of workers at Jaguar Land Rover (JLR) were told to ‘stay at home’, and customers are facing major delivery delays after a cyber attack forced the company to shut down production across its plants.

The incident, which began on Sunday, halted the UK’s biggest carmaker’s operations at sites in Solihull, Halewood, Wolverhampton and Castle Bromwich, disrupting retail systems during one of the busiest weeks of the year for new car registrations.

Dealers have been unable to process some of the new ‘76’ plates launched on 1 September, leaving its customers waiting longer for their vehicles, in some cases after already part-exchanging old cars.

JLR, which is owned by India’s Tata Motors, said it had “proactively shut down” systems to contain the cyber breach and was “working at pace” to restore operations.

The firm stressed there was “no evidence” of customer data being stolen and has reported the incident to the Information Commissioner’s Office (ICO).

Hacker group claims responsibility

A collective calling itself ‘scattered lapsus$ hunters’, an alliance of the ‘shiny hunters’, ‘lapsus$’ and ‘scattered spider’ groups, has claimed responsibility.

All of these subsidiaries have been linked to major corporate breaches in the past twelve months.

Sam Kirkman, director of services at NetSPI, noted this incident shows just how much harder cybercriminals are becoming to predict by pooling resources.

“JLR has stated that they took proactive steps to contain the breach and minimise its impact, which is commendable” he said.

The group has released only limited evidence of its involvement, with experts cautioning that attribution in such cases is often unclear.

Disruption at scale

The timing of the cyber attack, coinciding with the launch of the new registration plates, has been interpreted as strategic.

Read more

Has Range Rover just abandoned the SUV?

Range Rover GT side profile in camouflage wrap, parked in an anechoic chamber for acoustic testing.

“Cybercriminals often aim for the biggest possible disruptive impact”, argued Jake Moore, global cybersecurity advisor at ESET.

“Striking at a time when more customers are likely to see potential delays…will have been a tactful decision made by the attackers.”

Patrick Burgess, a cybersecurity specialist at the Chartered Institute for IT, also warned the disruption could last “weeks, if not months”, if the firm’s core systems are affected.

The National Crime Agency confirmed it was investigating and working with partners to assess the incident.

Growing threat to manufacturers

The JLR breach follows a spate of high-profile cyber attacks on UK retailers and manufacturers, including Marks & Spencer, Co-op and Harrods.

Bridgestone Americas also reported a “limited cyber incident” on Sunday, the same day as JLR,in a sign the automotive sector is firmly in the crosshairs.

Comparitech data showed ransomware attacks on manufacturers jumped 57 per cent between July and August alone.

Experts have said criminals see the sector as particularly vulnerable because of the disruption that downtime can cause.

“Phishing, social engineering and account compromise remain the most common route of attack, while the size of targeted companies such as Harrods, M&S and Jaguar Land Rover show that no company is immune”, argued George Glass, associate managing director at Kroll.

For JLR, the immediate focus is restarting production lines that normally turn out around 1,000 cars a day.

Read more

M&S to face shareholder grilling over cyber attack recovery

Marks and Spencer was one of three UK retailers to be targeted

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • automotive
  • Co-op
  • Cyber
  • cyber attack
  • harrods
  • Jaguar
  • Jaguar Land Rover
  • JLR
  • Marks and Spencer
  • phishing
  • retail attack
  • scattered spider

Trending Articles

  • Government debt repayment ‘could rise to half’ of total taxes

  • Everest Group Announces Dividend

  • Moody’s Corporation Elects Keith Demmings to Board of Directors

  • Lattice to Deliver Keynote at 2026 OCP Global Summit

  • Martin Williams on his favourite Toast the City venues

More from Morning Wire

  • Has Range Rover just abandoned the SUV?

    Motoring
    Range Rover GT side profile in camouflage wrap, parked in an anechoic chamber for acoustic testing.
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • M&S chair: Tax and employment costs holding back Britain

    Retail
    Archie Norman, business leader, speaking at a corporate event wearing a suit and tie, engaging with the audience.
  • Champions Cup rugby team hacked in ransom attack with player data at risk

    Sport Business
    Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.
  • Accertify and Liminal Release First Empirical Study Proving Fraud-Cyber Convergence Works – and Defining How to Do It Right

    Business Wire
  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • Wasabi and Megaport Partner to Advance the Next Generation of AI and Cloud Infrastructure

    Business Wire
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook