Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Jaguar Land Rover Cyberattack 2025: The UK’s Costliest…
Breach analysis Incident: 31 Aug 2025

Jaguar Land Rover Cyberattack 2025: The UK’s Costliest Cyber Incident and the Identity Questions It Left

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 11 min read
On this page

At the end of August 2025, a cyberattack forced Jaguar Land Rover (JLR) to shut down its systems and stop building cars. Production stayed down for more than five weeks, the UK government guaranteed a £1.5 billion loan to protect the supply chain, and the Cyber Monitoring Centre estimated the cost to the UK at £1.9 billion, which Infosecurity Magazine reported as the UK's costliest cyber incident ever. How the attackers got in has still not been officially disclosed. Reports of staff being impersonated on the phone to obtain corporate credentials were widely repeated, but JLR's chief information security officer at the time has said no social engineering was involved. A separate intrusion earlier in 2025, through a third party's stolen Jira credentials, shows how exposed JLR's identity perimeter already was.

Key takeaways

  • JLR says it was "impacted by a cyber incident" and took immediate action by "proactively shutting down our systems". Production halted from 1 September 2025 and a phased restart began on 8 October.
  • JLR first said there was no evidence customer data had been stolen, then said "some data has been affected" and informed regulators. A group calling itself Scattered Lapsus$ Hunters claimed the attack on Telegram.
  • The Cyber Monitoring Centre rated the incident a Category 3 systemic event, estimated the UK cost at £1.9 billion and said more than 5,000 UK organisations were affected.
  • The initial access route has not been confirmed. In June 2026, The New York Times reported that investigators linked the attack to Russian hackers and that no ransom was demanded; JLR's then CISO has said no social engineering was involved.
  • In March 2025, a different attacker had already breached JLR's Jira server using credentials of a third-party employee harvested by infostealer malware years earlier and never changed.

At a glance

OrganisationJaguar Land Rover (JLR), owned by Tata Motors
WhenAttack began 31 August 2025; production halted 1 September; phased restart from 8 October 2025
AttackerClaimed by Scattered Lapsus$ Hunters; linked by investigators to Russian hackers, according to The New York Times (June 2026). Not officially attributed.
Entry pointNot publicly disclosed
Identities abusedNot confirmed. Vishing of staff for corporate credentials was widely reported but disputed by JLR's then CISO. In a separate March 2025 intrusion, a third-party employee's Jira credentials stolen by infostealer malware were used.
ImpactMore than five weeks of halted production; "some data" affected; £196 million in direct costs in JLR's second quarter; £1.5 billion UK government loan guarantee; estimated £1.9 billion cost to the UK economy
CategoryHuman identity (not listed as an NHI or AI agent breach)

What happened

On 2 September 2025, JLR said: "JLR has been impacted by a cyber incident. We took immediate action to mitigate its impact by proactively shutting down our systems. We are now working at pace to restart our global applications in a controlled manner. At this stage there is no evidence any customer data has been stolen but our retail and production activities have been severely disrupted." TechCrunch reported that the network shutdown began on 31 August.

A group calling itself Scattered Lapsus$ Hunters, presented as a merger of three cybercriminal groups, claimed responsibility on Telegram and posted screenshots it said came from inside JLR's IT systems, including internal technical documentation on vehicle charging troubleshooting and system logs, according to TechRadar. The same name has been linked to the 2025 attacks on UK retailers. Within days, JLR changed its position on data: "As a result of our ongoing investigation, we now believe that some data has been affected and we are informing the relevant regulators." It has not said whose data was involved.

The shutdown kept being extended. The Register reported on 16 September that JLR had pushed the pause in production to 24 September, saying "We are very sorry for the continued disruption this incident is causing." On 28 September, the UK government announced a £1.5 billion loan guarantee, repayable over five years, to "bolster JLR's cash reserves so it can support its supply chain which has been greatly impacted by the shutdown." HM Treasury said JLR directly employs 34,000 people in the UK, with around 120,000 more in its supply chain, and TechCrunch reported that it was the first time the UK government had provided financial assistance to a company after a cyberattack and that JLR did not have cyber insurance.

JLR began a "controlled, phased restart" on 8 October, starting with its Wolverhampton engine plant, its battery centre and its stamping, body and paint operations, according to Autocar. On 22 October, the Cyber Monitoring Centre classified the incident as a Category 3 systemic cyber event and estimated its cost to the UK at £1.9 billion, with more than 5,000 UK organisations affected. It said "the vast majority of the financial impact" came from "loss of manufacturing output at JLR and its suppliers". In November 2025, JLR reported £196 million of costs from the incident in its second quarter, a 24% fall in quarterly revenue to £4.9 billion and a quarterly loss before tax of £485 million, according to Security Affairs, and the Bank of England said the disruption had contributed to weaker than expected UK growth in the third quarter.

How the attackers got in remains unclear. In June 2026, The New York Times reported, citing people close to the investigation, that the attack was linked to Russian hackers, that Microsoft had been tracking them and raised the alarm with JLR, that no ransom was demanded and that the attackers used novel ransomware, according to Infosecurity Magazine's summary. The same report said a hacker known as "Rey" had separately breached part of JLR's network. Infosecurity Magazine noted that it "has been widely reported that the hackers impersonated staff in vishing attacks to get hold of corporate credentials", but that Ashish Shrestha, JLR's group CISO at the time, has said no social engineering was involved.

That earlier breach by Rey is the clearest identity story on record. In March 2025, BleepingComputer reported that Rey, a member of the HellCat group, had accessed JLR's Jira server and leaked about 700 internal documents, including development logs, tracking data and source code, plus an employee dataset. Hudson Rock's Alon Gal said the access came from Jira credentials belonging to an LG Electronics employee with third-party access to JLR. The credentials had been harvested by infostealer malware years earlier and were still valid.

Timeline

DateEvent
March 2025HellCat member Rey leaks about 700 JLR internal documents after using a third-party employee's stolen Jira credentials.
31 August 2025JLR's network shutdown begins.
1 September 2025Production paused.
2 September 2025JLR confirms a cyber incident and says there is no evidence customer data was stolen.
September 2025Scattered Lapsus$ Hunters claims the attack; JLR says "some data has been affected" and informs regulators.
16 September 2025Production pause extended to 24 September.
28 September 2025UK government announces a £1.5 billion loan guarantee.
8 October 2025Phased restart of production begins.
22 October 2025Cyber Monitoring Centre estimates a £1.9 billion UK cost and rates it a Category 3 systemic event.
November 2025JLR reports £196 million of incident costs for its second quarter; the Bank of England cites the disruption in weaker GDP growth.
June 2026The New York Times reports investigators linked the attack to Russian hackers.

How it happened: the identity attack path

JLR has not published how the September 2025 attackers gained access, so the path below separates what is known from what is claimed.

  1. Initial access: unconfirmed. Widely repeated reports said attackers impersonated staff in vishing calls to obtain corporate credentials, the playbook associated with Scattered Spider. JLR's then CISO has said no social engineering was involved.
  2. Access to internal IT systems. The attackers posted screenshots they said came from inside JLR's IT environment, including technical documentation and system logs.
  3. Disruptive payload. According to The New York Times, as summarised by Infosecurity Magazine, novel ransomware was used and no ransom was demanded.
  4. Defensive shutdown. JLR shut down its own systems to contain the attack, which stopped manufacturing and retail activity across its operations.
  5. A known weak spot in third-party access. Months earlier, a third-party employee's Jira credentials, stolen by infostealer malware years before and never rotated, had been enough for a separate attacker to take internal documents.

Impact

  • Operations: vehicle production halted from 1 September to a phased restart from 8 October 2025.
  • Data: JLR says "some data has been affected" and informed regulators; it has not said whose.
  • Financial: £196 million of costs in JLR's second quarter, according to Security Affairs; about $350 million in fiscal year 2026, according to The New York Times as reported by Infosecurity Magazine.
  • Economy: an estimated £1.9 billion cost to the UK and more than 5,000 UK organisations affected, according to the Cyber Monitoring Centre.
  • Government: a £1.5 billion loan guarantee to support JLR and its suppliers.

What this means for identity security

The JLR attack is a warning about how little the public record can show about initial access, even for an incident this costly. What is on record is a pattern. The attack was claimed by a group whose name ties it to help desk and phone-based social engineering of employees. And earlier in 2025, JLR's Jira server was opened with an outside contractor's credentials that had been stolen years before and never changed.

Both routes point at the same control gaps: account recovery and credential reset processes that trust a caller's voice, third-party accounts that are not reviewed or expired, passwords that stay valid long after they appear in infostealer logs, and single-factor access to internal collaboration tools. The machine identity parallel is direct. A stolen API key or service account password that is never rotated behaves exactly like the contractor's Jira password: valid for years, owned by no one, and invisible until someone uses it.

Recommendations

  • Harden help desk and account recovery. Require strong identity verification before any password or MFA reset, especially for privileged or IT staff. Our Workforce Identity Security Guide covers help desk social engineering.
  • Use phishing-resistant MFA everywhere, including collaboration tools. A password alone should never be enough to reach Jira, wikis or source code.
  • Govern third-party accounts. Give every contractor and supplier account an owner, an expiry date and regular access reviews, as covered in IAM and IGA Basics.
  • Act on infostealer exposure. Monitor for employee and contractor credentials in infostealer logs and force resets when they appear.
  • Apply the same rules to machine credentials. Rotate and expire API keys, tokens and service account passwords, following our guide to NHI rotation challenges.
  • Plan for a defensive shutdown. Know which systems production depends on and how to restart them safely, so containment does not become weeks of downtime.

Frequently asked questions

How did hackers get into Jaguar Land Rover in 2025?

JLR has not disclosed it. Reports that attackers impersonated staff by phone to obtain credentials were widely repeated, but JLR's then CISO has said no social engineering was involved. A separate intrusion in March 2025 used a third-party employee's stolen Jira credentials.

How much did the JLR cyberattack cost?

JLR reported £196 million of costs in its second quarter. The Cyber Monitoring Centre estimated the total cost to the UK economy at £1.9 billion, and the UK government guaranteed a £1.5 billion loan.

Is the JLR attack a non-human identity breach?

Not on current evidence. The confirmed identity weakness involved a human user account from a third party, and the September 2025 access route is not public. The lessons on stale, unrotated credentials apply equally to machine identities.

Co-op Group breach · MGM Resorts breach · Human vs Non-Human Identity · Workforce Identity Security Guide · NHI breaches

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as attackers move between stolen employee credentials, third-party accounts, API keys, tokens and secrets. Our NHI Foundation Level Training Course gives teams the practical grounding to find, govern and protect these identities.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org