Skip to content
LatestLabour’s ‘chaotic’ zero-hour crackdown could cost firms £3bn per year
CityAM Canada

Canadian business, markets & economy · Thursday, 13 August 2026

  • Business
  • Markets
  • Economy
  • Technology
  • Politics
  • Energy
  • Property
  • Opinion
Friday 05 September 2025 10:14 am

JLR staff told to stay at home amid massive cyber attack disruption

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
The government loan has skidded to a halt prompting £500m to be supplied by bosses
The shutdown has been estimated to have cost the company around £120m

Thousands of workers at Jaguar Land Rover (JLR) were told to ‘stay at home’, and customers are facing major delivery delays after a cyber attack forced the company to shut down production across its plants.

The incident, which began on Sunday, halted the UK’s biggest carmaker’s operations at sites in Solihull, Halewood, Wolverhampton and Castle Bromwich, disrupting retail systems during one of the busiest weeks of the year for new car registrations.

Dealers have been unable to process some of the new ‘76’ plates launched on 1 September, leaving its customers waiting longer for their vehicles, in some cases after already part-exchanging old cars.

JLR, which is owned by India’s Tata Motors, said it had “proactively shut down” systems to contain the cyber breach and was “working at pace” to restore operations.

The firm stressed there was “no evidence” of customer data being stolen and has reported the incident to the Information Commissioner’s Office (ICO).

Hacker group claims responsibility

A collective calling itself ‘scattered lapsus$ hunters’, an alliance of the ‘shiny hunters’, ‘lapsus$’ and ‘scattered spider’ groups, has claimed responsibility.

All of these subsidiaries have been linked to major corporate breaches in the past twelve months.

Sam Kirkman, director of services at NetSPI, noted this incident shows just how much harder cybercriminals are becoming to predict by pooling resources.

“JLR has stated that they took proactive steps to contain the breach and minimise its impact, which is commendable” he said.

The group has released only limited evidence of its involvement, with experts cautioning that attribution in such cases is often unclear.

Disruption at scale

The timing of the cyber attack, coinciding with the launch of the new registration plates, has been interpreted as strategic.

Read more

Has Range Rover just abandoned the SUV?

Range Rover GT side profile in camouflage wrap, parked in an anechoic chamber for acoustic testing.

“Cybercriminals often aim for the biggest possible disruptive impact”, argued Jake Moore, global cybersecurity advisor at ESET.

“Striking at a time when more customers are likely to see potential delays…will have been a tactful decision made by the attackers.”

Patrick Burgess, a cybersecurity specialist at the Chartered Institute for IT, also warned the disruption could last “weeks, if not months”, if the firm’s core systems are affected.

The National Crime Agency confirmed it was investigating and working with partners to assess the incident.

Growing threat to manufacturers

The JLR breach follows a spate of high-profile cyber attacks on UK retailers and manufacturers, including Marks & Spencer, Co-op and Harrods.

Bridgestone Americas also reported a “limited cyber incident” on Sunday, the same day as JLR,in a sign the automotive sector is firmly in the crosshairs.

Comparitech data showed ransomware attacks on manufacturers jumped 57 per cent between July and August alone.

Experts have said criminals see the sector as particularly vulnerable because of the disruption that downtime can cause.

“Phishing, social engineering and account compromise remain the most common route of attack, while the size of targeted companies such as Harrods, M&S and Jaguar Land Rover show that no company is immune”, argued George Glass, associate managing director at Kroll.

For JLR, the immediate focus is restarting production lines that normally turn out around 1,000 cars a day.

Read more

M&S to face shareholder grilling over cyber attack recovery

Marks and Spencer was one of three UK retailers to be targeted

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • automotive
  • Co-op
  • Cyber
  • cyber attack
  • harrods
  • Jaguar
  • Jaguar Land Rover
  • JLR
  • Marks and Spencer
  • phishing
  • retail attack
  • scattered spider

Trending Articles

  • Five-star Mayfair hotel hit with HMRC winding-up petition

  • Revolut takes flight with launch of new airport lounges

  • It’s not just Jason Arday, most of sociology is a scam

  • IT consultant ordered to pay £50,000 after being accused of stealing Soho House members’ personal details

  • As it happened: FTSE 100 falls as Iran and US clash over Strait of Hormuz; Oil stockpiles ‘rapidly depleting’

More from CityAM

  • Has Range Rover just abandoned the SUV?

    Motoring
    Range Rover GT side profile in camouflage wrap, parked in an anechoic chamber for acoustic testing.
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • M&S chair: Tax and employment costs holding back Britain

    Retail
    Archie Norman, business leader, speaking at a corporate event wearing a suit and tie, engaging with the audience.
  • Champions Cup rugby team hacked in ransom attack with player data at risk

    Sport Business
    Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.
  • Accertify and Liminal Release First Empirical Study Proving Fraud-Cyber Convergence Works – and Defining How to Do It Right

    Business Wire
  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • Wasabi and Megaport Partner to Advance the Next Generation of AI and Cloud Infrastructure

    Business Wire
CityAM Canada

Independent Canadian business, markets and economic journalism, published by CityAM Publishing in Toronto. Read our editorial standards and corrections policy.

CityAM Publishing, 3 Borden Street #301, Toronto, Ontario M5S 2M8, Canada.
Newsroom enquiries: contact the editorial desk.

Follow

LinkedInXRSSApple News

Sections

BusinessMarketsEconomyTechnologyPoliticsEnergyPropertyOpinion

Newsroom

About usEditorial standardsCorrectionsOur journalistsContact

Company

AdvertisePrivacy noticeTerms of useCookie preferences

© 2026 CityAM Publishing. All rights reserved.

PrivacyTermsCookiesContact

Nothing published on CityAM Canada constitutes investment advice or a recommendation to buy or sell any security. CityAM Canada is an independent Canadian edition and is not affiliated with any UK publication.