Full Breakdown
Jaguar Land Rover Faces Extended Shutdown Following Cyber Attack
9/8/2025, 9:00:53 PM
Overview of the Cyber Attack
Jaguar Land Rover (JLR), the UK's largest car manufacturer owned by Tata Motors, has been significantly impacted by a cyber attack that began on August 31, 2025. The attack forced JLR to shut down its IT systems to prevent further damage, resulting in halted production across its UK factories in Halewood, Solihull, and Wolverhampton, as well as operations in Slovakia, Brazil, India, and China. The disruption is expected to last until at least October, with reports suggesting that production could remain paused for most of September.
Impact on Production and Supply Chain
The cyber incident has immobilized JLR's operations, which typically produce around 1,000 vehicles daily. Thousands of production workers have been instructed to stay home while continuing to receive pay, allowing them to "bank" their hours for future use. The shutdown has also affected numerous suppliers, including Evtec, WHS Plastics, SurTec, and OPmobility, which collectively employ over 6,000 people in the UK. These suppliers have similarly paused operations, exacerbating the impact on JLR's supply chain.
Operational Challenges
JLR's dealerships have faced severe disruptions, unable to process vehicle registrations or access spare parts databases. Many have resorted to manual processes, including phone calls and paperwork, to manage orders and repairs. The timing of the attack coincided with the launch of new vehicle registration plates on September 1, a peak sales period for the automotive industry, further complicating the situation for dealerships.
Official Statements and Responses
In response to the attack, JLR has stated, “We continue to work around the clock to restart our global applications in a controlled and safe manner following the recent cyber incident.” The company is collaborating with third-party cybersecurity specialists and law enforcement to investigate the breach and restore operations. JLR has also notified the Information Commissioner’s Office about the incident, although there is currently no evidence of customer data being stolen.
Criticism and Opposition
Experts have expressed concern over the vulnerabilities exposed by the attack. Jake Moore, Global Cybersecurity Advisor at ESET, described the incident as a "frustratingly simple" attack that could have significant long-term ramifications for JLR. David Bailey, a professor of business economics at Birmingham University, warned that the attack could cost JLR approximately £5 million per day, emphasizing the potential for customers to seek alternatives if delays persist.
Claims of Responsibility
The cyber attack has been attributed to a group of hackers known as "Scattered Lapsus$ Hunters," which has previously targeted other retailers, including Marks & Spencer and the Co-op. The group claimed responsibility via a Telegram channel, sharing screenshots that allegedly show access to JLR's internal systems. This incident highlights the evolving nature of cybercrime, where attacks are strategically timed to maximize disruption.
What's Next
As JLR continues to work on restoring its systems, updates for employees and customers are expected regularly. The company aims to resume production as soon as it is safe to do so, while also addressing the broader implications for its supply chain and customer service operations. The ongoing situation serves as a reminder of the critical importance of cybersecurity in the modern manufacturing landscape.
