CSIDB logo
Incident

Jaguar Land Rover

Incident posture

Attack window
Aug 2025
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:21

Linked entities

Victim
Jaguar Land Rover
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Aug 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack on the British automotive manufacturer Jaguar Land Rover forced a prolonged shutdown of vehicle production, disrupted repairs and maintenance across multiple facilities, and compromised personal data belonging to current and former employees and contractors. The incident is estimated to have caused roughly £1.9 billion in financial losses, marking it as the most economically damaging cyber event to hit a UK organisation to date. The breach triggered regulatory scrutiny, raised the prospect of legal action, and exposed the company to broader supply-chain risk, as IT vendors were identified as the initial entry point. In response, the carmaker arranged credit access and a dedicated helpline for affected individuals while engaging with regulators. The episode also prompted its IT services partner to pilot standardised, AI-led cybersecurity response frameworks aimed at limiting fallout from similar attacks on other major clients.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In August 2025, Jaguar Land Rover (JLR), the British luxury automotive manufacturer, suffered a cyberattack that forced a halt to its manufacturing operations and compromised the personal data of employees and contractors. The incident originated through IT vendors associated with the company and disrupted vehicle production, repairs, and maintenance across several JLR facilities. TCS, which manages JLR's back-end IT systems under a five-year IT transformation deal signed in 2023 and valued at $1 billion, was closely involved in the response. TCS management stated that the attack did not enter through its own systems. The cyberattack prompted close oversight from senior Tata Group leadership, with weekly updates provided to Tata Sons chairman Natarajan Chandrasekaran. The incident was reviewed by TCS chief operating officer Aarthi Subramaniam, Tata Sons chief digital officer Aparna Ganesh, and Sudeep Mazumdar, vice-president and manufacturing head for TCS UK and Ireland.

JLR confirmed the data leak, stating that it was in touch with affected individuals and regulators. A company spokesperson told Mint, "From the ongoing forensic investigation, JLR believes that certain data related to current and former JLR employees and contractors was affected by the cyber incident." The carmaker remained engaged with regulators and reached out to those impacted, while also arranging credit access and a dedicated helpline for affected employees and vendors. The breach was reported to have triggered regulatory scrutiny and the risk of legal action against JLR, and was described as the most economically damaging cyber incident to hit the UK. Financial losses associated with the shutdown of vehicle production reached £1.9 billion, according to Tokio Marine HCC International's annual cyber incidents report. The prolonged breach was estimated to result in losses of up to $1 billion in another assessment, while Safe Security's Saket Modi estimated the overall cost of the fallout at around $1.5 billion.

TCS booked an exceptional loss of $150 million due to vehicles not being produced during the affected period, as acknowledged by TCS chief executive P.B. Balaji during a post-earnings media briefing. Balaji added that further recovery would depend on how quickly production could be ramped up. Following the breach, TCS began piloting a set of standardised cybersecurity measures for its largest customers, forming six specialised teams with a combined strength of about 150 professionals to test predefined procedures aimed at reducing damage during cyber incidents. The measures being tested included video-based verification of employees responsible for critical IT support, the use of artificial intelligence tools to monitor hacker movement within systems, and the deployment of additional cybersecurity layers to strengthen network protection. Once validated, the results of these pilots were to be showcased to clients and integrated into their IT environments.

The JLR incident was the third cyber incident involving TCS clients in a year, following attacks on British retailers Marks & Spencer and Co-operative Group Ltd. Like the M&S breach, the JLR attack originated through IT vendors. Tokio Marine HCC International included the JLR ransomware attack in its list of the ten most significant cyber incidents of 2025, noting that ransomware, technology supply-chain compromise, and cloud infrastructure concentration continue to drive systemic cyber risk for organisations worldwide.

Sources

Sources available to members: 2 sources.

CSIDB