Cyber Incident Victim: Jaguar Land Rover
Date:
Sep 2025
Location:
United Kingdom
Summary
Jaguar Land Rover faced a crippling cyber attack that halted production, triggering a sales plunge with wholesale volumes falling over 40% and retail sales dropping 25% in the final quarter. The operational turmoil, exacerbated by the phase-out of legacy Jaguar models and US tariffs, drove a pre-tax loss of nearly £500m for the second quarter and a £134m loss for the first half, reversing prior year profits. Production normalized later, and the company asserts strong recovery momentum, bolstered by a £1.5bn government aid package and a £500m supply chain funding effort.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Jaguar Land Rover suffered a severe cyber attack in September 2025 that directly halted its global vehicle production, marking the most costly such incident in British history at the time. The attack's immediate impact was a complete stoppage of manufacturing operations, creating a significant disruption to the company's supply chain and delivery schedules. Production did not return to normal levels until mid-November, a two-month outage that severely constrained the volume of vehicles available for wholesale and retail sale in the subsequent quarter. This operational paralysis was a primary driver behind a catastrophic financial performance in the second quarter of its financial year, where the company reported a pre-tax loss of £485 million, a stark reversal from a £398 million profit in the same period the prior year. The financial damage extended through the first half of the financial year, culminating in a loss of £134 million compared to a profit of £1.1 billion in the first half of 2024. The incident's scale prompted a coordinated response from the UK government, which announced a £1.5 billion financial support package for the company, while JLR itself arranged a separate £500 million funding injection specifically to stabilize its supply chain partners affected by the production freeze.

The sales consequences of the production halt were severe and quantifiable in the final quarter of 2025. Wholesale volumes, representing vehicles shipped to dealers, plummeted by over 40% year-on-year to 59,200 units. Retail sales, those directly to consumers, fell by 25% to 79,600 units. JLR explicitly linked this decline to the cyber incident, noting that the time required to distribute vehicles globally once production resumed further suppressed volumes. However, the company also identified two compounding external factors: the planned cessation of production for legacy Jaguar models ahead of a new model launch and incremental U.S. tariffs impacting its exports to that key market. The attack's ripple effect was felt industry-wide, as data from the Society of Motor Manufacturers and Traders indicated that overall UK car production dropped by 27.1% in September 2025, directly correlating with JLR's halted output. Chief Executive Adrian Mardell acknowledged the "significant challenges" of the quarter, emphasizing that the company had made "strong progress in recovering its operations safely and at pace" following the cyber incident, though the full recovery of sales and financial stability was projected to extend beyond the immediate quarter due to the combined pressures.
