A threat actor, going by the alias “Rey,” claims to have breached the internal systems of British automaker Jaguar Land Rover (JLR) and leaked around 700 internal documents containing sensitive technical and operational data.

The breach, first announced on a dark web forum, reportedly includes proprietary source code, vehicle development logs, tracking datasets, and an employee database with usernames, email addresses, display names, and time zones.
If verified, the incident could cause serious problems for the company, putting intellectual property and employee privacy.
See also: Hunters International says it published Tata Technologies data
Jaguar Land Rover data leak
According to ThreatMon 's post on X, the leaked data covers many categories of internal automotive operations.
Development logs, often used to track software iterations and hardware integration processes, could reveal vulnerabilities in vehicle firmware or Jaguar Land Rover embedded systems.
In addition, the source code leak could expose the company's algorithms related to driver assistance systems, infotainment platforms, or electric vehicle battery management.
Cybersecurity analysts speculate that the breach likely originated from a compromised corporate server or cloud repository (based on the volume and diversity of the data).
See also: 2024: Human error responsible for 95% of data breaches
The employee database, which includes metadata such as time zones and display names, could be used by the attacker for phishing and credential-stuffing attacks.
The technical nature of the leaked data – particularly the inclusion of tracking datasets – could also benefit competitors seeking information about JLR's autonomous driving or telematics systems.
The exposed data does not appear to include financial or customer information, but the exposure of internal communications and technical specifications could indicate industrial espionage.

Rey has not revealed the exact method of breaching Jaguar Land Rover, but it is likely that vulnerabilities in JLR's supply chain software or a misconfigured API endpoint.
Jaguar Land Rover has yet to issue an official statement regarding the breach, but cybersecurity firms monitoring the activity have begun to validate the authenticity of the leaked data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New York sues Allstate over data breach and security gaps
Automakers: How to strengthen cybersecurity
Enhanced Encryption – Encryption of sensitive customer and vehicle data
Strict access controls – Implement multi-factor authentication (MFA) and role-based access to sensitive information.
Regular security audits – Conducting penetration testing and vulnerability assessments.
Supply Chain Security – Ensuring that third-party suppliers follow strict cybersecurity practices.
Incident Response Planning – Robust plans for detecting, mitigating, and recovering from breaches.
With the increasing reliance on connected vehicles, automakers must prioritize cybersecurity to protect customer trust, intellectual property, and business continuity.
Source: cybersecuritynews.com
