HomeSecurityJaguar Land Rover: Cyberattack led to data theft

Jaguar Land Rover: Cyberattack led to data theft

Jaguar Land Rover (JLR) has confirmed that the recent cyberattack that hit its systems was not limited to disrupting operations, but also led to data theft. The incident forced the company to temporarily halt production and ask staff to stay off work while an investigation into the scope of the breach continues.

Jaguar Land Rover cyberattack data theft

JLR, which operates as a subsidiary of Tata Motors India after being acquired by Ford in 2008, is one of the world's largest luxury carmakers. With annual revenues of more than $38 billion and about 39,000 employees, the company produces more than 400,000 vehicles each year, making the strike particularly worrisome for the global auto industry.

The timeline of the attack

The breach was revealed on September 2, when Jaguar Land Rover announced that its manufacturing operations had suffered a “serious disruption.” The company immediately mobilized defense mechanisms and is working with the UK’s National Cyber ​​Security Centre (NCSC), while also notifying relevant regulators of the data breach.

See also: HackerOne confirms data breach

In a recent statement, JLR said: "Since becoming aware of the incident, we have been working continuously with external experts to restart our systems in a controlled and secure manner. We now have reason to believe that some data has been affected and will update stakeholders where necessary."

Despite transparency efforts, the company declined to provide further details about the type of data leaked and the potential impact on customers.

Jaguar Land Rover: Cyberattack led to data theft

Who is behind the attack?

Jaguar Land Rover has not officially attributed the cyberattack to a specific group, and no known ransomware gang has yet claimed responsibility. However, an organization calling itself “Scattered Lapsus$ Hunters” has appeared on Telegram claiming to be behind the breach. The group even posted screenshots of JLR’s internal SAP system, claiming to have also deployed ransomware on the company’s servers.

The organization claims to be made up of cybercriminals from the notorious Lapsus$, Scattered Spider , and ShinyHunters. This is not the first time these names have been in the news: in the past, their members have been linked to large-scale attacks against tech giants.

See also: Workday confirms data breach

A repeating pattern

The “Scattered Lapsus$ Hunters” have a recent history of targeted attacks. They are believed to be responsible for a series of data breaches on the Salesforce, leveraging social engineering techniques and stolen OAuth tokens to gain access to corporate accounts.

The list of victims is indicative of the severity: Google, Cloudflare, Elastic, Palo Alto Networks, Zscaler, Proofpoint, CyberArk, BeyondTrust, JFrog, Fastly, Qualys, Workday, Cato Networks, HackerOne, BugCrowd and Rubrik. The fact that leading companies in the cybersecurity and cloud space were exposed shows how sophisticated and dangerous these methods are.

Why the attack on JLR matters

JLR is not just another organization that has been the victim of a cyberattack. The automotive industry has become a particularly attractive target for hackers, as modern production chains are completely dependent on digital systems. An interruption of operations can mean delivery delays, billions in financial losses and damage to the company's reputation.

See also: CyberVolk ransomware targets critical infrastructure

At the same time, data theft can include not only corporate documents, but also customer or supplier information, which could pave the way for further attacks and fraud.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Jaguar Land Rover: Cyberattack led to data theft

The broader message

The JLR incident serves as a wake-up call for the entire industry. As companies increasingly integrate digital tools into their processes, these types of attacks are becoming more destructive and sophisticated. Traditional defenses are not enough, and the need for continuous staff training, adoption of advanced security solutions and cooperation with government agencies is becoming imperative.

JLR, with the support of the NCSC, is trying to recover. Whether it can limit the consequences and strengthen its resilience against future attacks will be an indicator of how the entire automotive industry will face the challenges of the new digital age.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS