01Summary
On May 5, 2025, Scattered Spider launched a targeted attack against JLR. The group used social engineering to gain initial access, then deployed ransomware across critical systems. The attack forced the company to shut down several production lines for nearly two weeks, affecting thousands of vehicles. Customer and employee personal data was also exfiltrated.
02Background
Jaguar Land Rover is one of the UK's largest automotive manufacturers and a major exporter. Like many manufacturers, its complex supply chain and reliance on IT systems make it highly vulnerable to ransomware.
03Key revelations
- 01High financial impact of ransomware on manufacturing operations.
- 02Persistent effectiveness of Scattered Spider social engineering tactics.
04Technical analysis
Attackers used vishing to compromise IT support staff, gained domain admin access, and deployed ransomware. They also exfiltrated large volumes of data before encryption. The attack heavily impacted manufacturing execution systems (MES).
- Attack vector
- Vishing / Social Engineering
- Attack method
- Ransomware + Double Extortion
- Initial access
- Vishing (Voice Phishing)
- Lateral movement
- Privilege Escalation
- Exfiltration
- Bulk data extraction
- Tool / malware
- Custom ransomware
- Malware type
- Ransomware
Vulnerabilities exploited
- Social Engineering
- Weak helpdesk verification processes
05Threat actor
Scattered Spider – notorious for using social engineering and vishing to target large, high-value organizations.
Aliases
- Scattered LAPSUS$ Hunters
- SH
Attribution sources
- Jaguar Land Rover statements
- BleepingComputer
- The Times
- Cybersecurity firms
06Victims and impact
Countries affected
- United Kingdom
- Global
07Data exposed
Data types
- Customer PII
- Employee Data
- Supplier Information
- Internal Business Data
08Financial damage
Estimated losses exceeded £200 million due to production downtime, lost sales, and recovery costs.
09Timeline
- 2025-05-05Attack begins, systems compromised.
- 2025-05-06JLR publicly acknowledges the incident.
- 2025-05-20Major production lines restored.
10Reaction and fallout
Public reaction
Widespread concern over production delays and data privacy.
Political impact
UK government expressed serious concern over critical manufacturing sector security.
11Legal
Ongoing ICO and regulatory investigations.
Civil lawsuits
- Multiple class-action and supplier claims
12Aftermath
Policy changes
- Stronger cybersecurity requirements for UK automotive sector.
Security improvements
- Major overhaul of identity verification processes
- Improved network segmentation
- Enhanced backup and recovery capabilities
13Significance and legacy
Significance
One of the most expensive and disruptive ransomware attacks on a UK manufacturer in 2025.
Legacy
Became a case study for ransomware impact on physical manufacturing and supply chains.
14Disclosure and media
- Authentication
- Ransom note and hacker leak site
Publishing organisations
- BBC
- The Times
- Reuters
- BleepingComputer
15Field notes
- 01The attack caused significant delays in the production of new Jaguar and Land Rover models.
16Resolution
Production gradually restored by late May 2025; data was leaked by the attackers.
17Sources
Official documents
- JLR Cyber Incident Statement
References
- [1]Jaguar Land Rover official updates
- [2]BBC News
- [3]The Times coverage









