EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2025-jaguar-land-rover-attack
063/430

File EL-0368CriticalResolvedData Breach / Ransomware / Business Disruption

Jaguar Land Rover Cyber Attack

Also filed as JLR Ransomware Attack · Jaguar Land Rover Supply Chain Breach

Sophisticated ransomware attack on Jaguar Land Rover that caused major production disruptions across UK factories and exposed customer and employee data.

  • #automotive
  • #manufacturing
  • #ransomware
  • #supply-chain
  • #uk
Notoriety9/10
Event
5 May 2025
Disclosed
6 May 2025
Target
Jaguar Land Rover
Actor
Scattered Spider
Scale
1.2M people
Status
Resolved

01Summary

On May 5, 2025, Scattered Spider launched a targeted attack against JLR. The group used social engineering to gain initial access, then deployed ransomware across critical systems. The attack forced the company to shut down several production lines for nearly two weeks, affecting thousands of vehicles. Customer and employee personal data was also exfiltrated.

02Background

Jaguar Land Rover is one of the UK's largest automotive manufacturers and a major exporter. Like many manufacturers, its complex supply chain and reliance on IT systems make it highly vulnerable to ransomware.

03Key revelations

  1. 01High financial impact of ransomware on manufacturing operations.
  2. 02Persistent effectiveness of Scattered Spider social engineering tactics.

04Technical analysis

Attackers used vishing to compromise IT support staff, gained domain admin access, and deployed ransomware. They also exfiltrated large volumes of data before encryption. The attack heavily impacted manufacturing execution systems (MES).

Attack vector
Vishing / Social Engineering
Attack method
Ransomware + Double Extortion
Initial access
Vishing (Voice Phishing)
Lateral movement
Privilege Escalation
Exfiltration
Bulk data extraction
Tool / malware
Custom ransomware
Malware type
Ransomware

Vulnerabilities exploited

  • Social Engineering
  • Weak helpdesk verification processes

05Threat actor

Scattered Spider – notorious for using social engineering and vishing to target large, high-value organizations.

Aliases

  • Scattered LAPSUS$ Hunters
  • SH

Attribution sources

  • Jaguar Land Rover statements
  • BleepingComputer
  • The Times
  • Cybersecurity firms

06Victims and impact

Countries affected

  • United Kingdom
  • Global

07Data exposed

Data types

  • Customer PII
  • Employee Data
  • Supplier Information
  • Internal Business Data

08Financial damage

Estimated losses exceeded £200 million due to production downtime, lost sales, and recovery costs.

09Timeline

  1. 2025-05-05Attack begins, systems compromised.
  2. 2025-05-06JLR publicly acknowledges the incident.
  3. 2025-05-20Major production lines restored.

10Reaction and fallout

Public reaction

Widespread concern over production delays and data privacy.

Political impact

UK government expressed serious concern over critical manufacturing sector security.

11Legal

Ongoing ICO and regulatory investigations.

Civil lawsuits

  • Multiple class-action and supplier claims

12Aftermath

Policy changes

  • Stronger cybersecurity requirements for UK automotive sector.

Security improvements

  • Major overhaul of identity verification processes
  • Improved network segmentation
  • Enhanced backup and recovery capabilities

13Significance and legacy

Significance

One of the most expensive and disruptive ransomware attacks on a UK manufacturer in 2025.

Legacy

Became a case study for ransomware impact on physical manufacturing and supply chains.

14Disclosure and media

Authentication
Ransom note and hacker leak site

Publishing organisations

  • BBC
  • The Times
  • Reuters
  • BleepingComputer

15Field notes

  1. 01The attack caused significant delays in the production of new Jaguar and Land Rover models.

16Resolution

Production gradually restored by late May 2025; data was leaked by the attackers.

17Sources

Official documents

  • JLR Cyber Incident Statement

References

  1. [1]Jaguar Land Rover official updates
  2. [2]BBC News
  3. [3]The Times coverage
Fact sheetEL-0368

Dates

Event
5 May 2025
Started
5 May 2025
Ended
20 May 2025
Duration
15 days
Discovered
5 May 2025
Disclosed
6 May 2025
Ongoing
No

Target

Organisation
Jaguar Land Rover Automotive plc
Type
Automotive Manufacturer
Sector
Automotive / Manufacturing
Country
United Kingdom

Actor

Name
Scattered Spider
Type
Criminal Gang
Motivation
Financial gain through ransomware extortion and operational disruption.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
1,200,000
Records
1,200,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Damage
$250,000,000
Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.