JLR production and sales systems hit by cyber-attack
JLR has confirmed that global production and sales have been “severely disrupted” by a cyber-attack.
The carmaker, owned by India’s Tata Motors, confirmed on Tuesday that it had been “shutting down our systems” to mitigate the impact of a “cyber incident” that started Sunday.
JLR said it had taken immediate action to mitigate the impact of the hack and that there was no evidence that any customer data had been stolen.
It’s believed to have halted production at the Solihull site, where the Range Rover and Range Rover Sport are built.
The attack coincides with the September number plate change, traditionally a significant time for car sales, and comes after JLR pushed back first deliveries of the Range Rover Electric to 2026 to allow for more testing time and for EV demand to pick up, potentially impacting the arrival of the big rebrand of Jaguar. The company also told staff over the summer that it would axe up to 500 management jobs in the UK as part of a voluntary redundancy scheme.
In a statement, the carmaker wrote: “JLR has been impacted by a cyber incident. We took immediate action to mitigate its impact by proactively shutting down our systems.
“We are now working at pace to restart our global applications in a controlled manner.
“At this stage there is no evidence any customer data has been stolen but our retail and production activities have been severely disrupted.”
JLR is the latest British firm to be hit by cyber-attacks, following high-profile incidents at Marks & Spencer and Co-op Group earlier this year.
Lauren Wills-Dixon, head of privacy at law firm Gordons and an expert in cyber security, said: “Often with cyber attacks, the risk to businesses is that hackers will access personal data, either of employees or customers. In this case, it seems the target was to cause maximum disruption to the production line. It’s not a new threat for manufacturing companies, but it’s an alternative way in which malicious groups are targeting businesses – and one that they must be aware of.
“From the initial reports it seems that Jaguar Land Rover detected this attack while in progress, which suggests a robust cyber security programme is in place. However, this is another reminder of the need for stringent security measures required in a world where cyber attacks are increasingly common, both for small and large businesses.”
Dray Agha, senior manager of security operations at cyber security firm Huntress, also said that the incident highlights the critical vulnerability of modern manufacturing, “where a single IT system attack can halt a multi-billion-pound physical production line, directly impacting sales, especially during a key period like a new registration month”.
Agha continued: “Cybercriminals know this, and many leverage the stopped clock of business functions as the leverage they need to force capitulation of ransomware demands. It is not known if ransomware was involved in the Jaguar Land Rover attack, but ransomware actors target manufacturers for a reason.
“While the quick shutdown of systems was a textbook damage limitation tactic that likely prevented a data breach, it underscores the immense recovery challenge companies now face in safely rebooting complex, interconnected operations after an attack. In 2025, there are still companies that wait until a devastating cyberattack to invest in a robust security posture. Fortunately, Jaguar Land Rover appears to have had processes and procedures in place to ‘lessen the effect’ and return to business as usual.”
And Marijus Briedis, CTO at NordVPN, said: “While JLR states no customer data has been compromised, this doesn’t mean consumers are entirely safe. We often see that information gathered from an attack is reported later, sometimes when it is too late for people to take action. We may see highly targeted phishing campaigns, so customers should be on high alert for suspicious emails or messages that claim to be from JLR asking for personal details.
“In a global industry like car manufacturing, a single point of failure can disrupt the entire supply chain and ecosystem, leading to problems that are far more difficult to untangle than the initial incident itself. This one blip could have a ripple effect for weeks to come.
“Every company of JLR’s scale must start viewing a cyberattack not as a possibility, but as an inevitability. As the attacks at JLR, M&S, the Co-op and countless others show, it’s no longer about whether you will be attacked, but when.”

