Russian State-Linked Group Accused of £2.5 Billion JLR Cyberattack, UK Demands Answers

Experts described the ransomware encryption algorithm used in the JLR attack as 'mind-blowing' and previously unseen, marking a novel variant in this incident.
The attack is dated to begin on August 31, 2025, with production halted by September 1 and lasting nearly six weeks, tied to an estimated cost of about £2.5 billion and a measured drag on UK GDP.
An estimated 5,000 businesses across Jaguar Land Rover’s supply chain were affected by the breach, underscoring the wider industrial impact beyond the carmaker itself.
UK government support for JLR included an unprecedented loan intervention of about £1.5 billion to stabilize the supply chain (reports also note a roughly $2 billion loan guarantee in other coverage).
The investigation involved a broad coalition beyond local authorities, including Google's Mandiant and Palo Alto Networks alongside FBI, NCA, and the National Cyber Security Centre.
A New York Times investigation has concluded that a Russian state-linked group — not the criminal hackers who initially claimed credit — carried out the cyberattack on Jaguar Land Rover last year, costing the UK economy £1.9 billion ($2.5 billion). The New York Times reported that Microsoft tracked the group in real time and alerted JLR during the breach itself.
The attack began on August 31, 2025, shut down production lines at three JLR plants by September 1, and paralyzed operations for nearly six weeks. The UK government was forced to step in with an unprecedented £1.5 billion loan guarantee to keep JLR's supply chain from collapsing, gadgetreview.com reported.
Within days of the breach, a group calling itself "Scattered Lapsus$ Hunters" claimed responsibility on Telegram and posted screenshots of JLR's internal systems. Investigators now believe this was a smokescreen. The Next Web reported that the actual operation differed sharply from known criminal groups, using a ransomware encryption algorithm that experts described as "mind-blowing" and previously unseen.
Weeks before the breach, attackers ran a vishing campaign — voice phishing — where they posed as IT staff to trick JLR employees into handing over administrator passwords. That level of preparation pointed toward a state-level operation, not opportunistic criminals. Whether the Kremlin directly ordered the attack remains unclear. Russia's spokesman Dmitry Peskov denied any involvement, calling the accusations baseless.
Production at JLR's Solihull, Halewood, and Wolverhampton plants stayed dark for nearly six weeks. JLR lost an estimated £50 to £70 million in revenue every week during the shutdown, us.headtopics.com reported. A phased restart only began on October 6, starting with the Wolverhampton engine plant. JLR's wholesale sales volumes fell 43.3% in Q3 fiscal 2026 as a result.
The damage spread far beyond the factory gates. More than 5,000 businesses in JLR's supply chain were hit, according to gadgetreview.com. Smaller suppliers were forced to lay off workers or apply for government benefits. The Bank of England directly linked the shutdown to a 0.2% drag on UK GDP growth. Ciaran Martin, the former head of the UK's cyber agency, called it "by some distance, the most economically damaging cyber event in UK history."
Business Secretary Peter Kyle announced the £1.5 billion loan guarantee on September 28, 2025, to stop the supply chain from breaking down entirely. Chancellor Rachel Reeves said the move was needed to protect what she called "the jewel in the crown of our economy." The intervention was the largest of its kind ever deployed for a single cyber incident in the UK.
Critics pushed back hard. Some cybersecurity experts warned the bailout sets a dangerous precedent — essentially telling hackers that the UK government will cover the losses of companies with weak defenses. Reports in the Financial Times and The Telegraph also noted that JLR had no cyber insurance at the time of the attack, raising questions about whether taxpayers were subsidizing corporate negligence, uk.headtopics.com noted.
UK MPs are now pressing the government for more transparency about the investigation. MP Liam Byrne called the attack a "digital siege," while MP Graeme Downie argued that the UK is "already in conflict with Moscow" — even if ministers won't say so publicly, uk.headtopics.com reported. The investigation drew in a broad coalition: the FBI, the National Crime Agency, the National Cyber Security Centre, Google's Mandiant, and Palo Alto Networks all played roles.
The Cyber Monitoring Centre officially graded the JLR incident a "Category 3 Systemic Event" on October 22, 2025 — its most serious classification. Security analysts say the case exposes how a single cyberattack on one manufacturer can threaten an entire industrial ecosystem. Calls are growing for the UK to treat cyber resilience as a core pillar of national economic security, not just an IT problem, dailymail.com reported.
Publishers
12
Articles
5
Reach
17