Jaguar Land Rover (JLR) has confirmed that data was stolen in the large-scale cyberattack that has paralyzed its global operations and forced production to a halt since early September.
The British luxury automaker, owned by India’s Tata Motors, is working with external cybersecurity experts to investigate the breach and restore critical systems.
The incident, first disclosed on September 2, 2025, led JLR to shut down its IT infrastructure as a precaution, disrupting manufacturing and sales worldwide. Production has stopped at key UK plants in Solihull, Halewood, and Wolverhampton, where roughly 1,000 vehicles a day are built. The outage has also impacted facilities in Slovakia and India, along with dealer operations, vehicle handovers, and parts ordering.
At the time of the disclosure, JLR maintained there was no indication of customer data compromise. However, in an updated statement on September 10, the company acknowledged that “some data has been affected” during the attack. However, the nature of the data—whether belonging to customers, employees, or the company itself—remains undisclosed. Regulators, including the UK’s Information Commissioner’s Office (ICO), have been notified.
According to a company spokesperson, as soon as they became aware of the cyber incident, they have been working around the clock, alongside third-party cybersecurity specialists, to restart the global applications in a controlled and safe manner.
JLR added that its forensic investigation is ongoing and assured to contact individuals if their data is confirmed to be compromised.
The shutdown has raised alarm in the UK government over the potential economic fallout, as the disruption could last for weeks. A hacking group known as “Scattered Lus$”, previously linked to attacks on UK retailers, has reportedly claimed responsibility.
Most production staff remain off work while JLR continues to assess the situation daily. The company has apologized for the severe disruption caused by the attack.














Comments