News Article · Jun 27, 2026 at 2:41 AM
2 min read 0
Member
Russian Hackers Behind Jaguar Land Rover Ransomware Attack That Cost UK $2.5B
Security #cyberattack #ransomware #Jaguar Land Rover #Russian hackers #New York Times #UK economy #automotive security

Russian Hackers Behind Jaguar Land Rover Ransomware Attack That Cost UK $2.5B

A Russian hacker collective is responsible for the ransomware attack on Jaguar Land Rover that shut down production for nearly six weeks and cost the UK economy an estimated $2.5 billion.

Listen to this article 3 min

A loose collective of Russian hackers orchestrated the ransomware attack that crippled Jaguar Land Rover in late 2025, according to a New York Times investigation published Thursday. The breach began on August 31, 2025, and shut down production across JLR’s factories for nearly six weeks, costing the British economy an estimated $2.5 billion.

The attack used what investigators described as “mind blowing” encryption, which proved exceptionally difficult to decrypt and contributed to the extended outage. The hackers initially took credit under a pseudonym before the investigation tied them to known Russian cybercriminal networks.

Attack Impact and Encryption Method

The encryption method deployed against Jaguar Land Rover was unlike typical ransomware, according to cybersecurity experts briefed on the investigation. The hackers used a custom variant that encrypted files in parallel across the company’s manufacturing and administrative systems, preventing even partial recovery from backups for weeks.

  • Production halted at all JLR factories in the UK, Slovakia, and China for nearly six weeks.
  • Estimated $2.5 billion economic impact includes lost sales, supply chain disruption, and remediation costs.
  • Hackers demanded a ransom but the amount has not been disclosed. JLR did not confirm payment.
  • UK National Cyber Security Centre and the FBI assisted in the investigation.
  • Attack affected over 40,000 employees and thousands of suppliers.

Broader Implications for Automotive and Industrial Security

This attack marks one of the most damaging ransomware incidents ever against a major manufacturer. The automotive industry has been a growing target because of the complexity of its supply chains and the difficulty of securing legacy industrial control systems. The six week shutdown demonstrates the catastrophic consequences when encryption can’t be quickly reversed.

Jaguar Land Rover has since revamped its cybersecurity posture, implementing network segmentation and more frequent backup testing. But the incident underscores the vulnerability of just in time manufacturing to ransomware. The UK government is now reviewing whether to mandate minimum cybersecurity standards for critical infrastructure operators, including carmakers.

No arrests have been made, and the investigation continues. The NCSC has warned that similar attacks are likely against other manufacturers unless defenses improve across the sector.

Fact check

  • Russian hackers were behind the Jaguar Land Rover ransomware attack that began on August 31, 2025.

    reported · source

  • The attack cost the UK economy an estimated $2.5 billion.

    reported · source

  • The attack shut down production across JLR's factories for nearly six weeks.

    reported · source

  • The encryption used was described as 'mind blowing' by investigators.

    reported · source

Source reporting (3)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 734 users online: 0 registered, 726 guests and 8 bots.

Most users ever online was 2,919 on 27 Jun 2026, 4:35 am.

Bots: AhrefsBot Applebot Bingbot Googlebot Other Bot Other Crawler Other Spider SemrushBot

Users active in the past 15 minutes. Total registered members: 361