The Jaguar Land Rover cyberattack: the UK’s costliest hack

In late August 2025, managers at Jaguar Land Rover’s Halewood plant noticed strange behaviour in the company’s IT systems. Within a day, JLR’s own teams had detected an intrusion into the network, and the company made the drastic decision to shut down its systems entirely to contain the attack.

The consequences were severe. Production was halted for almost six weeks, an unusually long shutdown for a single cyber incident, and normal output only resumed on 8 October 2025. Retail operations were disrupted too, leaving dealers unable to register new cars for weeks.

The financial damage has been enormous. JLR reported that the attack cost 196 million pounds in a single quarter, contributing to an overall quarterly loss of 559 million pounds. Across the wider economy, the total damage from the incident has been estimated at 1.9 billion pounds, making it the most costly cyberattack the UK has ever recorded.

The disruption did not stop at JLR’s own factories. Hundreds of smaller suppliers, many of them dependent almost entirely on JLR contracts, saw their supply chain orders vanish overnight, putting thousands of additional jobs at risk across the country.

Recognising the scale of the crisis, the UK government stepped in with a loan guarantee designed to unlock up to 1.5 billion pounds, giving suppliers the certainty they needed to keep paying staff while JLR’s systems slowly came back online.

Adapted from BleepingComputer and Cybersecurity Dive, September – November 2025