Government

Cyberattack on JLR Prompts £1.5 Billion UK Government Intervention

The government has announced a support package, but a cybersecurity expert has raised some concerns.

The UK government has announced a £1.5 billion ($2 billion) loan guarantee for Jaguar Land Rover (JLR) in response to the highly disruptive cyberattack that recently hit the carmaker.

The government made the announcement on Sunday, saying that the support package is meant to “give certainty to its supply chain following a recent cyber-attack”.

“The loan from a commercial bank, backed by the Export Development Guarantee (EDG) provided by export credit agency UK Export Finance, will be paid back over five years and bolster JLR’s cash reserves so it can support its supply chain which has been greatly impacted by the shutdown,” the government said.

The government’s announcement points out that JLR is one of the UK’s largest exporters and is responsible for one of the largest automotive sector supply chains in the country. Roughly 34,000 people are employed directly by JLR and 120,000 in supply chain operations. 

Some experts believe the bailout will encourage cybercriminals to continue targeting UK companies with weak cybersecurity. 

“Personally I think the UK is going to be one to watch now,” said cybersecurity researcher Kevin Beaumont, who has been monitoring this and other major cyber incidents, “if I was an e-crime threat actor, I’d zero in on the UK.”

Advertisement. Scroll to continue reading.

Insurance news website The Insurer reported last week that JLR had failed to secure cyberinsurance ahead of the hacker attack, claims that the carmaker has refused to confirm or deny. 

The Guardian reported that JLR, which is owned by Tata Group, has outsourced cybersecurity and other IT services to Tata Consultancy Services (TCS), which also works with Marks & Spencer and Co-op, both believed to have been targeted by Scattered Spider, the same cybercrime group that has taken credit for the attack on JLR.

The cyberattack, discovered in late August, resulted in severe disruptions to the company’s internal systems and the shutdown of production lines. 

In a statement issued on September 25, JLR said it had managed to restore “sections of its digital estate”, including systems related to invoicing, parts logistics, and sales. On September 29, the company said some of its manufacturing operations will “resume in the coming days”.  JLR previously said production would resume on October 1 at the earliest. 

The company admitted that the cyberattack resulted in a data breach, but it has yet to clarify what type of information has been compromised. 

JLR has also yet to make public any estimate on the cyberattack’s financial impact. The British retailers believed to have been targeted recently by Scattered Spider reported losses of hundreds of millions of pounds. Co-op last week reported £206 million ($275 million) in lost sales, while Marks & Spencer in May estimated losses of £300 million ($400 million). 

Related: Ransomware Group Claims Attacks on Ascom, Jaguar Land Rover

Related: Cost of Data Breach in US Rises to $10.22 Million, Says Latest IBM Report

Related: Wytec Expects Significant Financial Loss Following Website Hack

Related Content

Data Breaches

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

Government

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. 

ICS/OT

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. 

ICS/OT

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Government

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

Incident Response

The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version