Sunday, 16 August 2026
The Verified Journalism Press

Journalism with its sources attached.

Sections
WORLD
AUSTRALIA
INDIA
BUSINESS
TECHNOLOGY
SCIENCE
SOCIETY
RIGHTS
CORRUPTION
CULTURE
OPINION
FAMOUS
The Press
Latest
Brussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached AustraliaBrussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached Australia
Markets
ASX 200
S&P 500
Nasdaq
FTSE 100
Nikkei
Gold
Brent
AUD / USD
AUD / EUR
AUD / GBP
AUD / JPY
Bitcoin
Ethereum
Yahoo · ECB · CoinGecko

Front page / Technology

Cybersecurity

Investigators now blame Russian hackers for the Jaguar Land Rover shutdown, not the crew that claimed it

The New York Times reported in June 2026 that the attack which halted Britain's largest carmaker for five weeks was carried out by Russian hackers who never asked for money. The Cyber Monitoring Centre puts the cost to the United Kingdom economy at 1.9 billion pounds, the most damaging cyber incident in British history.

Jaguar - Land Rover Factory - Halewood - geograph.org.uk - 2496590
Jaguar - Land Rover Factory - Halewood - geograph.org.uk - 2496590. Photograph: Anthony Parkes, CC BY-SA 2.0

The cyberattack that halted production at Jaguar Land Rover for about five weeks was carried out by Russian hackers, not by the young, English speaking extortion collective that claimed it on Telegram under the name Scattered Lapsus$ Hunters, The New York Times reported on 26 June 2026, citing people familiar with the investigation.

TechCrunch, reporting on the Times findings the same day, said Microsoft had been tracking the Russian group and passed information about the hackers to Jaguar Land Rover, and that the FBI, Britain's National Crime Agency, the National Cyber Security Centre, Google's Mandiant unit and Palo Alto Networks all worked on the investigation.

Two details in that reporting matter more than the label. Infosecurity Magazine, summarising the Times account, reported that no ransom demand was ever made and that the malware deployed locked servers without asking for payment. TechCrunch reported that investigators have not established whether the hackers were working for the Russian government, operating as independent criminals, or acting with the government's tacit approval.

That distinction changes what the incident was. An extortion attempt is a commercial crime. An intrusion that stops a national manufacturer and never asks for money is closer to sabotage, and British politicians have begun saying so. LBC reported that the Labour MP Graeme Downie said he had spent months pressing the government to be more open about the incident, and that Al Carns, a former armed forces minister, described an attack causing billions in damage with no ransom demand. The Cabinet Office declined to comment on ongoing investigations, LBC reported, but said it had provided daily support to Jaguar Land Rover and supplied expertise from the National Cyber Security Centre.

Jaguar Land Rover shut down its own IT systems on 1 September 2025, a day after intruders reached them, and did not restore full production for about five weeks.

The cost figures are now settled. The Cyber Monitoring Centre, an independent body that grades British cyber incidents, classified the event as a Category 3 systemic incident and modelled a financial impact of 1.9 billion pounds on the United Kingdom economy, within a range of 1.6 billion to 2.1 billion pounds, affecting more than 5,000 organisations. The centre attributed most of that loss to forgone manufacturing output, estimating around 108 million pounds a week during the five week shutdown as production fell by roughly 5,000 vehicles a week.

The company's own accounts show the damage. Tata Motors booked 196 million pounds of exceptional direct costs in the quarter, pushing its passenger vehicle arm into loss, according to reporting by just-auto. Jaguar Land Rover cut its earnings margin guidance for the 2026 financial year to a range of zero to 2 per cent, from 5 to 7 per cent previously.

The 1.5 billion pounds of state support announced after the shutdown was never drawn. UK Export Finance offered to guarantee up to 1.5 billion pounds of commercial lending, covering 80 per cent of any default, as TechCrunch reported in September 2025. Business Matters magazine subsequently reported that the facility was only formally signed in November and was never used, and that the company raised money from commercial banks instead. The guarantee was a backstop that went untouched.

A separate intrusion had already hit the carmaker earlier in 2025. The HellCat ransomware group breached Jaguar Land Rover in March 2025, using Jira credentials harvested years earlier by infostealer malware from an employee of a supplier, as documented by the researchers at InfoStealers, and a second actor leaked further data. That was a data theft rather than a production halt.

The policy response has been contested. The Cyber Security and Resilience Bill was introduced in the Commons on 12 November 2025 and received its second reading on 6 January 2026, extending incident reporting duties and minimum security standards to managed service providers, data centres and critical suppliers. Critics have noted the obvious gap: the Bill covers existing network and information systems sectors plus suppliers, not manufacturing or retail, and would not have brought Jaguar Land Rover into scope. The Bill was still before the House of Lords in July 2026.

What remains unresolved is the most important question. No arrests have been announced in connection with the August 2025 attack. Investigators have not said publicly whether the hackers acted on instructions from the Russian state, and the British government has not confirmed the attribution reported by the Times. Until it does, the country's costliest cyber incident has a suspected nationality but no official one.

Sources

Every factual claim above rests on the 11 published sources below. They are listed so you can check the reporting rather than take it on trust.

  1. TechCrunchRussian hackers were behind $2.5B hack of Jaguar Land Rover: Report
  2. Infosecurity MagazineRussian Hackers Accused of Destructive Attack on Jaguar Land Rover
  3. Cyber Monitoring CentreCyber Monitoring Centre Statement on the Jaguar Land Rover Cyber Incident
  4. Infosecurity MagazineJLR Hack UK's Costliest Ever, Hitting Economy with 1.9bn Loss
  5. LBCMPs demand transparency over reports Russians hacked Jaguar Land Rover
  6. TechCrunchUK government bails out Jaguar Land Rover with 1.5B loan after hack disrupts vehicle production for weeks
  7. Business MattersGovernment under fire as Jaguar Land Rover leaves 1.5bn state-backed loan untouched after cyber crisis
  8. just-autoJLR cyber-attack drags Tata Motors into the red
  9. UK Parliament (Hansard)Cyber Security and Resilience (Network and Information Systems) Bill, second reading
  10. InfoStealersJaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook, Then a Second Hacker Strikes
  11. WikipediaJaguar Land Rover cyberattack

The Verified Briefing

One email each morning. Every story in it carries its sources, so you can check the reporting before you repeat it.

No tracking pixels. One click to leave.