Jaguar Land Rover Halted Production and Retail Operations Following Cyber Attack
Jaguar Land Rover, the UK's biggest carmaker, has been forced to shut down its global IT systems and halt production after a cyber attack compromised its operations. The incident, which has disrupted its plant on Merseyside, has prompted the company to take its systems offline as a precaution. In a statement, JLR assured customers that there was "no evidence" that customer data had been stolen, but an IT blackout has left dealers unable to register new vehicles and the company's parent company, Tata, has confirmed the incident as an "IT security incidence".
Key Takeaways:
- Jaguar Land Rover has halted production and retail operations worldwide due to a cyber attack on its global IT systems.
- The company has kept specialist staff on site, but production associates have been told to remain at home, with shifts cancelled and hours banked under the site's corridor agreement.
- Oakley Cox, director of product at Darktrace, believes the attack may have targeted JLR's operational systems, not just customer data, citing the company's rapid response as evidence of a genuine concern about operational impact.
- The disruption comes at a sensitive moment for JLR, as dealers were unable to register new vehicles on 1 September, the day new 75 registration plates were launched.
- The attack follows a string of high-profile cyber incidents across the UK retail sector, including breaches at Co-op and Marks & Spencer, which has reported losses of £300m.
- The National Crime Agency has recently stepped up investigations into ransomware groups targeting UK companies, with four individuals accused of attacks on major retailers including Harrods and M&S arrested in June.
- JLR's parent company, Tata, has confirmed the incident as an "IT security incidence" but has not provided further details on the nature of the attack or how long systems may remain offline.
- Data from Abnormal AI suggests a clear seasonal pattern in retail-focused cyberattacks, with the second quarter consistently seeing a spike as criminals exploit busy trading periods.
Statistics:
- Up to 6.5m customers may have been affected by the Co-op's breach in May.
- The losses suffered by Marks & Spencer due to the attack in April amount to £300m.
- Four individuals have been arrested in connection with cyber attacks on major retailers, including Harrods and M&S.
- 6.5m customers, Abnormal AI's data suggests, is a typical number of customers affected by a seasonal retail-focused cyberattack in the second quarter.
- The National Crime Agency has been investigating ransomware groups targeting UK companies since June, making a positive impact on reducing these cyber threats.
Sources:
- (https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-staff-told-32396209)
- (https://www.cityam.com/retail-data-threats-peak-in-q2-as-uk-sector-grapples-with-cyber-spree/)
- Tata's filing to the Indian stock exchange, confirming the incident as an "IT security incidence"
- Abnormal AI's data on seasonal patterns in retail-focused cyberattacks