What Companies Can Learn from the Jaguar Cyberattack

Posted

A version of this article originally appeared on the Corsica Technologies blog.

The recent cyberattack on Jaguar Land Rover (JLR) is a sobering reminder that today’s cyberthreat environment is constantly evolving. Even Greenville companies can fall prey to devastating attacks once criminals gain access to their systems.

So what happened here? How can manufacturers prevent similar cyberattacks?

We’ll cover all that and more.

Key takeaways:

· Jaguar Land Rover experienced a devastating cyberattack in August 2025 that forced the company to shut down operations.

· Cyber criminals most likely used social engineering and vishing to execute the initial breach of systems.

· Greenville companies in all verticals should establish layered cybersecurity defenses to prevent this type of attack.

What happened in the Jaguar cyberattack?

Inbrlate August 2025, a cyberattack on Jaguar Land Rover (JLR) severely disrupted the company's manufacturing and retail operations, leading to a global production shutdown. The attack was claimed by a hacker group known as Scattered Lapsus$ Hunters, a collective linked to previous breaches at other companies. The incident forced JLR to proactively shut down its systems to contain the damage.

How did the criminals launch the attack?

The hackers gained access to JLR's manufacturing IT systems, most likely through a sophisticated vishing campaign. The criminal group, which includes elements of the Scattered Spider, Lapsus$, and ShinyHunters collectives, is known for using social engineering tactics to breach systems and obtain access.

Unfortunately, this attack vector is often effective in manufacturing, where operational technology (OT) often integrates with traditional IT systems. This creates a complex environment with many potential vulnerabilities requiring constant monitoring and management.

How did the attack affect Jaguar’s operations?

This was a devastating cyberattack that forced Jaguar to shut down production and sales activities. The effects of the attack also rippled out into the broader supply chain in the auto industry.

Here are the detailed repercussions of the breach.

  • Production halt: JLR was forced to stop manufacturing at its global manufacturing sites, including its main UK factories. JLR announced the initial shutdown on September 1, then extended the pause until at least September 24 as a forensic investigation and system rebuild continued.
  • Financial losses: The production halt is estimated to have cost JLR millions of pounds per week, with some sources reporting losses of up to £50 million weekly.
  • Supply chain fallout: The disruption had abr ripple effect across the automotive supply chain, with thousands of workers at suppliers affected and some smaller companies facing bankruptcy.
  • Data each: While JLR initially stated there was no evidence of customer data theft, they later confirmed that some company data had been affected. This included the potential compromise of internal systems, though the full scope was still under investigation.
  • Hacker activity: Scattered Lapsus$ Hunters reportedly targeted JLR during a key sales period, possibly leveraging a known vulnerability through social engineering. The group also used a public Telegram channel to boast about the attack and issue threats against other companies.

How can Greenville companies prevent similar attacks?

Unfortunately, JLR isn’t the only organization that’s vulnerable to cyberattacks. This incident highlights the need for a multi-layered, proactive cybersecurity strategy with robust toolsets and continuous monitoring by human experts.

While that might sound intimidating, this level of security is actually quite attainable. Greenville companies in all verticals can take seven steps to prevent similar attacks.

1. Strengthen access controls and authentication

  • Adopt strong passwords and MFA. Enforce strict password policies and require multi-factor authentication (MFA) for all users, particularly for accounts with privileged access.
  • Implement least privilege. Restrict user access to only the data and systems necessary for their job functions. This limits a hacker's ability to move laterally across the network after an initial each.

2. Prioritize employee training and awareness

  • Conduct regular training. Educate employees on how to recognize and report common cyber threats like phishing, which is a major entry point for attackers.
  • Run phishing simulations. Test and reinforce employee vigilance with simulated phishing exercises.

3. Maintain updated systems and software

  • Patch vulnerabilities promptly. Keep all operating systems and software updated with the latest security patches. This fixes known vulnerabilities before attackers can exploit them.
  • Automate patch management. Use a patch management system to ensure updates are deployed consistently and in a timely manner.

4. Secure networks and endpoints

  • Use firewalls. Deploy firewalls to control network traffic and block unauthorized access.
  • Encrypt data. Encrypt all sensitive data, both in transit and at rest, to make it unreadable to unauthorized parties.
  • Implement endpoint protection. Install and maintain antivirus and anti-malware software on all devices.

5. Manage third-party vendor risk

Assess the cybersecurity posture of all third-party vendors and ensure they meet your security standards. Attackers can exploit vulnerabilities in a supplier's network to access your own systems.

6. Prepare a comprehensive incident response plan

  • Create a detailed plan. Establish a clear, documented plan outlining the steps to be taken in case of a each. This ensures a coordinated and rapid response.
  • Conduct data backups. Regularly back up all critical data and store it securely, preferably following the 3-2-1 rule (three copies, two different media, one off-site).
  • Implement a “killswitch.” Have a plan to quickly shut down affected systems to contain the spread of an attack.

7. Continuously monitor and audit

  • Employ network monitoring. Use tools to continuously monitor your network for suspicious activity.
  • Perform regular audits. Conduct security audits and vulnerability assessments to proactively identify weaknesses in your security defenses.

The takeaway: Get the layered protection you need

The world of cyberattacks is constantly evolving, but Greenville companies don’t have to fall prey to devastation. The key is layered defenses and access to cybersecurity experts. That can get expensive, and for companies that are hesitant to invest in cybersecurity staff, an MSSP (managed security service provider) offers the same value at a lower price point. Whichever path your organization chooses, the key is to use the right people, processes, and technology to maintain vigilance.

About the author

Ross Filipek is Corsica Technologies’ CISO. He has more than 20 years’ experience in the managed cyber security services industry as both an engineer and a consultant. In addition to leading Corsica’s efforts to manage cyber risk, he provides vCISO consulting services for many of Corsica’s clients. Ross has achieved recognition as a Cisco Certified Internetwork Expert (CCIE #18994; Security track) and an ISC2 Certified Information Systems Security Professional (CISSP). He has also earned an MBA degree from the University of Notre Dame.

Comments

No comments on this item Please log in to comment by clicking here