Luxury automaker Jaguar Land Rover (JLR) has announced an extended production halt lasting another week as the company continues to recover from a severe cyberattack that struck in late August. The British manufacturer, owned by India’s Tata Motors since 2008, employs 39,000 people globally and produces over 400,000 vehicles annually with revenues exceeding $38 billion.
## Attack Timeline and Impact
JLR first disclosed the cyber incident on September 2, revealing that production had been significantly disrupted across its global operations. The company initially instructed staff not to report to work while security teams assessed the damage. Today, JLR confirmed that manufacturing will remain suspended until September 24, 2025, as forensic investigations continue.
“We have extended the current pause in our production as our forensic investigation of the cyber incident continues, and as we consider the different stages of the controlled restart of our global operations,” the company stated.
## Data Breach Confirmed
Beyond operational disruption, JLR has acknowledged that attackers successfully stole company data during the breach. However, the automaker has not yet disclosed the specific types of information compromised or provided details about potential customer impact.
## Cybercriminal Group Claims Responsibility
A threat actor group calling itself “Scattered Lapsus$ Hunters” has claimed responsibility for the attack. The group posted screenshots of JLR’s internal SAP systems on Telegram and stated they deployed ransomware across the company’s network.
This cybercriminal collective claims ties to several notorious hacking groups, including Scattered Spider, Lapsus$, and ShinyHunters. The same group recently targeted Salesforce customers, using social engineering tactics and compromised authentication tokens to steal data from major companies including Google, Cloudflare, and Palo Alto Networks.
## Ongoing Investigation
JLR continues its forensic investigation while planning a phased restart of global operations. The company has not responded to requests for additional details about the incident’s scope or timeline for full recovery. No established ransomware groups have publicly claimed the attack, leaving attribution questions open as the investigation proceeds.
The extended shutdown highlights the severe operational impact sophisticated cyberattacks can have on major manufacturers, particularly those with complex global supply chains and production networks.
