Ransomware

Jaguar Land Rover Scattered Lapsus$ Hunters Cyberattack

πŸ“… 2025-08-31
Primary Source β†—

Incident Details

Beginning August 31, 2025, the ‘Scattered Lapsus$ Hunters’ alliance β€” a cybercrime consortium of Scattered Spider (initial access/social engineering), LAPSUS$ (extortion/amplification), and ShinyHunters (data harvesting) β€” attacked Jaguar Land Rover. JLR paused production on September 1; manufacturing plants across UK, Slovakia, Brazil, and India were shut down for approximately five weeks. The group claimed responsibility via Telegram and leaked screenshots of internal systems including the jlrint.com domain. The attack is estimated to be the most costly cyberattack in British history, with estimated economic damage of Β£1.9 billion and confirmed costs of Β£196 million. The attack originated from social engineering and credential abuse rather than zero-day exploits, exploiting weak network segmentation and inadequate detection.

Technical Details

Initial Attack Vector
Vishing (voice phishing) campaign weeks before the attack tricked employees into disclosing credentials; attackers posing as internal IT staff. Subsequent credential abuse and lateral movement into production and manufacturing systems.

Timeline

  1. 2025-08-31 Breach occurred
  2. 2025-09-01 Publicly disclosed