Site navigation

Jaguar Land Rover Cyber-attack Estimated to be the Most Costly in UK History

Graham Turner

,

JLR cyber-attack cost
Jaguar Land Rover’s £1.9 billion cyber-attack has become the most costly in UK history, disrupting production, suppliers and jobs.

The cyber-attack that brought Jaguar Land Rover’s production to its knees is expected to cost around £1.9 billion, making it the most economically damaging cyber incident in UK history, according to new analysis from the Cyber Monitoring Centre (CMC).

The CMC, an independent, non-profit organisation that tracks and categorises major cyber events, said the attack has affected more than 5,000 businesses and that a full recovery will not be reached until early 2026. The group classified the incident as a “Category 3 systemic event” on its five-point scale, where Category 5 represents the most severe level.

Production at JLR’s major UK plants in Solihull, Halewood and Wolverhampton was halted for five weeks from 1 September, following an IT shutdown triggered by a “major cyber incident” that began in late August. Dealer systems were intermittently unavailable, while suppliers faced cancelled or delayed orders and growing uncertainty about future supply.

JLR has begun a phased restart of operations but declined to comment on the CMC’s findings, saying only that it was bringing portions of manufacturing back online in a controlled manner.

Eye-watering financial implications in a year to forget for UK businesses

The CMC estimated the total economic loss at between £1.6 billion and £2.1 billion, settling on £1.9 billion as the most likely figure. More than half of that loss is expected to fall directly on JLR, including lost profit, fixed costs during the production halt, and the expense of rebuilding IT systems.

The remainder reflects the impact on suppliers, dealerships, logistics providers, and local economies around affected manufacturing hubs.

“Operational disruption has generated virtually all of the financial loss,” the CMC said in its report. “The cost dwarfs the financial losses associated with any previous known data breach incident.”

Production was suspended for roughly five weeks, resulting in an estimated loss of around 5,000 vehicles per week and weekly financial damage to JLR’s UK operations of approximately £108 million. The analysis assumes a full recovery to pre-incident production levels by early January 2026, though the CMC warned that unforeseen challenges in IT infrastructure and supply chains could delay this timeline.

While not a major factor in the overall cost, the report also modelled a short period of overproduction – up to 120% of normal capacity – in early 2026 to make up lost ground.

Ripple effects through the supply chain

JLR’s extensive network of nearly a thousand tier-one suppliers and thousands more tier-two and tier-three partners has been heavily affected. The CMC found that some suppliers faced severe cash flow problems, with at least one taking out a personally backed loan to stay afloat.

The report noted that JLR has attempted to stabilise its supply chain by clearing outstanding invoices and prepaying qualifying suppliers, but warned that “if any key supplier fails, it will be challenging for JLR to replace them, and this could cause longer delays.”

Downstream effects were also felt by dealerships, service centres, and logistics providers, where reduced vehicle supply led to lower sales and postponed shipments. Local economies dependent on JLR plants saw further knock-on impacts, with reductions in income among workers and contractors.

Although the hack included an apparent data breach, the CMC said it does not expect data losses to be a material part of the total cost. It has also not factored in any ransom payments, noting that “nothing has emerged in the public domain about ransoms being either demanded or paid.”

Nature of the attack remains unclear

Few technical details have been disclosed publicly about the nature of the cyber-attack.

Analysts at the CMC suggested that JLR’s decision to shut down its systems implied a “significant risk that attackers had reached, or would reach, sensitive operational infrastructure”, raising the possibility of crossover between IT and operational technology systems.

However, the company’s ability to resume limited production in October suggests this crossover may not have been extensive.

A group of hackers, believed to be young, English-speaking, and linked to previous high-profile incidents, reportedly claimed responsibility for the breach, but this has not been confirmed.

The human cost of the attack

Beyond the financial damage, the CMC report described “a significant human impact”, with some suppliers reducing pay, banking hours, or laying off staff to survive the disruption.

A much underreported factor (ourselves included), the CMC warned that such instability can erode household resilience and exacerbate existing regional inequalities.


Recommended reading


The UK government has reportedly underwritten a £1.5 billion loan guarantee to provide liquidity to JLR if needed. Although the CMC’s analysis assumes this support will not be used, it cautioned that “the government’s intervention in this incident could create expectations for future events” and called for a clearer framework to define thresholds for state support following major cyber incidents.

Lessons and recommendations

The CMC urged boards and policymakers to recognise that operational disruption — not data theft — now represents the biggest cyber risk to most businesses. It recommended that organisations:

  • Strengthen the resilience of both IT and operational technology systems.

  • Map supply chain dependencies and plan for liquidity during shutdowns.

  • Evaluate cyber insurance coverage to ensure protection against supply chain disruptions.

“Future high-impact events are likely to be caused by disruptive attacks rather than by data exfiltration,” the report said.

JLR cyber-attack the largest recorded cyber loss in UK history

At an estimated £1.9 billion, the JLR incident far exceeds the scale of the CMC’s previous assessment of cyber-attacks on M&S, the Co-op and Harrods earlier this year, which were classified as Category 2 and valued between £270 million and £440 million.

“This event demonstrates how a cyber-attack on a single manufacturer can reverberate across regions and industries,” the CMC concluded, “and underscores the strategic importance of cyber resilience in the UK’s industrial base.”

The organisation said it would continue to work with affected companies, insurers and government agencies to deepen understanding of the attack’s full impact and strengthen national preparedness for future cyber threats.

Graham Turner

Sub Editor

Latest News

AI Infrastructure

Scottish Parliament Votes to Pause All AI Data Centre Applications

Cybersecurity Editor's Picks Security

Cyber Essentials Certifications Rise as SME Uptake Remains Limited

AI Editor's Picks Funding

Edinburgh Graduates’ AI Infrastructure Firm Expanse Raises $5.3m

Featured Finance

Fintech Summit 2026 Countdown Enters Final Three Weeks