Currently reading: Hackers who hit M&S claim responsibility for JLR cyber attack

No new Land Rover cars are able to be made or registered as manufacturer races to solve global system fault

The group that hacked Marks & Spencer earlier this year has claimed responsibility for the cyber attack on JLR that has caused production shutdowns and sales stoppages.

Scattered Spider hit the British retailer in May, causing seven weeks of disruption and costing £300 million in lost operating profit.

Along with fellow hacking group Shiny Hunters, it claims to have obtained customer data after exploiting a similar flaw in JLR’s IT system, The Telegraph reports.

The claim was made on a Telegram messenger group, where a user linked to the hackers posted a screenshot of what appeared to show JLR's internal system.

A member of the group told The Telegraph that a well known flaw in SAP Netweaver - third-party software used by JLR - was exploited to access the data.

US cyber agency CISA warned about the flaw earlier this year. An update for the software was released, but whether JLR applied it is unknown.

It's also not known what data was taken or if a ransom demand has been made. 

JLR told Autocar in a statement yesterday that “there is no evidence any customer data has been stolen”.

It refused to comment on the latest claims today (Wednesday).

The hack has caused three days of sales and production issues which have “severely disrupted” JLR's operations.

In an effort to combat the hack, JLR began “shutting down our systems” on Tuesday and is now in the process of rebuilding them.

This shutting down of systems has led to a halt of production at both Halewood and Solihull, where the Range Rover and Range Rover Sport are built. 

JLR was also unable to confirm a timescale for the fix, but it's understood that the hack could continue to cause disruption for the rest of the week.

According to The Telegraph, the hacking groups are believed to be made up of teenagers from English-speaking countries.

Autocar first reported the issues affecting JLR on Monday, when dealers couldn't register new cars on 'new plate day' (1 September), traditionally one of the year's busiest for registrations.

To combat the delays, the registering of cars is now being carried out by hand, a JLR dealer revealed to Autocar on Wednesday. 

Back to top

Autocar also understands the issues are impacting parts supplies and new car handovers, although JLR wouldn't confirm this.

JLR's public-facing website appears to be fully operational, including the car configurator.

Join our WhatsApp community and be the first to read about the latest news and reviews wowing the car world. Our community is the best, easiest and most direct place to tap into the minds of Autocar, and if you join you’ll also be treated to unique WhatsApp content. You can leave at any time after joining - check our full privacy policy here.

Will Rimell

Will Rimell Autocar
Title: News editor

Will is Autocar's news editor.​ His focus is on setting Autocar's news agenda, interviewing top executives, reporting from car launches, and unearthing exclusives.

As part of his role, he also manages Autocar Business – the brand's B2B platform – and Haymarket's aftermarket publication CAT.

Felix Page

Felix Page
Title: Deputy editor

Felix is Autocar's deputy editor, responsible for leading the brand's agenda-shaping coverage across all facets of the global automotive industry - both in print and online.

He has interviewed the most powerful and widely respected people in motoring, covered the reveals and launches of today's most important cars, and broken some of the biggest automotive stories of the last few years. 

Join the debate

Comments
4
Add a comment…
gavsmit 2 September 2025

There's so much of it going on with large companies it's a joke. Maybe senior management need to consider their outsourcing partners and how diligently they manage their staff and those they contract out to. 

I still can't believe that so much UK sensitive data and processing is performed and managed by offshore commpanies in nations that trade with countries like Russia! 

Marc 2 September 2025

Some wronguns stood outside their data centre with an aerial and some tin snips, bypassed the security system and stole all the data, broke it for parts and resold it all on eBay. Now Mardell will come out of retirement and angrily demand that the police and the taxpayer should pay to cover the additional security measures needed to stop happening again.

Thekrankis 1 September 2025
The renowned JLR ongoing unreliability in a nutshell.
autoindustryinsider 3 September 2025

The ubiquitous slagging off of JLR by a BTL commenter straight off the bat. Change the record.