A cyber attack on **Jaguar Land Rover (JLR)** forced the shutdown of its **Halewood production plant** in Merseyside, halting all manufacturing operations since **31 August 2024**. The attack disrupted the supply chain, leaving **small and medium-sized suppliers**—some of whom rely solely on JLR—under severe financial strain. With production not expected to resume until **1 October at the earliest**, workers face potential job losses, unpaid bills, and economic instability. Local leaders, including **Knowsley Council**, have urged the UK government to introduce a **furlough scheme** to support affected employees and suppliers. The incident has also raised concerns about broader economic impacts in the **Liverpool City Region and West Midlands**, where JLR operates additional plants. While investigations continue with **cybersecurity specialists, the National Cyber Security Centre, and law enforcement**, the attack has already caused **significant operational and financial damage**, threatening livelihoods and regional manufacturing stability.
Source: https://www.bbc.com/news/articles/cwywvpxrx0ro
TPRM report: https://www.rankiteo.com/company/jaguar-land-rover_1
"id": "jag5002050092525",
"linkid": "jaguar-land-rover_1",
"type": "Cyber Attack",
"date": "8/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'Automotive',
'location': 'Halewood, Merseyside, UK (primary '
'affected site); additional plants in '
'Solihull and Wolverhampton, West Midlands',
'name': 'Jaguar Land Rover (JLR)',
'size': 'Large enterprise',
'type': 'Automotive Manufacturer'},
{'industry': 'Automotive Manufacturing',
'location': 'Primarily Merseyside and West Midlands, '
'UK',
'name': 'JLR Supply Chain Partners (SMEs)',
'size': ['Small', 'Medium'],
'type': ['Suppliers', 'Service Providers']}],
'customer_advisories': ['JLR retailers remain open; customer support '
'prioritized'],
'date_detected': '2024-08-31',
'date_publicly_disclosed': '2024-09-XX',
'description': 'A cyber attack on Jaguar Land Rover (JLR) in late August 2024 '
'forced the shutdown of its Halewood production plant in '
'Merseyside, UK, with operations not expected to resume until '
"at least 1 October. The incident has severely disrupted JLR's "
'supply chain, particularly impacting small and medium-sized '
'suppliers dependent on the automaker. Local leaders, '
'including Knowsley Council leader Graham Morgan, have called '
'for government intervention, such as a furlough scheme, to '
'support affected workers and businesses during the prolonged '
'downtime. The attack is under investigation by JLR, '
'cybersecurity specialists, the National Cyber Security Centre '
'(NCSC), and law enforcement. The financial and operational '
'strain on suppliers has raised concerns about potential '
"closures, which could further delay JLR's recovery even after "
'production resumes.',
'impact': {'brand_reputation_impact': ['Negative publicity due to prolonged '
'shutdown',
'Local political and public concern '
'over livelihoods'],
'downtime': {'duration': 'At least 1 month (ongoing as of report)',
'end': '2024-10-01 (estimated)',
'start': '2024-08-31'},
'operational_impact': ['Complete halt of production at Halewood '
'plant',
'Disruption to supply chain (SMEs at risk '
'of closure)',
'Cashflow crises for suppliers',
'Potential long-term delays even after '
'restart due to supplier failures'],
'systems_affected': ['Production systems at Halewood plant (Range '
'Rover Evoque and Discovery Sport lines)',
'Supply chain operations']},
'initial_access_broker': {'high_value_targets': ['Production systems',
'Supply chain data '
'(speculative)']},
'investigation_status': 'Ongoing (as of 2024-09-XX)',
'recommendations': ['Government support (e.g., furlough scheme) for affected '
'supply chain workers',
'Financial aid packages for SME suppliers facing cashflow '
'crises',
'Enhanced cybersecurity measures for critical '
'manufacturing infrastructure',
'Supply chain resilience planning to mitigate '
'single-point dependencies'],
'references': [{'date_accessed': '2024-09-XX',
'source': 'BBC News',
'url': 'https://www.bbc.com/news/uk-england-merseyside-6695XXXX'}],
'regulatory_compliance': {'regulatory_notifications': ['Likely notifications '
'to UK regulatory '
'bodies (e.g., ICO if '
'data breach '
'confirmed)']},
'response': {'communication_strategy': ['Public statements by JLR and local '
'officials',
'Engagement with suppliers, unions, '
'and MPs',
'Media updates on investigation '
'progress'],
'containment_measures': ['Extended production pause to prevent '
'further damage',
'Isolation of affected systems '
'(assumed)'],
'incident_response_plan_activated': True,
'law_enforcement_notified': True,
'recovery_measures': ['Collaboration with NCSC and law '
'enforcement',
'Planned restart on 2024-10-01 '
'(conditional on security clearance)'],
'third_party_assistance': ['Cybersecurity specialists',
'National Cyber Security Centre '
'(NCSC)']},
'stakeholder_advisories': ['Knowsley Council (Graham Morgan) advocating for '
'furlough scheme',
'Liverpool City Region Metro Mayor Steve Rotheram '
'condemning attackers',
'Business Secretary Peter Kyle visiting JLR to '
'assess impact',
'Unions and MPs engaged in discussions on '
'compensation'],
'title': 'Cyber Attack on Jaguar Land Rover (JLR) Halts Production at '
'Halewood Plant',
'type': ['Cyber Attack', 'Operational Disruption']}