Skip to content
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Caint logo. It's just text.
  1. Home
  2. Uncategorized
  3. Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.

Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.

Scheduled Pinned Locked Moved Uncategorized
34 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Kevin BeaumontG Kevin Beaumont

    Meanwhile the LAPSUS guys were busy posting large numbers of US defense Top Secret marked documents last night. They've since been deleted from Telegram.

    Kevin BeaumontG This user is from outside of this forum
    Kevin BeaumontG This user is from outside of this forum
    Kevin Beaumont
    wrote last edited by
    #20

    One surprising thing with the Jaguar Land Rover incident - they've only isolated JAGUAR LAND ROVER AUTOMOTIVE PLC (AS205756), the UK network. The India, China etc networks are still online.

    When I dealt with LAPSUS elsewhere they entered via a different country network/biz unit and then pivoted to target country/biz unit.

    Kevin BeaumontG 1 Reply Last reply
    0
    • Kevin BeaumontG Kevin Beaumont

      One surprising thing with the Jaguar Land Rover incident - they've only isolated JAGUAR LAND ROVER AUTOMOTIVE PLC (AS205756), the UK network. The India, China etc networks are still online.

      When I dealt with LAPSUS elsewhere they entered via a different country network/biz unit and then pivoted to target country/biz unit.

      Kevin BeaumontG This user is from outside of this forum
      Kevin BeaumontG This user is from outside of this forum
      Kevin Beaumont
      wrote last edited by
      #21

      JLR UK have got one internet facing system back online - wslx.jlrext.com

      Single factor auth only because that's how automotives roll. If you visit direct IP, it's still branded Ford - Ford sold the business in 2008.

      Kevin BeaumontG 1 Reply Last reply
      0
      • Kevin BeaumontG Kevin Beaumont

        JLR UK have got one internet facing system back online - wslx.jlrext.com

        Single factor auth only because that's how automotives roll. If you visit direct IP, it's still branded Ford - Ford sold the business in 2008.

        Kevin BeaumontG This user is from outside of this forum
        Kevin BeaumontG This user is from outside of this forum
        Kevin Beaumont
        wrote last edited by
        #22

        Just checked in on JLR - factory production won't be resuming tomorrow (day 7).

        Kevin BeaumontG 1 Reply Last reply
        0
        • Kevin BeaumontG Kevin Beaumont

          Just checked in on JLR - factory production won't be resuming tomorrow (day 7).

          Kevin BeaumontG This user is from outside of this forum
          Kevin BeaumontG This user is from outside of this forum
          Kevin Beaumont
          wrote last edited by
          #23

          Jaguar Land Rover car production is still shut down tomorrow, day 8. I’ve checked the network border, everything except one system in UK is also still offline.

          Kevin BeaumontG 1 Reply Last reply
          0
          • Kevin BeaumontG Kevin Beaumont

            Jaguar Land Rover car production is still shut down tomorrow, day 8. I’ve checked the network border, everything except one system in UK is also still offline.

            Kevin BeaumontG This user is from outside of this forum
            Kevin BeaumontG This user is from outside of this forum
            Kevin Beaumont
            wrote last edited by
            #24

            JLR are keeping car production closed until least Monday. They also say “some data was impacted”, whatever that means.

            https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-issues-crisis-32447659

            Kevin BeaumontG 1 Reply Last reply
            0
            • Kevin BeaumontG Kevin Beaumont

              JLR are keeping car production closed until least Monday. They also say “some data was impacted”, whatever that means.

              https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-issues-crisis-32447659

              Kevin BeaumontG This user is from outside of this forum
              Kevin BeaumontG This user is from outside of this forum
              Kevin Beaumont
              wrote last edited by
              #25

              JLR have started switching border routers back on (don't ask me why SNMP, NTP and SSH are internet facing).

              Kevin BeaumontG H 2 Replies Last reply
              0
              • Kevin BeaumontG Kevin Beaumont

                JLR have started switching border routers back on (don't ask me why SNMP, NTP and SSH are internet facing).

                Kevin BeaumontG This user is from outside of this forum
                Kevin BeaumontG This user is from outside of this forum
                Kevin Beaumont
                wrote last edited by
                #26

                JLR shouldn't feel bad, Tata Motors (their parent) is way worse shape. They've even got Exchange Server with OWA internet facing without MFA.

                Kevin BeaumontG 1 Reply Last reply
                0
                • Kevin BeaumontG Kevin Beaumont

                  JLR have started switching border routers back on (don't ask me why SNMP, NTP and SSH are internet facing).

                  H This user is from outside of this forum
                  H This user is from outside of this forum
                  MrHumlekotten
                  wrote last edited by
                  #27

                  @GossiTheDog
                  Wouldn’t the uptime rather suggest that they just plugged the cable back in?
                  Doesn’t seem to even had bothered patching the routers beforehand.

                  The routers could potentially be CEs and thus the responsibility of the service provider.

                  1 Reply Last reply
                  1
                  0
                  • Kevin BeaumontG Kevin Beaumont

                    JLR shouldn't feel bad, Tata Motors (their parent) is way worse shape. They've even got Exchange Server with OWA internet facing without MFA.

                    Kevin BeaumontG This user is from outside of this forum
                    Kevin BeaumontG This user is from outside of this forum
                    Kevin Beaumont
                    wrote last edited by
                    #28

                    Jaguar Land Rover have told factory workers worldwide to stay home until at least next Wednesday, which will be 17 days since the cyber incident began. https://www.bbc.co.uk/news/articles/c3e712nvyz9o.amp

                    Kevin BeaumontG 1 Reply Last reply
                    0
                    • Kevin BeaumontG Kevin Beaumont

                      Jaguar Land Rover have told factory workers worldwide to stay home until at least next Wednesday, which will be 17 days since the cyber incident began. https://www.bbc.co.uk/news/articles/c3e712nvyz9o.amp

                      Kevin BeaumontG This user is from outside of this forum
                      Kevin BeaumontG This user is from outside of this forum
                      Kevin Beaumont
                      wrote last edited by
                      #29

                      Unite are calling on the government to urgently intervene over the Jaguar Land Rover cyber incident, to introduce a furlough scheme for JLRs suppliers.

                      https://www.unitetheunion.org/news-events/news/2025/september/jlr-supply-chain-workers-impacted-by-cyberattack-must-receive-government-support-says-unite

                      Kevin BeaumontG 1 Reply Last reply
                      0
                      • Kevin BeaumontG Kevin Beaumont

                        Unite are calling on the government to urgently intervene over the Jaguar Land Rover cyber incident, to introduce a furlough scheme for JLRs suppliers.

                        https://www.unitetheunion.org/news-events/news/2025/september/jlr-supply-chain-workers-impacted-by-cyberattack-must-receive-government-support-says-unite

                        Kevin BeaumontG This user is from outside of this forum
                        Kevin BeaumontG This user is from outside of this forum
                        Kevin Beaumont
                        wrote last edited by
                        #30

                        JLR have lost between £50m-£100m so far according to BBC estimates https://www.bbc.co.uk/news/articles/czdjn0lv64ro

                        Kevin BeaumontG 1 Reply Last reply
                        0
                        • Kevin BeaumontG Kevin Beaumont

                          JLR have lost between £50m-£100m so far according to BBC estimates https://www.bbc.co.uk/news/articles/czdjn0lv64ro

                          Kevin BeaumontG This user is from outside of this forum
                          Kevin BeaumontG This user is from outside of this forum
                          Kevin Beaumont
                          wrote last edited by
                          #31

                          If anybody is interested, TCS’ website says JLR outsourced cybersecurity (not sure which bits) to it a few years ago.

                          TCS also run security operations and monitoring for Co-op (my old team) along with their IT and IT helpdesk, and M&S secops monitoring, IT and IT helpdesk.

                          Kevin BeaumontG 1 Reply Last reply
                          0
                          • Kevin BeaumontG Kevin Beaumont

                            If anybody is interested, TCS’ website says JLR outsourced cybersecurity (not sure which bits) to it a few years ago.

                            TCS also run security operations and monitoring for Co-op (my old team) along with their IT and IT helpdesk, and M&S secops monitoring, IT and IT helpdesk.

                            Kevin BeaumontG This user is from outside of this forum
                            Kevin BeaumontG This user is from outside of this forum
                            Kevin Beaumont
                            wrote last edited by
                            #32

                            Jaguar Land Rover have extended their manufacturing shutdown until at least next Wednesday, the 24th of September. https://www.theguardian.com/business/2025/sep/16/jaguar-land-rover-production-shutdown-cyber-attack

                            Kevin BeaumontG Ed WiebeE 2 Replies Last reply
                            0
                            • Kevin BeaumontG Kevin Beaumont

                              Jaguar Land Rover have extended their manufacturing shutdown until at least next Wednesday, the 24th of September. https://www.theguardian.com/business/2025/sep/16/jaguar-land-rover-production-shutdown-cyber-attack

                              Kevin BeaumontG This user is from outside of this forum
                              Kevin BeaumontG This user is from outside of this forum
                              Kevin Beaumont
                              wrote last edited by
                              #33

                              In my own story, I discovered JLR outsourced different cybersecurity areas to TCS and then made many of the UK team redundant 6 months ago.

                              https://doublepulsar.com/the-elephant-in-the-biz-outsourcing-of-critical-it-and-cybersecurity-functions-risks-uk-economic-96205e0585bf

                              1 Reply Last reply
                              2
                              0
                              • R AodeRelay shared this topic
                              • Kevin BeaumontG Kevin Beaumont

                                Jaguar Land Rover have extended their manufacturing shutdown until at least next Wednesday, the 24th of September. https://www.theguardian.com/business/2025/sep/16/jaguar-land-rover-production-shutdown-cyber-attack

                                Ed WiebeE This user is from outside of this forum
                                Ed WiebeE This user is from outside of this forum
                                Ed Wiebe
                                wrote last edited by
                                #34

                                @GossiTheDog When I see a Jaguar or Land Rover going past I see a bad person who doesn’t care about anything but themselves.

                                1 Reply Last reply
                                1
                                0
                                • R AodeRelay shared this topic

                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Don't have an account? Register

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • All Topics
                                • Popular
                                • World
                                • Users
                                • Groups