Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks

June 30, 2026

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

June 30, 2026

FBI Sounds Alarm Over Russian Intelligence Signal Phishing

June 30, 2026
Facebook X (Twitter) Instagram
Tuesday, June 30
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Russian Hackers Accused of Destructive Attack on Jaguar Land Rover
News

Russian Hackers Accused of Destructive Attack on Jaguar Land Rover

Team-CWDBy Team-CWDJune 29, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security experts and practitioners have weighed in on a new report claiming that Russia was behind the Jaguar Land Rover (JLR) breach last year.

The New York Times report cited people close to the investigation in its story on June 26 linking Russian hackers to the incident, which is estimated to have cost the British economy £1.9bn ($2.5bn).

Microsoft, which was tracking the Russians, reportedly raised the alarm with JLR. However, while the report didn’t explicitly link the Putin regime with the attack, experts have been more forthright.

Halcyon Ransomware Research Center SVP and former FBI cyber deputy director, Cynthia Kaiser, said there are several reasons to believe Kremlin involvement.

There was seemingly no ransom demand and the attack landed just before a new vehicle rollout, she said. The hackers also used novel ransomware with a “mind-blowing” algorithm, and JLR’s Land Rover fleet have strong links to the British royals and military, Kaiser argued.

“There are a lot of good reasons why nation states use criminal tactics when conducting destructive attacks. They are fast, scalable, and highly repeatable. They exploit common weaknesses that exist across nearly every critical infrastructure environment. And critically, they complicate attribution, allowing attackers to operate below traditional response thresholds,” she continued.

“But this is the first time I can remember where it is now highly suspected that Russia at least tacitly approved an economically destructive attack, delivering an estimated $2.5bn hit to the British economy and costing the company about $350m in the 2026 fiscal year.”

Read more on JLR attack: Jaguar Land Rover’s Q3 Sales Crash Amid Cyber-Attack Fallout

By disguising the attack as a cybercrime effort, the threat actors helped create enough doubt to limit a geopolitical response, Kasier claimed.

“Adversaries believe they can stop appropriate reactions from democratic nations by planting seeds of doubt,” she said. “We all need to be more forward leaning in expecting and responding to nation states who will almost certainly increase their use of criminal tactics in the future.”

The Scattered Lapsus$ Hunters Distraction

Initially, attribution efforts were complicated by claims by Scattered Lapsus$ Hunters that it was responsible for the attack, which closely followed extortion attacks on M&S and Co-op Group by Scattered Spider.

However, former Paramount CISO and now VC partner, Pete Chronis, has also backed the Russia theory.

“When JLR got hacked, nobody asked for money,” he said in a LinkedIn post. “Sit with that. Ransomware gangs lock you up because they want a payout. Whoever hit JLR didn’t want one. No demand, no negotiation. They just wanted the company on the floor. That’s why Russia is in the frame, and why this reads less like crime and more like sabotage.”

Ashish Shrestha – CEO of Zyn Global and group CISO of JLR at the time of the cyber incident – told Infosecurity  in a conversation on June 18 that at the time of the cyber-attack they knew the attacker was “quite sophisticated.”

However, he did not confirm attribution of the incident.

Shrestha said that within the first 24 hours of the incident the threat actors asked him not to involved law enforcement.

“I had law enforcement physically in my world,” he said, and at no time did Shrestha or his team reach out to their attackers.

On recovery, he noted that his team was taking its time to ensure the adversaries would not be able to conduct a follow-on attack. “Business continuity is not just about coming back, but coming back stronger,” he noted.

Interestingly, he said that no social engineering was involved in the attack. At the time of the 2025 incident, it has been widely reported that the hackers impersonated staff in vishing attacks to get hold of corporate credentials.  

The NYT report claimed that a Jordanian hacker known as “Rey” also breached part of the JLR network, independently of the Russians.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleResearchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
Next Article Ethical AI Is an Operational Discipline, not a Philosophy
Team-CWD
  • Website

Related Posts

News

UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks

June 30, 2026
News

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

June 30, 2026
News

FBI Sounds Alarm Over Russian Intelligence Signal Phishing

June 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What is it, and how do I get it off my device?

September 11, 2025

Your information is on the dark web. What happens next?

January 13, 2026

Managing risks to your loved one’s digital estate

April 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.