Skip to content
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.
Welcome to Caint!

Issues? Post in Comments & Feedback
You can now view, reply, and favourite posts from the Fediverse. You can click here or click on the on the navigation bar on the left.

Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident.

Scheduled Pinned Locked Moved Uncategorized
19 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Kevin BeaumontG This user is from outside of this forum
    Kevin BeaumontG This user is from outside of this forum
    Kevin Beaumont
    wrote last edited by
    #1

    Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident. VPNs and network border in UK all down.

    Kevin BeaumontG 1 Reply Last reply
    0
    • Kevin BeaumontG Kevin Beaumont

      Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident. VPNs and network border in UK all down.

      Kevin BeaumontG This user is from outside of this forum
      Kevin BeaumontG This user is from outside of this forum
      Kevin Beaumont
      wrote last edited by
      #2

      Jaguar Land Rover moved their cybersecurity and IT functions to TCS two years ago 🫡

      Kevin BeaumontG 1 Reply Last reply
      0
      • Kevin BeaumontG Kevin Beaumont

        Jaguar Land Rover moved their cybersecurity and IT functions to TCS two years ago 🫡

        Kevin BeaumontG This user is from outside of this forum
        Kevin BeaumontG This user is from outside of this forum
        Kevin Beaumont
        wrote last edited by
        #3

        Jaguar Land Rover is ransomware, I can see network traffic from infrastructure used by multiple e-crime groups over the past week. I've asked one I think likely responsible if they did it.

        They (JLR) appear to be doing contain to eradicate, i.e. all UK border services shut, Windows infrastructure offline etc.

        Kevin BeaumontG 1 Reply Last reply
        0
        • Kevin BeaumontG Kevin Beaumont

          Jaguar Land Rover is ransomware, I can see network traffic from infrastructure used by multiple e-crime groups over the past week. I've asked one I think likely responsible if they did it.

          They (JLR) appear to be doing contain to eradicate, i.e. all UK border services shut, Windows infrastructure offline etc.

          Kevin BeaumontG This user is from outside of this forum
          Kevin BeaumontG This user is from outside of this forum
          Kevin Beaumont
          wrote last edited by
          #4

          Jaguar Land Rover latest from the outside looking in.

          AS205756 aka JAGUAR LAND ROVER AUTOMOTIVE PLC is shut down - UK network only (however it hosts their most important infrastructure).

          Staff have been told not to turn up to manufacturing facilities.

          Tata Motors (parent company) appears to be online still but looks like a mess on Shodan, e.g. lots of SAP Netweaver boxes dangling directly off the internet.

          Kevin BeaumontG 1 Reply Last reply
          0
          • Kevin BeaumontG Kevin Beaumont

            Jaguar Land Rover latest from the outside looking in.

            AS205756 aka JAGUAR LAND ROVER AUTOMOTIVE PLC is shut down - UK network only (however it hosts their most important infrastructure).

            Staff have been told not to turn up to manufacturing facilities.

            Tata Motors (parent company) appears to be online still but looks like a mess on Shodan, e.g. lots of SAP Netweaver boxes dangling directly off the internet.

            Kevin BeaumontG This user is from outside of this forum
            Kevin BeaumontG This user is from outside of this forum
            Kevin Beaumont
            wrote last edited by
            #5

            JLR - network border all still offline. Liverpool Echo reports factory production still at all stop.

            Kevin BeaumontG 1 Reply Last reply
            0
            • Kevin BeaumontG Kevin Beaumont

              JLR - network border all still offline. Liverpool Echo reports factory production still at all stop.

              Kevin BeaumontG This user is from outside of this forum
              Kevin BeaumontG This user is from outside of this forum
              Kevin Beaumont
              wrote last edited by
              #6

              The lapsus$ guys are taking credit for the Jaguar Land Rover thing, speed run to see how many times they can get v&'d in 5 years.

              Kevin BeaumontG 1 Reply Last reply
              0
              • Kevin BeaumontG Kevin Beaumont

                The lapsus$ guys are taking credit for the Jaguar Land Rover thing, speed run to see how many times they can get v&'d in 5 years.

                Kevin BeaumontG This user is from outside of this forum
                Kevin BeaumontG This user is from outside of this forum
                Kevin Beaumont
                wrote last edited by
                #7

                I can see ecrime infrastructure was talking to this at JLR https://beta.shodan.io/host/185.193.35.39

                It's a SAP Netweaver box. The Lapsus$ kids have been running around with a SAP exploit for a while, prior thread reference: https://cyberplace.social/@GossiTheDog/115005311849134541

                Kevin BeaumontG 1 Reply Last reply
                0
                • Kevin BeaumontG Kevin Beaumont

                  I can see ecrime infrastructure was talking to this at JLR https://beta.shodan.io/host/185.193.35.39

                  It's a SAP Netweaver box. The Lapsus$ kids have been running around with a SAP exploit for a while, prior thread reference: https://cyberplace.social/@GossiTheDog/115005311849134541

                  Kevin BeaumontG This user is from outside of this forum
                  Kevin BeaumontG This user is from outside of this forum
                  Kevin Beaumont
                  wrote last edited by
                  #8

                  The lapsus$ guys also posted this screenshot, on an internal Jaguar Land Rover SAP box last night:

                  Kevin BeaumontG 1 Reply Last reply
                  0
                  • Kevin BeaumontG Kevin Beaumont

                    The lapsus$ guys also posted this screenshot, on an internal Jaguar Land Rover SAP box last night:

                    Kevin BeaumontG This user is from outside of this forum
                    Kevin BeaumontG This user is from outside of this forum
                    Kevin Beaumont
                    wrote last edited by
                    #9

                    The Lapsus$ screenshot of Jaguar is legit, jlrint.com is their internal AD name, also solihull is a sub AD well documented online etc. https://www.scribd.com/document/317755552/Networker-Errors-and-Resolutions

                    Kevin BeaumontG 1 Reply Last reply
                    0
                    • Kevin BeaumontG Kevin Beaumont

                      The Lapsus$ screenshot of Jaguar is legit, jlrint.com is their internal AD name, also solihull is a sub AD well documented online etc. https://www.scribd.com/document/317755552/Networker-Errors-and-Resolutions

                      Kevin BeaumontG This user is from outside of this forum
                      Kevin BeaumontG This user is from outside of this forum
                      Kevin Beaumont
                      wrote last edited by
                      #10

                      The lapsus guys continue to go nuts on IRC^H^H^HTelegram https://www.bbc.co.uk/news/articles/c4gqepe5355o

                      Kevin BeaumontG 1 Reply Last reply
                      0
                      • Kevin BeaumontG Kevin Beaumont

                        The lapsus guys continue to go nuts on IRC^H^H^HTelegram https://www.bbc.co.uk/news/articles/c4gqepe5355o

                        Kevin BeaumontG This user is from outside of this forum
                        Kevin BeaumontG This user is from outside of this forum
                        Kevin Beaumont
                        wrote last edited by
                        #11

                        To back up ReliaQuest - this is the exploit LAPSUS guys have running around with on SAP Netweaver, just had a look this evening after acquiring the exploit. https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/

                        There’s a metric ton - over 5 figures - of these boxes directly internet facing. Worse; from version printing, less than 5% are patched for the two CVEs being exploited.

                        Kevin BeaumontG 1 Reply Last reply
                        0
                        • Kevin BeaumontG Kevin Beaumont

                          To back up ReliaQuest - this is the exploit LAPSUS guys have running around with on SAP Netweaver, just had a look this evening after acquiring the exploit. https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/

                          There’s a metric ton - over 5 figures - of these boxes directly internet facing. Worse; from version printing, less than 5% are patched for the two CVEs being exploited.

                          Kevin BeaumontG This user is from outside of this forum
                          Kevin BeaumontG This user is from outside of this forum
                          Kevin Beaumont
                          wrote last edited by
                          #12

                          Liverpool Echo reports Jaguar Land Rover production still isn't running, with factory staff told to stay at home, and report it impacts all manufacturing locations. https://www.liverpoolecho.co.uk/news/liverpool-news/update-jaguar-land-rover-shut-32411513

                          Separately, the network border is also still offline (I have monitoring in place to see when they come back online).

                          Kevin BeaumontG 1 Reply Last reply
                          0
                          • Kevin BeaumontG Kevin Beaumont

                            Liverpool Echo reports Jaguar Land Rover production still isn't running, with factory staff told to stay at home, and report it impacts all manufacturing locations. https://www.liverpoolecho.co.uk/news/liverpool-news/update-jaguar-land-rover-shut-32411513

                            Separately, the network border is also still offline (I have monitoring in place to see when they come back online).

                            Kevin BeaumontG This user is from outside of this forum
                            Kevin BeaumontG This user is from outside of this forum
                            Kevin Beaumont
                            wrote last edited by
                            #13

                            If anybody runs into a LAPSUS$ incident at their org hit me up on Signal, I can try to help profile their MO as been there, done that.

                            They'll frequently not even bother to deploy ransomware, they'll also do crazy things (and like to write about poo, and send people poo packages in the mail). It's basically like fighting Mr Bean, who is also good at computers.

                            Kevin BeaumontG 1 Reply Last reply
                            0
                            • Kevin BeaumontG Kevin Beaumont

                              If anybody runs into a LAPSUS$ incident at their org hit me up on Signal, I can try to help profile their MO as been there, done that.

                              They'll frequently not even bother to deploy ransomware, they'll also do crazy things (and like to write about poo, and send people poo packages in the mail). It's basically like fighting Mr Bean, who is also good at computers.

                              Kevin BeaumontG This user is from outside of this forum
                              Kevin BeaumontG This user is from outside of this forum
                              Kevin Beaumont
                              wrote last edited by
                              #14

                              This isn't anything against the LAPSUS guys btw as they're basically having a five year ninja fight with Mandiant, DART, cyber standards and law enforcement while playing teenage Mr Bean and lets be honest... that's pretty funny and eye opening.

                              Kevin BeaumontG 1 Reply Last reply
                              0
                              • Kevin BeaumontG Kevin Beaumont

                                This isn't anything against the LAPSUS guys btw as they're basically having a five year ninja fight with Mandiant, DART, cyber standards and law enforcement while playing teenage Mr Bean and lets be honest... that's pretty funny and eye opening.

                                Kevin BeaumontG This user is from outside of this forum
                                Kevin BeaumontG This user is from outside of this forum
                                Kevin Beaumont
                                wrote last edited by
                                #15

                                ITV reports Jaguar Land Rover has shut down car production in the UK, Slovakia, China, India and Brazil.
                                https://www.itv.com/news/2025-09-04/jaguar-land-rover-temporarily-halts-all-car-production-following-cyber-attack

                                Kevin BeaumontG 1 Reply Last reply
                                0
                                • Kevin BeaumontG Kevin Beaumont

                                  ITV reports Jaguar Land Rover has shut down car production in the UK, Slovakia, China, India and Brazil.
                                  https://www.itv.com/news/2025-09-04/jaguar-land-rover-temporarily-halts-all-car-production-following-cyber-attack

                                  Kevin BeaumontG This user is from outside of this forum
                                  Kevin BeaumontG This user is from outside of this forum
                                  Kevin Beaumont
                                  wrote last edited by
                                  #16

                                  ITV News 6pm lead story on Jaguar Land Rover

                                  Key take away is anonymous source at JLR saying they may need UK government support for motor sector off the back of the incident.

                                  https://www.youtube.com/watch?v=V4xQz0iKK4g

                                  Kevin BeaumontG 1 Reply Last reply
                                  0
                                  • Kevin BeaumontG Kevin Beaumont

                                    ITV News 6pm lead story on Jaguar Land Rover

                                    Key take away is anonymous source at JLR saying they may need UK government support for motor sector off the back of the incident.

                                    https://www.youtube.com/watch?v=V4xQz0iKK4g

                                    Kevin BeaumontG This user is from outside of this forum
                                    Kevin BeaumontG This user is from outside of this forum
                                    Kevin Beaumont
                                    wrote last edited by
                                    #17

                                    JLR is keeping all factory production suspended today, tomorrow, Sunday and at least Monday (possibly longer) in UK, Slovakia, China, India and Brazil.
                                    https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-staff-until-32413174

                                    Kevin BeaumontG 1 Reply Last reply
                                    0
                                    • Kevin BeaumontG Kevin Beaumont

                                      JLR is keeping all factory production suspended today, tomorrow, Sunday and at least Monday (possibly longer) in UK, Slovakia, China, India and Brazil.
                                      https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-staff-until-32413174

                                      Kevin BeaumontG This user is from outside of this forum
                                      Kevin BeaumontG This user is from outside of this forum
                                      Kevin Beaumont
                                      wrote last edited by
                                      #18

                                      JLR direct employ 32k people in the UK so I imagine there's going to be ripple effects on the wider economy off the back of this one the longer it goes on.

                                      Kevin BeaumontG 1 Reply Last reply
                                      0
                                      • Kevin BeaumontG Kevin Beaumont

                                        JLR direct employ 32k people in the UK so I imagine there's going to be ripple effects on the wider economy off the back of this one the longer it goes on.

                                        Kevin BeaumontG This user is from outside of this forum
                                        Kevin BeaumontG This user is from outside of this forum
                                        Kevin Beaumont
                                        wrote last edited by
                                        #19

                                        Meanwhile the LAPSUS guys were busy posting large numbers of US defense Top Secret marked documents last night. They've since been deleted from Telegram.

                                        1 Reply Last reply
                                        1
                                        0
                                        • R AodeRelay shared this topic
                                        Reply
                                        • Reply as topic
                                        Log in to reply
                                        • Oldest to Newest
                                        • Newest to Oldest
                                        • Most Votes


                                        • Login

                                        • Don't have an account? Register

                                        • Login or register to search.
                                        • First post
                                          Last post
                                        0
                                        • Categories
                                        • Recent
                                        • Tags
                                        • All Topics
                                        • Popular
                                        • World
                                        • Users
                                        • Groups