← All news

ransomware

JLR Hack Looks Less Like a Heist and More Like Sabotage

2026-06-29

A New York Times report this week put Russia in the frame for last year's attack on Jaguar Land Rover, an incident now reckoned to have cost the British economy around £1.9bn and the carmaker itself roughly $350m this fiscal year. Microsoft had reportedly been tracking the group and tipped JLR off. The Times itself stopped short of naming the Kremlin. Others have been less careful.

The tell is what didn't happen

Halcyon's Cynthia Kaiser points to the absence of the usual ransomware furniture. No ransom note. No negotiation. No haggling over a payout. Ransomware crews exist to get paid, and whoever did this didn't seem interested in money at all.

The rest of the shape is just as awkward. The attack landed just before a major vehicle launch. The ransomware used a novel and reportedly remarkable encryption algorithm, the sort of thing you build, not buy. And Land Rover is about as embedded in the British establishment as a carmaker gets: royals, military, the lot.

Sabotage in fancy dress

Former Paramount CISO Pete Chronis put it bluntly on LinkedIn: nobody asked for money, they just wanted the company on the floor. Dressing the operation up as cybercrime gives a nation state plausible deniability and keeps the response well below the threshold that would normally trigger a geopolitical reaction.

The early confusion helped. Scattered Lapsus$ Hunters loudly claimed credit, conveniently muddying attribution at exactly the right moment. By the time anyone took a serious look, the noise had already done its job.

What the former CISO said

Ashish Shrestha, JLR's group CISO at the time, told Infosecurity the attackers were sophisticated and asked him within 24 hours not to involve law enforcement. He didn't. He also said, notably, that no social engineering was involved, which cuts directly against the widely repeated story that vishing was used to harvest credentials.

For added flavour, the Times reports that a Jordanian hacker known as Rey breached part of the network independently, because of course someone else was in there too.

The precedent is the problem

This is the uncomfortable part. If a nation state can wreck a major manufacturer, knock nearly two billion pounds out of a G7 economy, and walk away because the whole thing looked enough like ransomware to confuse everyone for long enough, that playbook is going to get used again.

What looked like a criminal attack with a ransomware label slapped on the front is starting to look much more like sabotage that borrowed the costume. The label matters, because it shapes the response, the insurance, the regulator, the headlines. Get the label wrong and you mis-price the threat.

JLR will rebuild. The harder problem is that the next target won't know, in the moment, whether it's being robbed or wrecked. And the people running the playbook are counting on that confusion.

JLR Hack Looks Less Like a Heist and More Like Sabotage | RiskSense