Jaguar Land Rover has been forced to suspend production and even sales operations after what appears to be a major cyber attack.

The disruption has affected global systems and led to plants, including the Halewood Assembly facility in Merseyside, England, telling workers not to report for duty. The company’s parent, Tata Motors, confirmed its global IT division was working to contain the incident.

According to The Guardian, cybersecurity experts believe the swift shutdown shows just how serious the threat is. Oakley Cox, director at UK firm Darktrace, said the fact JLR halted operations worldwide suggested that attackers may have been targeting core operational systems rather than simply customer data.

At this stage, JLR has not provided details on who was behind the attack, when it was detected, or how long recovery will take. The UK’s National Cyber Security Centre has been contacted for comment but has not released further information.

The automaker has issued a short statement, stressing that it does not believe customer data has been compromised. “We are now working at pace to restart our global applications in a controlled manner,” the company said. “At this stage there is no evidence any customer data has been stolen but our retail and production activities have been severely disrupted.”

This is not the first time JLR has been linked to cyber breaches. Earlier this year, the Hellcat ransomware group claimed to have stolen corporate documents, source codes, employee data, and more. JLR downplayed the claims at the time, noting that it was not the only manufacturer dealing with such threats.

The timing is also significant. March 2025 saw a wave of ransomware attacks across industries, many of which locked companies out of their own systems. As automakers digitise production lines, integrate connected vehicle services, and outsource cloud storage to providers like Amazon, the attack surface has widened considerably.

The incident highlights the vulnerability of modern carmakers. Vehicles and factories are now as much software as they are machinery. With more data available to steal and more connected systems to exploit, the automotive sector is becoming a prime target for cybercriminals.

For Jaguar Land Rover, the priority is restoring production. But the bigger challenge may be restoring confidence in its ability to protect both its operations and its customers in a digital age.

Brands