700 internal Jaguar and Land Rover documents leaked

12 March 2025 2 minutes Author: Newsman

One of the UK’s largest car companies, *Jaguar Land Rover (JLR)*, has suffered a major data breach. Hackers using the pseudonym *Ray* allegedly accessed JLR’s internal systems and posted around 700 documents containing critical technical and operational information on the darknet.

Jaguar Land Rover has been hacked, with hundreds of sensitive documents leaked:

  • JLR software source code;
  • vehicle development and equipment integration logs;
  • employee databases including names, email addresses and time zones;
  • internal algorithms that could reveal surveillance datasets.

Cybersecurity experts believe the attack may have been carried out via compromised company servers or cloud storage. While no financial or customer data was compromised, the scale of the incident is of serious concern.

The Jaguar Land Rover hack is part of a global trend of attacks on major automakers: hacking groups such as ALPHV/BlackCat have previously used source code leaks to blackmail companies. However, in this case, *Ray* did not demand a ransom, and the motive for the attack remains unclear. Experts believe that an unpatched vulnerability in the software supply chain or a misconfigured API was exploited.

If the stolen files are confirmed to be authentic, this would be one of the most serious data breaches in the automotive industry, and JLR is being urged to urgently audit its code repositories, strengthen multi-factor authentication and review the security of its internal systems.

Other related articles
News
Read more
Lazarus group used 6 npm packages to steal developer logins
*Lazarus* hackers compromised 6 npm packages to steal developer logins and passwords. They used hidden code to collect data and send it to fake domains. The npm community has already eliminated the threat, but companies are advised to immediately update packages and change credentials. How the attack worked and how to protect yourself – read our article.
36
News
Read more
Switzerland obliges critical companies to report cyberattacks within 24 hours
Switzerland will introduce a new law that will require important organizations to report cyberattacks within 24 hours. The changes will come into effect on April 1, 2025, and failure to comply after October 1 will result in fines of up to 100,000 Swiss francs. Read our article to learn more about how the reporting system works and what it means for business.
47
Found an error?
If you find an error, take a screenshot and send it to the bot.