Field Notes / Supply Chain
The Jaguar Land Rover Cyber Attack Hit Over 5,000 UK Organisations. Almost None of Them Were the Target.
The Cyber Monitoring Centre modelled the UK cost of the JLR incident at £1.9 billion and counted more than 5,000 UK organisations affected. Most of those firms were never attacked. Their security held and their revenue stopped anyway, because it depended on one buyer whose plants went quiet. Here is the supplier's version of the event, what the £1.9bn figure actually rests on, and the question a scoped penetration test will never answer unless you put it in scope.
01 The supplier’s version of the incident
In late August 2025 JLR shut down its IT environment and halted global manufacturing, including the UK plants at Solihull, Halewood and Wolverhampton CMC statement, October 2025 . Production stayed suspended for roughly five weeks. The CMC puts the reduction in UK manufacturing at close to 5,000 vehicles a week, each week costing JLR's UK manufacturing operations a modelled £108 million in fixed costs and lost profit.
Read those numbers from the other end of the order book. Three West Midlands chambers of commerce surveyed 84 businesses representing more than 29,700 employees and published the results on 26 September 2025 West Midlands chambers survey . Of those 84 firms, 77% reported a negative impact and 44% called it significant. 45% reported significant financial damage including lost revenue, higher costs and customers slowing their payments. 35% had already cut staff hours or asked people not to come in. 14% were making redundancies. 17% were asking their bank for more finance, and 18% wanted protection from exposure under the Insolvency Act until the crisis ended. It is a small, self-selecting regional sample. It is also the closest public record of what that month felt like inside a tier two machine shop.
JLR's payment calendar made it worse. Its standard supplier terms are 60 days after invoice JLR supplier financing, October 2025 . A supplier that delivered in August was waiting on cash in October, from a customer that had stopped taking deliveries in between. JLR restarted in phases from 8 October and launched a financing arrangement paying qualifying suppliers the majority of an order shortly after it is placed, accelerating payment by up to 120 days and reimbursing suppliers' financing costs during the restart. By November that had become a £500 million facility paying qualifying suppliers at the point of production scheduling JLR Q2 FY26 results .
Government moved at the same time. Officials from the Department for Business and Trade attended an extraordinary meeting of the SMMT Automotive Components Section on 19 September to hear from suppliers directly Joint supplier statement . On 28 September the government backed up to £1.5 billion of commercial bank lending to JLR through an Export Development Guarantee from UK Export Finance, repayable over five years, to bolster cash reserves so the company could support its supply chain £1.5bn loan guarantee . JLR employs 34,000 people directly in the UK, and its supply chain supports around 120,000 jobs.
The CMC is blunt about how far down the pain went. It describes suppliers "reducing pay, banking hours, and in some cases laying off staff", and records "at least one case a supplier taking out a personally backed loan to support the business" CMC statement, October 2025 . It also flags the reason nobody could see the bottom of the chain: "As JLR lacks direct relationship with many lower-tier suppliers, it will need to collaborate closely with its direct suppliers to ensure that all key elements of the supply chain are supported."
02 What the £1.9bn actually rests on
Most people quote the £1.9 billion without the conditions the CMC attached to it. The CMC calls its work "scenario-based analysis rather than confirmed operational data", based on information available as of 17 October 2025 CMC statement, October 2025 . Its evidence base is public data, supplier data, sector benchmarks and "insights shared by industry experts and those impacted by the event", and it says outright that "some of insights are anecdotal as opposed to verified JLR disclosures". The estimate excludes JLR's overseas operations and non-UK suppliers. It excludes any loss from the apparent data breach. It assumes nothing about ransoms, because nothing about ransoms has emerged publicly.
One assumption matters more than the rest. The model runs "a straight-line recovery from 8 October when the return to limited production was announced, to early January 2026", and the financial impact assessment is "based on an early January 2026 return to full production". JLR's own results tell a different story. On 5 January 2026 the company stated that "production returned to normal levels only by mid-November post the cyber incident" JLR Q3 sales, January 2026 , roughly seven weeks earlier than the model assumed. The CMC has also said the rating will not move as more information emerges.
That gap does not make the event small. JLR reported Q2 FY26 revenue of £4.9 billion, down 24% year on year, a loss before tax excluding exceptional items of £485 million against a £398 million profit a year earlier, and £196 million of cyber related costs inside £238 million of exceptional costs for the quarter JLR Q2 FY26 results . Q3 wholesales came in at 59,200 units, down 43.3% year on year JLR Q3 sales, January 2026 . The point is narrower and more useful: the headline figure is a model, the model has published assumptions, and one of them was later contradicted by the victim's own filings.
Two other figures get misquoted. The 5,000 is a count of UK organisations affected, which includes dealerships, logistics and export firms and local businesses that lost worker spending, and the CMC's supplier description is "nearly one thousand tier one suppliers, and thousands of tier two and three suppliers". The 2,700 is not a victim count at all. It is the Category 3 threshold: material financial impact to more than 2,700 UK organisations.
03 What is reachable from their portal
Every supplier holds a connection into its customer, and most manufacturers hold several: a VPN into the buyer's network, an EDI link that exchanges orders and despatch advices, a portal login for schedules and self-billing, a shared file store for drawings, and increasingly a federated identity so one login works in both organisations. Each one is a path, and paths run both ways.
A single supplier portal credential is worth more than the portal. It exposes the order data and delivery schedules behind it, which tells an attacker what you build and when. It often exposes drawings and specifications. It can expose an EDI endpoint, where a forged despatch or an altered bank detail is a fraud rather than a hack. Where the portal sits behind the buyer's single sign-on, the credential inherits whatever trust that federation grants. And the same password is frequently reused inside the supplier's own estate, which turns one stolen buyer-side login into a way into your email and your finance system. A test walks those paths deliberately, in scope and with permission, so the findings arrive with proof rather than after an incident.
Attackers take that path in nearly half of all breaches now. Verizon's 2026 Data Breach Investigations Report found that breaches involving a third party now account for 48% of all breaches, with third-party involvement up 60%, and that 31% of all breaches start with vulnerability exploitation, the first time in nineteen years that exploitation has passed stolen credentials Verizon DBIR 2026 . The NCSC's Annual Review 2025 recorded 429 incidents needing its incident management team in the year to 31 August 2025. 204 of those, 48%, were nationally significant, against 89 the year before, and 18 were highly significant, close to a 50% increase NCSC Annual Review 2025 . Manufacturing sits among the top sectors reporting ransomware to the NCSC.
Three questions put this into a scope. Which of your systems are reachable from your customer's network, and which of theirs are reachable from yours? What does a working portal credential reach if an attacker has it, including anywhere that password is reused? And is the machine that holds the VPN client or the EDI gateway segmented from the finance system, or is it a workstation in the office? An external penetration test answers the first from the internet inwards. A scoped penetration test that includes the customer connection answers the other two.
04 Concentration risk as a testable question
The body that priced the event states the finding for you. In its recommendations the CMC writes: "Having a high proportion of revenue reliant on a single ultimate customer increases the potential impact if that supplier stops operating. Tier 0.5, 1, and 2 suppliers should assess revenue concentrations and maintain liquidity buffers or develop other mitigation strategies to manage extended shutdowns." CMC statement, October 2025 That is a risk assessment instruction, published by a body whose job is categorising systemic cyber events, aimed at firms whose own security was fine.
The CMC's advice to boards for 2026 turns it into three tasks: identify the critical digital assets required to deliver business value, challenge systems compromise scenarios, and hold recovery plans that contain losses when key systems fail. Note which risk it ranks first. "Operational disruption has generated virtually all of the financial loss. The cost dwarfs the financial losses associated with any previous known data breach incident." Its expectation is that future high-impact UK events will be disruptive rather than exfiltration-led.
None of that is exotic to scope. Name the customers that account for more than a fifth of your revenue. For each, write down what stops if their systems stop: the orders you cannot receive, the despatches you cannot confirm, the invoices you cannot raise. Ask what the business does for eight weeks without that income. Then have an offensive team test the technical half, which is the connection itself, and record the commercial half in the same report so one document reaches the board. The NCSC's supply chain security collection sets twelve principles for gaining and keeping control of a supply chain, and notes that very few UK businesses set minimum security standards for their suppliers NCSC supply chain security .
05 What 15% and 6% mean for you
DSIT surveyed 2,112 UK businesses, 1,085 charities and 577 education institutions between August and December 2025 for the Cyber Security Breaches Survey 2025/2026. That is the exact window in which JLR's supply chain was falling over. Just over one in ten businesses, 15%, said they reviewed the risks posed by their immediate suppliers. Under one in ten, 6%, looked at their wider supply chain DSIT CSBS 2025/26 . Charities came in at 9% and 4%.
Split the same question by size and you sit on both sides of it. 48% of large businesses and 30% of medium businesses review the cyber security risks posed by their immediate suppliers, against 22% of small businesses and 12% of micro businesses. Large customers run that review four times as often as micro suppliers do, so the request for evidence reaches you from above. The tiers below you mostly go unreviewed, and the CMC has just documented what happens to a chain whose lower tiers are invisible.
The same survey explains why the evidence is thin when the request arrives. 13% of UK businesses ran a penetration test in the last twelve months, 18% carried out a vulnerability audit, and 5% hold Cyber Essentials, up from 3% the year before. 43% reported a breach or attack in the same twelve months DSIT CSBS 2025/26 . The distance between 43% and 13% is the distance between what happens and what gets tested.
The request is coming in writing. The government launched its Cyber Resilience Pledge at Downing Street in July 2026. Signatories commit to register for the Cyber Essentials Supplier Check Tool within two months of signing, put an audit of Cyber Essentials coverage across their supply chain in front of the board, and "take a risk-based approach to requiring Cyber Essentials across our supply chain (which may include requiring it from all suppliers)" Cyber Resilience Pledge . By September 2026 over 140 businesses had signed, and 61,430 Cyber Essentials certificates were awarded in the year to 30 June 2026, 15,185 of them Cyber Essentials Plus DCMS newsletter, September 2026 . The same newsletter records the Cyber Security and Resilience Bill completing Lords committee stage. Under that Bill, regulators will be able to designate critical suppliers and bring them inside the regulatory regime DSIT Bill factsheet . We covered what it will ask of providers in the Bill and your MSP. If your biggest customer signs the pledge, their commitment becomes your purchase order condition, and Cyber Essentials becomes the entry ticket rather than the finish line.
The suppliers hurt in autumn 2025 did not fail a security test. What hit them arrived through a commercial dependency rather than a firewall. You can get two answers this month: what an attacker reaches through the connection your largest customer gave you, and what your business does if that customer goes quiet for eight weeks. We find the first by attacking it, hand you every path with proof and a plain fix, and re-test for twelve months so the answer stays current when the next tender asks. Book the free audit and we will tell you where an attacker would start, in thirty minutes, with your own systems on the screen.
References
Sources
- Cyber Monitoring Centre. Statement on the Jaguar Land Rover Cyber Incident, 22 October 2025. cybermonitoringcentre.com
- DSIT / Home Office. Cyber Security Breaches Survey 2025/2026. Official statistics, 30 April 2026. gov.uk
- HM Government. Government backs Jaguar Land Rover with £1.5 billion loan guarantee, 28 September 2025. gov.uk
- HM Government. Joint statement on government-industry supplier meeting regarding the Jaguar Land Rover cyber incident, 19 September 2025. gov.uk
- Black Country, Greater Birmingham, and Coventry and Warwickshire Chambers of Commerce. Survey of 84 businesses, 26 September 2025. blackcountrychamber.co.uk
- JLR. JLR restarts manufacturing and introduces new financing solution to pay JLR suppliers early, 7 October 2025. jlr.com
- JLR. Performance impacted in a challenging quarter (Q2 FY26 results), 14 November 2025. media.jlr.com
- JLR. Q3 sales impacted by cyber incident as previously indicated, 5 January 2026. jlr.com
- NCSC. Annual Review 2025, incident management (1 September 2024 to 31 August 2025). ncsc.gov.uk
- NCSC. Supply chain security collection, twelve principles. Page reviewed 22 October 2025. ncsc.gov.uk
- Verizon. 2026 Data Breach Investigations Report, newsroom announcement, 19 May 2026. verizon.com
- HM Government. Cyber Resilience Pledge declaration, 13 July 2026. gov.uk
- DCMS. Cyber Security Newsletter, September 2026. Published 15 September 2026. gov.uk
- DSIT. Cyber Security and Resilience (Network and Information Systems) Bill factsheet: Summary of the Bill. gov.uk