An investigation into a large-scale hack of the systems of the British automaker Jaguar Land Rover has revealed its connection with a group of Russian hackers. The New York Times writes about this, citing five sources familiar with the investigation.
The cyber attack in question took place in August last year. It forced the corporation to shut down its IT systems and suspend all production for several weeks. The hack was the most expensive in the country's history.
A hacker group, including the British, then took responsibility for the hacking, but back in the fall of 2025, The Telegraph newspaper wrote that suspicions fell on hacker groups from Russia.
This is confirmed by the current findings of the investigation, writes NYT. The Russian trace in this hacker attack of the affected company was also confirmed by Microsoft. It remains unclear, however, whether the hackers acted on the instructions of the Kremlin or on their own.
Hackers exploited vulnerabilities in outdated Jaguar Land Rover technologies, as well as advanced software. Cybersecurity experts interviewed by the newspaper noted that the encryption they launched had not been used in hacker attacks before. It has been called "very complex" and even "mind-blowingly" complex."
Cyber attacks from Moscow-backed groups are far from a new phenomenon, the NYT notes. However, given the specific target of the attack - Jaguar - and the potential involvement of the Russian state, analysts conclude that this was not an ordinary extortion attack, but an attack on the economic foundations of the UK.
Jaguar Land Rover produces not only civilian cars (including King Charles III), but also cars for the British military. The company was able to restore production to normal levels only by November 2025, which took about two months.