When hackers cut through the open path: inside the 95 million euro per day crisis at Jaguar Land Rover

23. septembra 2025

The halt of global production at Jaguar Land Rover due to a cyberattack reveals an uncomfortable truth about modern industry. When hackers can paralyze assembly lines from Britain to Slovakia with just a few keyboard clicks, it testifies to a fundamental shift in industrial vulnerability.

Let's look at the mathematics of disruption. JLR achieves annual revenues of approximately 35 billion euros – representing around 95 million euros daily. However, managers are painfully discovering that when production stops in a "just-in-time" environment, this money won't wait for you. Irreplaceable production slots cause a domino effect across suppliers, transport schedules, and dealer inventory stocks. Revenue simply disappears.

This isn't just a problem for the United Kingdom, where JLR accounts for 4% of total goods exports. It's equally serious for Slovakia. The plant in Nitra, which produces Discovery and Defender models, ranks among the jewels of foreign investment in Central Europe. In a country where the automotive industry provides more than a tenth of GDP and supports 200,000 jobs, a cyberattack thousands of kilometers away immediately transforms into an urgent domestic crisis.

The attackers – whether they call themselves Hellcat, Scattered Lapsus$ Hunters, or something entirely different – have revealed a reality that the industry has been unwilling to acknowledge until now. The clean separation between digital systems and physical production lines is an illusion. When IT infrastructure gets hacked, robots stop functioning, conveyor belts halt, and the carefully choreographed ballet of modern industry collapses. All of this happening precisely in September, when dealers are feverishly clearing warehouses and trying to meet quarterly targets.

It's no wonder that manufacturing has become an irresistible target for cybercriminals. Downtime costs are astronomical, supply chains are stretched so tight that every outage immediately spreads further, and brand damage grows hour by hour. Management boards, which until recently viewed cybersecurity as a technical issue on the IT department's periphery, today recognize that it must be at the core of corporate strategy.

Old approaches – checking off ISO 27001 compliance boxes, annual penetration tests, firewall patches – seem almost nostalgically retroactive. Real resilience requires more radical solutions. Organizations must have continuous oversight of every corner of their IT and OT networks. They need to transition from a "castle and moat" model to zero-trust architecture, which assumes from the start that defenses will be breached. Within such timeframes, they must begin implementing post-quantum cryptography before quantum computers completely invalidate today's encryption methods. And perhaps most importantly – they must know how to restore operations from clean backups without accidentally restoring the malicious code that originally knocked them out.

The Jaguar Land Rover episode destroys the last illusions that cyber risks are separate from business risks. When a single attack can erase 100 million euros from daily revenue, it represents an existential threat to large industrial enterprises. For the United Kingdom of Great Britain and Northern Ireland and Slovakia, economies heavily dependent on automotive manufacturing, the lesson is clear. Today's most modern factories in the world, full of cutting-edge robotics and automation, can be brought down by an ordinary computer virus. This is the new face of industry in the digital era. It's not a question of whether another attack will come, but when companies and countries will be prepared when it happens.

Source: Michalko, Matej. “Keď hackeri pretnú otvorenú cestu: vo vnútri krízy za 95 miliónov eur denne v Jaguar Land Rover.” DefenceNews.sk, September 22, 2025. https://www.defencenews.sk/kyberbezpecnost/clanok/766426-ked-hackeri-pretnu-otvorenu-cestu-vo-vnutri-krizy-za-95-milionov-eur-denne-v-jaguar-land-rover/. 

7. októbra 2026
A drone flying over a power plant, airport or water facility does not have to cause any physical damage to disrupt its operations. It may be enough for it to appear in the wrong place at the wrong time, while the critical entity has no idea what it is doing there. This is precisely why attention in Europe is shifting from technologies designed to neutralise drones to something less visible: the ability of critical entities to detect an incident in time, assess it correctly and manage it without unnecessary losses.
7. októbra 2026
Dron nad elektrárňou, letiskom alebo vodárenským objektom nemusí nič poškodiť, aby narušil jeho fungovanie. Stačí, že sa objaví v nesprávnom čase na nesprávnom mieste a kritický subjekt nevie, čo tam robí. Práve preto sa pozornosť v Európe presúva od samotných technológií na zneškodnenie dronov k niečomu menej viditeľnému: k schopnosti kritických subjektov incident včas zachytiť, správne vyhodnotiť a zvládnuť bez zbytočných strát.
2. októbra 2026
A series of expert articles by the Critical Infrastructure Association of the Slovak Republic on essential services under Annex No. 1 to Act No. 367/2024 Coll. on Critical Infrastructure
2. októbra 2026
Séria odborných článkov Asociácie kritickej infraštruktúry Slovenskej republiky o základných službách podľa prílohy č. 1 zákona č. 367/2024 Z. z. o kritickej infraštruktúre
29. septembra 2026
The incident at the primary school in Staškov brings back a topic that deserves continuous attention, not just attention in the aftermath of an incident. The protection of soft targets should form part of a systematic security policy, with clearly defined measures, responsibilities and preparedness for various types of threats.
29. septembra 2026
Udalosť v základnej škole v Staškove pripomína tému, ktorá si zaslúži pozornosť priebežne, nie až po incidente. Ochrana mäkkých cieľov by mala byť súčasťou systematickej bezpečnostnej politiky, s jasne nastavenými opatreniami, zodpovednosťami a pripravenosťou na rôzne typy hrozieb.
24. septembra 2026
We are continuing the series of expert articles by the Critical Infrastructure Association of the Slovak Republic, in which we gradually introduce the individual essential services listed in Annex No. 1 to Act No. 367/2024 Coll. on Critical Infrastructure. Having covered the operation of pipelines for the transport of crude oil and motor fuels, today we move one step upstream to a service that stands at the very beginning of the entire oil chain: crude oil extraction.
24. septembra 2026
Pokračujeme v sérii odborných článkov Asociácie kritickej infraštruktúry Slovenskej republiky, v ktorej postupne predstavujeme jednotlivé základné služby uvedené v prílohe č. 1 zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Po tom, ako sme sa venovali prevádzkovaniu potrubí na prepravu ropy a pohonných látok, sa dnes posúvame o krok proti prúdu k službe, ktorá stojí úplne na začiatku celého ropného reťazca: ťažbe ropy.
21. septembra 2026
On 16 September 2026, a test carried out in Norway demonstrated a new dimension of satellite navigation security. Europe’s Galileo system was tested under so-called spoofing conditions — a situation in which a receiver is fed a fake signal and may therefore receive incorrect information about its position.
21. septembra 2026
16. septembra 2026 sa v Nórsku uskutočnil test, ktorý ukázal nový rozmer bezpečnosti satelitnej navigácie. Európsky systém Galileo bol testovaný v podmienkach tzv. Spoofingu, teda situácie, pri ktorej je prijímaču podstrčený falošný signál a ten môže dostať nesprávnu informáciu o svojej polohe.