A Crew Took Credit for the Jaguar Land Rover Hack, but Investigators Now Point to Russia
Britain's costliest cyberattack was claimed by a Telegram crew. Investigators now point to Russian operators: novel ransomware, no ransom demand, encrypted backups. The defensive lessons that hold regardless of who was really at the keyboard.
The most expensive cyberattack in British history was blamed on the wrong people for months. Jaguar Land Rover went dark for five weeks: an estimated 2.5 billion hit to the UK economy, and $350 million out of JLR's own pocket. A group calling itself Scattered Lapsus Hunters took credit on Telegram, and most outlets ran with it.
Then the story changed. According to people close to the investigation, as reported by the New York Times, the operators who actually broke into JLR are believed to be Russian, and they were not there to extort a ransom. They were there to do economic damage. That detail has not been public until now, and it changes what the incident means for everyone else.
What actually happened
Around 31 August 2025, JLR knew something was wrong. It detected an intruder days before a major global vehicle rollout, and within hours it chose to pull its own plug: disconnect from the internet and halt production at plants in England, Brazil, China, India and Slovakia. That was a defensive call, not the attack landing. The ransomware was built to encrypt the backup servers too, so a full shutdown was how JLR stopped the intruder from taking the entire global network. Plants restarted in October and were back to full capacity by mid-November. To keep JLR's suppliers afloat through the crisis, the UK government backed a roughly $2 billion loan.
Who responded
The response team was heavy: the National Crime Agency, the National Cyber Security Centre, Google's Mandiant and Palo Alto Networks, with the FBI assisting. Microsoft, which had been tracking the Russian group, told JLR who was inside.
How the first story fell apart
Scattered Lapsus$ Hunters is a mashup of names, borrowing from Scattered Spider, Lapsus$ and ShinyHunters, crews tied to a string of high-profile breaches. Scattered Spider in particular was linked to the spring 2025 attacks on Harrods and Marks & Spencer, so on the surface the claim held together.
Forensics told a different story. The methods and the motive did not match anything associated with those three groups. Two things stood out. There was no ransom demand at all. And the ransomware carried a new encryption algorithm that the investigators doing the analysis said they had never seen before. The intruders moved quietly, exploited older vulnerabilities, and waited until they were ready to strike. That behaviour looks far more like statecraft than smash-and-grab crime.

The warning that came too late
In June 2025, an access broker known as "Rey" posted internal JLR data, including an internal IP address. Access brokers sell what they can already reach, so when Rey did this, JLR moved quickly: it patched the hole and rebuilt an old server that was vulnerable but still needed to keep the manufacturing line running.
It was already too late. The Russian operators had exploited the weakness and were sitting inside, waiting. The uncomfortable lesson is worth stating plainly: when an access broker is trading your data or your internal addresses, that is an active incident, not background noise. Patching the hole does nothing if someone is already through it.
State-directed, or just state-protected?
The real question is whether the Kremlin directed this or simply offered krysha, a protective "roof", to a Russian cybercrime group. There is precedent. In 2024, Britain sanctioned Evil Corp, a Moscow-based syndicate the National Crime Agency said had been used by Russian intelligence for attacks and espionage against NATO allies, well beyond the usual protection arrangement between a state and its criminals.
Jamie MacColl, a cyber research fellow who broke the reporting down publicly, put the strategic read cleanly: either a Russian criminal group acted on its own and caused more than 2 billion pounds in damage to the UK economy, or a Russian service ran an operation dressed up to look criminal so it could keep deniability. Both are bad, and both show why Russia treats its cybercrime ecosystem as an asset.
MacColl also flagged the caveat ZDW will underline. A missing ransom demand is suggestive, but it is not proof. Victims do not always engage with their attackers, so a ransom note may simply never have been sent. High-confidence attribution here rests on the relationship between these Russian crews and Russian intelligence, not on much that can be pulled from the malware itself. Here is the honest state of it: the forensics point one way, the certainty is not there yet, and anyone telling you they know for sure is running ahead of the evidence.
None of this is happening in a vacuum. It lands during open hostility between London and Moscow over Britain's support for Ukraine, and the same reporting notes that Britain runs its own offensive cyber operations against Russia.
The lessons that don't wait for attribution
Whoever turns out to have been at the keyboard, the defensive takeaways are already actionable.
- Treat backups as a primary target, not a safe haven. This ransomware went after the backup servers on purpose. Keep backups offline or immutable, because that is the line between a bad week and an existential one. If your backups sit on the same network segment as production, you do not have backups, you have more to encrypt.
- Access-broker chatter about your org is an incident. Leaked internal IPs or credentials for sale mean you assume breach and go hunting for the intruder. Closing the advertised entry point is not a response on its own.
- Do not let claims of responsibility shape your response, and do not read a missing ransom note as meaning anything. Telegram bragging and absent ransom demands are both noise to the people running the incident.
- Segment so you can amputate. JLR's global shutdown worked, but it cost five weeks because the alternative was losing everything. Better segmentation gives you the option to contain a blast radius without stopping the whole company.
- Your old, untouchable, business-critical systems are the soft spot. Inventory them now, because attackers already have.
The through-line: a Telegram post took the credit, but the incident was decided by unpatched legacy tech, encrypted backups, and an intruder who was already inside before anyone raised the alarm. None of that depends on knowing whose hands were on the keyboard.