back to article Jaguar Land Rover cyber-meltdown tipped to cost the UK almost £2B

The Jaguar Land Rover (JLR) cyberattack could end up being the costliest such incident in UK history, billed at an estimated £1.9 billion and affecting over 5,000 organizations. The figure comes from the Cyber Monitoring Centre (CMC) nonprofit, which categorizes and classifies incidents in the digital world. Events are …

  1. cd Silver badge

    Ta-Ta

    Good to see, nepo needs to become painfully expensive.

    1. Ochib

      Re: Ta-Ta

      Yeah but the UK government has loaned them a few billion. Which hopefully they will get back, I hope it's not a 0% loan

      1. Anonymous Coward
        Anonymous Coward

        Re: Ta-Ta

        At least it's a loan, not a subsidy.

        Now, what OS were they using?

        /me ducks quickly :)

        1. Anonymous Coward
          Anonymous Coward

          Re: Ta-Ta

          Like the £1/2bn bung from the previous Tory Govt to build the JLR battery giga factory in the automotive manufacturing backwater of Tory Somerset and not opposite their Head Office in Coventry - less the 10 miles from JLR Solihull main factory - on the site allocated for it- where lefty gobshite Zarah Sultana is MP.

          Even odder as the (Government supported) UK battery industrialisation centre is adjacent to this lot in Coventry.

          Pork barrelling.

  2. Charlie Clark Silver badge

    Coincidentally…

    … or not. JLR outsourced much IT to another subsidiary of its parent Tata, said subsidiary has been involved in various cyber-attacks recently.

    1. Anonymous Coward
      Anonymous Coward

      Re: Coincidentally…

      'Involved' as in 'perpetrating' or 'being on the receiving end'?

      Just curious :)

      1. Teal Bee

        Re: Coincidentally…

        A distinction without a difference.

  3. deive

    "financial support to the tune of £1.5 billion" - tory capitalists are the first to demand some socialism when it is for them.

    1. Anonymous Coward
      Anonymous Coward

      “Lucra privatiza, sumptus socializa”

      The motto of the Conservative Party.

    2. Anonymous Coward
      Anonymous Coward

      Given it was the unions who were out of the gate immediately asking for a spot of "compo" then I would say the trough guzzling piggies span both sides of the political spectrum ................

  4. Anonymous Coward
    Anonymous Coward

    MPs press outsourcer TCS over Jaguar cyber attack

    MPs press outsourcer TCS over Jaguar cyber attack

    “The government’s cross-bench Business and Trade Committee has written to Tata Consultancy Services seeking answers over possible links to cyber attacks on Jaguar Land Rover, Marks and Spencer, and Co-op”

    Hackers Prey On Tata’s Cozy Boards To Stall Jaguar Land Rover

    Background: JLR's Connected Enterprise Architecture Creates Massive Attack Surface

  5. Tron Silver badge

    Is there an issue with vanishing posts?

    Or do we have a new censor at El Reg?

    1. Taliesinawen

      Re: Is there an issue with vanishing posts?

      > Or do we have a new censor at El Reg?

      I've noticed some posts take ages to show-up. I promise to be good from now on :|

      1. Anonymous Coward
        Anonymous Coward

        Re: Is there an issue with vanishing posts?

        I've noticed a general slowdown over the last few days

        I would have blamed it on the new MacOS, but I also notice it on the Windows laptop from work so it may be something Microsoft is doing.

        Maybe its datacenters are full? With all the user data it's been 'liberating' there must be a point where space becomes an issue..

      2. Michael Strorm Silver badge

        Re: Is there an issue with vanishing posts?

        I noticed that too, and assumed it was just me. Some posts of mine took ages to appear, to the point I thought they'd possibly been shadow blocked in the most recent case.

        There sometimes used to be a delay if it was obvious a more controversial thread was having its comments pre-screened before showing up, but it seems to be worse recently.

    2. Doctor Syntax Silver badge
      IT Angle

      Re: Is there an issue with vanishing posts?

      I think somebody must have bitten the hand that fed IT.

      Total Inability To See Users' Posts.

    3. David Hicklin Silver badge

      Re: Is there an issue with vanishing posts?

      I seem to be seeing posts repeated unless the vertical hold on my eyesight is playing up again

  6. Woodnag

    "The issue was so severe that in September the UK government had to step in with financial support to the tune of £1.5 billion as JLR struggled to bring its systems back online."

    Because parent Tata Motors https://en.wikipedia.org/wiki/Tata_Motors (a public company) can't afford to pay for its own screwups, so the cost is socialised to the British taxpayer.

    1. Anonymous Coward
      Anonymous Coward

      Not socialized, this is a loan, not a subsidy. Heck, it may be the one activity this government has done that has the potential to turn a net positive..

      1. David Hicklin Silver badge

        I thought it was more a loan guarantee for the suppliers rather than a loan

  7. VoiceOfTruth Silver badge

    Computers make your life easier

    Until they don't.

    The dependence we ("we" in general) are building on computers is scary. The foundations may sometimes look firm, but it's only a little way down to the sand.

  8. elsergiovolador Silver badge

    Outsourcing

    Outsourcing saves money, you see?

    Terminally Confused Squad will fix it.

    1. Anonymous Coward
      Anonymous Coward

      Re: Outsourcing

      I suspect there will be a frantic deleting of email where suggestions to shore up their security were blocked by accountants on behalf of owners/shareholders..

    2. Dwarf Silver badge

      Re: Outsourcing

      I've worked on several programmes with Hopeless Consultants and Loosers.

      Possibly with a couple of alternative spellings around the C bit.

      But, as the old addage goes, pay peanuts, get monkeys.

  9. Tron Silver badge

    Political depths of transparency, compared to Amazon's downtime.

    Oh, and JLR are an Indian company, not a British one. A subsidiary of Tata. So how was it on the scale of Indian cyber attacks?

    The supply chain/workers were in part UK located, although car supply chains are international, but the bill for downtime should be Tata's.

    Jaguar and Land Rover were previously owned by Ford, so the Americans dodged the bullet on this one.

    Very little in the UK is actually British owned. Wealthy Britons are generally too lazy to go to the trouble of making things or employing people, to increase the size of their bank balances.

    1. Doctor Syntax Silver badge

      Re: Political depths of transparency, compared to Amazon's downtime.

      Wealthy Britons are generally too lazy to go to the trouble of making things or employing people in Britain

      FTFY

  10. Taliesinawen

    Analysis of the JLR Hack

    JLR Breach Breakdown: Analysis of the JLR Hack and Lessons Learned

    ‘Jaguar Land Rover is a global carmaker operating “smart” factories and integrated digital systems for manufacturing, logistics, and customer services. In today’s automotive industry, “everything is connected,” meaning that production lines, enterprise IT, and even customer-facing applications are deeply interlinked.’

    ‘This connectivity enables efficiency and innovation, but it also creates a broad attack surface if security is not airtight. JLR had invested heavily in IT modernization, including a £800 million contract for cybersecurity and IT support with a major consulting firm; yet, the breach showed that even well-funded defenses can falter against determined adversaries.’

    Hackers Prey On Tata’s Cozy Boards To Stall Jaguar Land Rover

    1. Anonymous Coward
      Anonymous Coward

      Re: Analysis of the JLR Hack

      I would *so* love to have the name of that 'major consultancy' so I know who to avoid..

      1. cookiecutter Silver badge

        Re: Analysis of the JLR Hack

        rhymes with Rata

        1. Anonymous Coward
          Anonymous Coward

          Re: Analysis of the JLR Hack

          This is an IT forum, I would have gone with SATA.

          :)

  11. Anonymous Coward
    Anonymous Coward

    Company selling cyber incident insurance says cyber incidents can be very expensive if you don't have insurance.

  12. This post has been deleted by its author

  13. Mark Exclamation

    I wonder if this will make them pay attention to their backups, now?

    1. Anonymous Coward
      Anonymous Coward

      I think their vehicles beep when they reverse.

      No, wait..

      :)

  14. This post has been deleted by its author

  15. MaDeX
    IT Angle

    Budget

    Wondering if they set aside a nice budget for strengthing their I.T structure or made cuts to help share holders.

  16. af109
    Stop

    Shared learning

    As with this and perhaps the M&S debacle I feel that details on exactly what happened, and lessons learned, are always kept in the dark.

    This is seemed to be some form of security from the companies affected. Which is very ironic given they were already well and truly screwed as a result of these breaches.

    In the linked article it says (emphasis mine)

    "As a result of our ongoing investigation, we now believe that *some data* has been affected

    JLR *did not identify the type of data* affected. "We are very sorry for the continued disruption this incident is causing and *we will continue to update* as the investigation progresses"

    No clear details of what actually happened and of course they never make public what they actually learned.

    I feel if they were open - or dare I say it even forced to be open by regulators - about WTF actually happened and how they resolved it, then other companies might sharpen up before this sort of thing continues.

    Saying we lost £x billion is a piss take when they aren't even prepared to admit what they got wrong. Very quick to put figures to what they feel they've lost but much less slower when it comes to any wrongdoing on their part. Not really a surprise though is it.

    1. elsergiovolador Silver badge

      Re: Shared learning

      No clear details of what actually happened

      Outsourcing. It's always outsourcing.

  17. MaDeX
    IT Angle

    I.T Budget

    Wondered if they made cuts to I.T to help the poor shareholders, then expect a government bailout.

  18. eyesonit

    Lessons to be learned

    Another stark reminder why prevention isn't enough, the Maersk landmark event should have been the lesson. Investment in assurance and recovery people! Lessons to be learned from regulated industries.

    1. cookiecutter Silver badge

      Re: Lessons to be learned

      maersk learnt from that fuck up, i went to a talk by their head of security & to be fair, what they're doing is bloody amazing considering size, the number of countries they work in & apparently up until this guy came in, some terminals were guarded by tigers!!

      JLR & TATA have ZERO excuses. it isn't that hard to secure an infrastructure.

      the fact that there are so many Uk IT people unemployed & offshoring is still happening is disgusting.

      Govt should have told Tata to fuck off! The same with any firm that offshores.. go ahead but the tax payer will be happily sticking 2 fingers up to you when it goes tits up. As Lloyds shifts its IT offshore again, the government should remote the tax payer deposit guarantee.

      you're private companies, do what you want but don't expect the tax payer to come running to your rescue as you ship jobs offshore

  19. Dwarf Silver badge

    I wonder ...

    What was the budget for the security function in JLR before this incident and how much had people fought to get it to an appropriate amount so that they could deliver what was necessary, whilst a more senior management denied requests as not necessary.

    Then, now that this has happened, you can bet that the wallet is wide open to security to please just get us out of this fscking mess ....

    Once its all fixed, any guesses as to which mode of operation will prevail ?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon