dealership sign of Jaguar Land Rover against blue sky

Jaguar Land Rover cyberattack: What happened, what are the risks, and what should you do now?

UPDATE: On 10 September 2025, Jaguar Land Rover (JLR) confirmed for the first time that data was stolen during the cyberattack that forced the company to shut down systems and halt production earlier this month.

A major cyberattack hit luxury car manufacturer Jaguar Land Rover (JLR) in early September 2025, causing massive global disruption and leaving customers worried about their personal information.

To date, there is no evidence of a personal data breach. However, Jaguar Land Rover customers should be vigilant as the situation develops. 

What happened in the Jaguar Land Rover cyberattack?

The cyberattack resulted in an outage that coincided with the key September registration period for new vehicle registrations.

JLR responded by shutting down its IT systems to contain the threat. This necessary step halted production at its UK plants and left dealerships unable to register new cars or complete customer orders. 

The UK’s National Crime Agency is investigating the incident, which JLR’s parent company, Tata Motors, confirmed was a global “IT security incidence”.

Why this matters

JLR has stated that “at this stage there is no evidence any customer data has been stolen”. However, this may not satisfy the concerns of many customers.

Cybersecurity experts warn that data theft is often discovered much later and have advised customers to be on “high alert” for targeted phishing scams. This incident also follows a separate data breach at JLR earlier in 2025, raising concerns about the company’s overall security.

Even without a confirmed data leak, customers have been affected by the significant disruption and anxiety caused by the major security failure.

What should you do now?

Following the cyberattack, we would advise all JLR customers to take these protective steps:

  1. Monitor your accounts: Keep a close watch on your bank accounts and online profiles for any unusual activity.

  2. Beware of phishing: Be extremely cautious of unsolicited emails or texts – especially those claiming to be from JLR. Never click on suspicious links or provide personal information. You can find more details on how to protect your data in our handy guide. 

  3. Register your interest in a potential claim: Due to the significant disruption and potential future risks, lawyers will now be assessing whether there could be grounds for a future group claim for affected JLR customers. With Join the Claim, you can register your interest for free to stay informed about the progress of this potential claim. It is likely that any future claim would be handled on a no-win, no-fee basis.

Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.  

This information is for general guidance only and does not constitute legal or financial advice.

You may also like:

BMW faces legal action over emissions-cheating software. Learn what the scandal involves, who is affected, and what it means for UK diesel car owners.
Capita’s data breach exposed pension holders’ personal data. Stay updated on the latest legal action, investigations, and regulatory responses.
Confused about Jaguar Land Rover DPF claims vs. Dieselgate? Learn the key differences, legal actions, and how to check if you qualify for compensation.

Latest news & insights

Did you know we have a newsletter?

Sign up for our newsletter to stay up to date.