Jaguar Land Rover (JLR) has had a great deal of press lately. Unfortunately, it has not been due to their business strategy “about the electrification of Range Rover, Defender, and Discovery, and the renaissance of Jaguar as an all-electric brand from 2025” or their sales of “Luxury SUVs and 4x4s”.
After M&S, Co-op and Harrods earlier this year, JLR were the next British company (owned by Tata, sure, but still considered to be British) to be victims of a cyber attack with a total cost estimated at £1.9Bn and impacts that halted production for five weeks, affecting 5,000 other businesses in their supply chain.
What happened
Initially, JLR did not publicly divulge the details regarding what type of cyber attack occurred other than that customer details were not the focus.
More recently, it is understood that the incident might relate to a separate ransomware attack carried out earlier in the year on JLR by a group known as ‘HELLCAT’. The group used ‘Infostealer’, a type of malware that is a known hallmark of HELLCAT’s operations. Infostealer exfiltrated hundreds of documents, source code and compromised employee and partner data through stolen Jira credentials. Jira is a project management and issue tracking software by Atlassian that helps teams plan, organise, and track their work. The stolen credentials allowed persistent remote access into JLR’s systems.
Scale of the impact
With these impacts, it is understandable why this is likely to be the most economically damaging cyber event in UK history. To add an additional ‘sting’, the attack coincided with the date for which new registration plates were issued, increasing financial losses as JLR dealers were unable to register and deliver new vehicles.
Supply chain vulnerabilities
At Nexor, our Information Assurance and Cyber Risk consultants understand that no matter what the business or operation, the size of a company or organisation, with the best security that could possibly be implemented, third parties are a vulnerability. For JLR, a supply chain vulnerability was exploited via Jira.
But it is interesting that this particular case demonstrates the multidirectional ‘ripple’ effect of risk and how it can evolve into other impacts: Suppliers, 5,000 businesses for example, can also be vulnerable from their customers.
Nexor’s perspective on assurance
Through their delivery of Supply Chain Assurance services, Nexor’s experience of the companies, businesses and organisations that get this right, understand that when it comes to suppliers and vendors, engaging as far as the necessary tier to identify critical assets, vulnerabilities and allow expansion of risk management across all parties is a step closer in achieving end to end security.