Last updated 1 month ago
Jaguar Land Rover (JLR), a United Kingdom-based automotive manufacturer, experienced a cyberattack that compromised staff credentials, affecting all 30,000 employees. The incident was disclosed publicly in June 2026 during the Infosecurity Europe conference by former JLR CISO Ashish Shrestha. No specific discovery date was provided, and the number of records affected beyond the employee count was not disclosed.
The attack vector involved unauthorized access to employee credentials, though the initial access method was not specified. JLR responded by requiring all 30,000 employees to physically verify their identity in person before resetting passwords, indicating a credential compromise. No threat actor was attributed, and no specific CVEs or MITRE ATT&CK techniques beyond T1078 (Valid Accounts) were mentioned. The compromised data type was limited to employee credentials.
No post-incident details regarding regulatory notifications, litigation, ransom payments, or containment milestones were provided in the article.
Cyberattack compromising staff credentials
JLR's requirement for in-person password resets highlights the risk of credential compromise and the need for robust identity verification processes. The incident underscores the importance of multi-factor authentication and continuous monitoring for credential misuse, particularly in large organizations with extensive employee access. The lack of disclosed attack vector suggests that organizations should prioritize employee security awareness and implement controls to detect and respond to credential-based attacks promptly.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Continent
Country
Industry
Attack Vector
MITRE ATT&CK