Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
CarCodyAdvertise
Service recordThe Garage

Jaguar Land Rover Source-Code Exposure Claims: What Hackers Alleged and What Is Confirmed

Threat actors claimed to have stolen Jaguar Land Rover source code and other internal data, but JLR has not confirmed that its entire repository was published. Here is what researchers reported, what JLR confirmed about the 2025 production shutdown, and what remains unknown about attribution.
Entry750 Date Time10 min MechanicCarCody Team
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Jaguar Land Rover’s source code was not conclusively shown to have been published in full. Hellcat claimed to have stolen 44 GB of JLR data, including source code, while CYFIRMA reported alleged files containing development material and employee records. JLR separately confirmed a serious cyber incident that shut down global systems and disrupted manufacturing and retail operations in September 2025. The evidence does not yet prove that the alleged source-code exposure and the later production attack were the same event.

There is no public proof that all of Jaguar Land Rover’s source code was published. In early 2025, the Hellcat group claimed it had stolen 44 GB of JLR data, including source code and development tools. Cybersecurity researchers at CYFIRMA later described alleged files containing development logs, tracking information, source code and employee records, while another actor called APTS claimed access to an additional tranche of about 350 GB.

Those are threat-actor claims and researcher reports—not a complete public confirmation by JLR. Separately, JLR confirmed that a serious cyber incident in September 2025 forced it to shut down global systems and severely disrupted manufacturing and retail operations. The public record still does not establish whether the alleged source-code exposure and the later production shutdown were one campaign, separate intrusions or multiple actors using overlapping access.

What is alleged, and what is confirmed?

Question Most defensible answer
Was JLR’s entire source-code repository published? No. Threat actors claimed to have obtained and leaked source code, but JLR has not publicly confirmed the completeness, authenticity or full contents of the material.
What did researchers say was in the alleged files? Development logs, tracking information, source code and employee records, including usernames, email addresses, display names and time zones. Other reporting referred to contracts and development tools.
Did JLR confirm a major cyber incident? Yes. JLR confirmed a serious incident on 2 September 2025, a shutdown of global systems and severe disruption to manufacturing and retail activities.
Were vehicle safety systems compromised? There is no public evidence in the reporting covered here that safety-critical vehicle control software was compromised or released.
Was Russia officially confirmed as responsible? No. June 2026 reporting attributed the production-disrupting attack to Russian hackers based on people close to the investigation, but that attribution remains reported rather than an uncontested official conclusion.

What the alleged JLR leak contained

In early 2025, Hellcat claimed responsibility for a JLR breach and said it had taken 44 GB of sensitive data. SecurityWeek reported that the claimed material included contracts, documents, development tools and source code. At that stage, JLR had not publicly confirmed the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
I3C Laptop Cable Lock, Hardware Security Cable Lock with Keys, Anti Theft Combination Lock Compatible with Laptop Monitor Tablet Surface Projector and Other Electronic Devices (1 Pack)
  • 🎁FIT FOR ALL THE TABLETS: 🎁With an anchor plate, The Hardware cable lock fits for Mac Book and all the Tablets, Smart Phones, such as for iPad, Microsoft Surface, Kindle, Samsung, Android Tablets and phones, etc
  • 🎁FIT FOR MOST THE LAPTOPS: 🎁With standard lock, the security cable lock also fits for most laptops that have Standard slots.
  • 🎁HOW TO USE: 🎁For Tablets/Laptops without standard lock slot: Bound the anchor plate, which is lined with strong adhesive, to the hard surface of the devices, then insert the locking head into the plate with keys and loop the cable around a fixed object. FOR LAPTOPS WITH LOCK SLOT, just simply insert the lock head into the slot, and loop the cable around a fixed object
  • 🎁ANTI THEFT: 🎁The lock head is made of super-strong stainless steel, can be rotated in 360 degrees. The cable is made of cut-resistant twisted steel with a PVC coat, the extra length of 6.5ft fully meets your daily demands
  • 🎁MODEL TIPS-- 🎁There are some Models need to be used with I3C Adhesive Security Plate, if you mind using I3C anchor plate, please buy it berofe thinking twice

In March 2025, CYFIRMA reported a second set of claims involving an actor known as APTS. According to CYFIRMA’s account, APTS said it had obtained access using credentials compromised by an infostealer and associated with third-party access to a JLR Jira server. APTS claimed that a further tranche of approximately 350 GB had been exposed.

CYFIRMA described the alleged Hellcat-related material as including:

  • development logs;
  • tracking information;
  • source code;
  • employee records containing usernames, email addresses, display names and time zones.

The available reporting supports describing these as alleged exposed categories. It does not support saying that all JLR source code, vehicle firmware, electronic control-unit software or safety-critical control systems were publicly released.

Why source-code exposure would matter

Source code is not one single type of automotive data. It can belong to internal development tools, websites, business applications, cloud services, testing systems or vehicle-related software. A claim that source code was stolen therefore does not, by itself, show that the code running a vehicle’s brakes, steering or other safety-critical systems was obtained.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the reported files were authentic, they could still create serious risks:

  • Intellectual-property loss: competitors or criminals could study proprietary development methods and tools.
  • Security reconnaissance: exposed code and development logs may reveal system names, interfaces, dependencies or weaknesses that make later attacks easier.
  • Credential and secret exposure: configuration files, tokens or accidentally embedded secrets can provide additional access if they were present and remained valid.
  • Targeted phishing: employee names, addresses, job information and time zones can make convincing messages easier to create.
  • Supplier risk: information about development or tracking systems could help attackers target contractors and other connected organizations.

These are consequences that could follow if the material is genuine and useful to attackers. They are risk assessments, not evidence that a particular JLR vehicle system was compromised.

Rank #2
Bitdefender Total Security 2026 – Complete Antivirus and Internet Security Suite – 5 Devices | 1 Year Subscription | PC/Mac | Activation Code by Mail
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
  • SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
  • ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
  • ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.

What Jaguar Land Rover officially confirmed

JLR’s public statements establish a separate and much more concrete part of the story. On 2 September 2025, the company said that a cyber incident had severely disrupted its manufacturing and retail activities. Its initial response was to shut down all global systems.

JLR said it was working with third-party specialists, the UK National Cyber Security Centre and law-enforcement agencies. The NCSC confirmed on 5 September that it was supporting JLR, but did not publicly identify the threat actor, initial access method or data involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

JLR’s statements confirmed the operational impact. They did not publicly validate every screenshot, file set or data category claimed by criminal groups and researchers.

JLR cyber-incident timeline

  1. Early 2025: Hellcat claimed to have stolen 44 GB of JLR data, including contracts, documents, development tools and source code. JLR had not confirmed the claim at the time.
  2. March 2025: CYFIRMA reported APTS claims involving third-party access to a JLR Jira server through infostealer-compromised credentials and an alleged additional leak of roughly 350 GB.
  3. 2 September 2025: JLR disclosed a cyber incident that severely disrupted manufacturing and retail operations and said it had shut down global systems.
  4. 5 September 2025: The NCSC confirmed that it was working with JLR, without publicly naming an attacker or explaining the intrusion route.
  5. 19 September 2025: The UK government and the Society of Motor Manufacturers and Traders said the incident was significantly affecting JLR and the wider automotive supply chain.
  6. 23 September 2025: JLR said production lines would remain halted until at least 1 October, according to Associated Press reporting.
  7. 28 September 2025: The UK government announced a guarantee expected to unlock up to £1.5 billion in commercial finance for JLR’s supply chain.
  8. 29 September 2025: JLR said a controlled, phased restart was under way, with some manufacturing operations expected to resume in the following days.
  9. 14 November 2025: JLR reported that production had returned to normal levels, although the incident had materially affected financial performance.
  10. 2 April 2026: JLR reported that fourth-quarter wholesale volumes had risen 61.1% quarter on quarter as production recovered, while full-year wholesale volumes were down 23.2% year on year.
  11. 26 June 2026: TechCrunch, summarizing New York Times reporting, said people close to the investigation had linked the major production-disrupting attack to Russian hackers. The same reporting described a separate intrusion by a Jordanian hacker using the name Rey.

The operational impact was real, even though the leak claims remain unverified

The distinction between the alleged data leak and the confirmed disruption matters, but it should not minimize the seriousness of the incident. JLR’s global-systems shutdown affected factories, retail operations and the flow of work through the automotive supply chain.

The UK government said JLR employed about 34,000 people directly in UK operations and that its supply chain employed approximately 120,000 people. The government’s 28 September guarantee was expected to unlock up to £1.5 billion in commercial finance to help suppliers manage the disruption. That support illustrates how a cyber incident at a major vehicle manufacturer can become a liquidity and production problem for companies that may never have been directly breached.

The Cyber Monitoring Centre estimated that the incident and its supply-chain fallout could cost the UK economy approximately £1.9 billion, or about $2.5 billion, and affect more than 5,000 organizations. That is an economic-impact estimate—not an audited statement of JLR’s direct loss and not a final confirmed cost.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Kensington Combination Cable T-Bar Standard Lock Slot for Laptops, Resettable 4 digit password with 6 Foot Cable, K64673AM
  • Computer lock for HP, Lenovo, Acer, Asus and other brands; not compatible with Dell or Alienware (see part # K68008WW)
  • Resettable 4-wheel Number code with 10, 000 possible combinations. Push-button design for one-handed engagement to easily attach lock
  • 6’ long carbon steel cable is cut-resistant and anchors to desks, tables, or any fixed structure
  • Attaches to laptops, desktops, TVs, monitors, hard drives, docking stations, projectors or any other device featuring a Kensington standard size security slot
  • Independently verified and tested for industry-leading standards in torque/pull, foreign implements, lock lifecycle, corrosion, key strength and other environmental condition

JLR’s 2 April 2026 results provide a clearer official measure of the recovery:

  • fourth-quarter FY26 wholesale volumes reached 95,300 vehicles;
  • that was a 61.1% increase from the previous quarter as production returned to normal;
  • full-year FY26 wholesale volumes were 307,900, down 23.2% year on year;
  • full-year retail sales fell 17.8%.

JLR said the full-year results reflected production stoppages following the cyber incident among other factors, including tariffs, challenges in China and the planned wind-down of legacy Jaguar models. The figures therefore should not be treated as the cyber incident’s isolated financial cost.

Who was behind the attacks?

The public record does not identify one confirmed perpetrator for every part of the story.

The early data-exposure claims were associated with Hellcat and later APTS. A separate English-speaking collective linked in reporting to the Marks & Spencer attack also claimed responsibility for the September 2025 operational incident and posted screenshots that it said came from JLR’s internal systems. Reporting cautioned that criminal groups can exaggerate their claims, and JLR had not confirmed the provenance of every screenshot.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The June 2026 reporting added a new attribution claim. TechCrunch, summarizing New York Times reporting, said investigators had linked the production-disrupting attack to Russian hackers. The reporting left open whether those hackers acted for the Russian government, independently or with tacit state approval. It also described a separate intrusion by a Jordanian hacker who used the name Rey.

That combination of reporting points to a potentially more complicated picture: the source-code claims and the destructive production attack may have involved different actors or separate access events. Nothing in the public record covered here conclusively connects Hellcat, APTS, the English-speaking collective, the reported Russian hackers and Rey into one chain of responsibility.

Rank #4
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

What remains unknown

  • Authenticity: JLR has not publicly confirmed the full contents, authenticity or completeness of the files claimed by Hellcat or APTS.
  • Scope: It is unknown whether the alleged source code belonged to business systems, development tools, vehicle software or a mixture of environments.
  • Initial access: No public official statement identified the exact entry point for the September operational attack.
  • Connection between events: The public record does not establish whether the early leak claims and September shutdown were one coordinated campaign, separate intrusions or multiple actors exploiting overlapping access.
  • Attribution: The Russian attribution comes through investigative reporting and has not been upgraded here to an independently verified official conclusion.
  • Financial loss: The £1.9 billion figure is an estimated UK-wide economic impact, not JLR’s exact direct loss.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this means for JLR owners and car shoppers

For vehicle owners, the most important point is that there is no evidence in the available reporting that the alleged source-code material included safety-critical vehicle control software or that the incident created a confirmed vehicle-safety defect.

There is also no sound basis for downloading alleged leaked files or treating posts from criminal groups as service information. Such files may be malicious, altered or used to distribute malware. Owners should use JLR’s official customer, dealer and recall channels for vehicle notices rather than relying on breach-related social-media claims.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The more plausible consumer-facing risk from the reported employee data is targeted phishing. Be cautious of unexpected messages that use a JLR or supplier employee’s name, request credentials, ask for payment changes or direct you to an unfamiliar document or login page. The reported data does not prove that every affected person will be targeted, but it explains why impersonation attempts could become more convincing.

Lessons for manufacturers and suppliers

The JLR case shows why automotive cyber resilience cannot be measured only by whether a company eventually restores production. A useful review should examine both data-protection controls and the ability to operate when corporate systems are unavailable.

  • Separate development, corporate, supplier and manufacturing environments so that access to one does not automatically expose the others.
  • Use strong controls for third-party access, including phishing-resistant multifactor authentication where practical, least privilege and prompt revocation of dormant accounts.
  • Monitor infostealer exposure and credential reuse, especially for accounts connected to Jira, source-code repositories and remote administration tools.
  • Keep tested offline or otherwise isolated recovery copies of essential configurations and operational data.
  • Define manual fallback procedures for production, logistics, dealer operations and supplier communications.
  • Test restoration in phases, because bringing systems back too quickly can reintroduce compromised accounts or dependencies.
  • Prepare a communications plan for employees, dealers, suppliers, regulators and customers before an incident occurs.

For organizations with factory or supplier exposure, an enterprise incident-response planning review can test decision-making, communications and recovery priorities before a crisis. An industrial OT security assessment can separately examine segmentation, monitoring and restoration around manufacturing networks. Neither service proves what happened at JLR, and no named provider should be inferred from JLR’s statement that it used third-party specialists.

Bottom line

Hackers and researchers said JLR data—including source code—was exposed in 2025, but the public evidence does not establish that the company’s entire source-code repository was published or that vehicle safety systems were compromised. What JLR did confirm was a severe cyber incident that shut down global systems and disrupted production and retail operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Kensington Combination Laptop Lock for Nano Size Security Slot, Resettable 4-Digit Combination Lock (K60214WW)
  • 5-Foot (1.5m) Carbon Steel Cable - Resists cutting attempts and provides ample length for easily anchoring your laptop to desks, tables, and other attachment points. Incorporates anti-shearing plastic sleeve to protect surfaces
  • Slim Lock Head - Designed to support thin laptops using nano sized lock slots (see images for sizing), lock secures while allowing your device to lie flat and stable
  • Resettable 4-Wheel Number Code - Set or reset your personal number code from 10,000 possible combinations
  • Pivoting Head and Rotating Anchor - The lock tip rotates 360º and the cable rotates up to 90º—allowing access to the ports near the lock slot on most devices and providing a convenient locking and unlocking experience

The later reporting about Russian hackers and a separate Jordanian actor makes a single, simple explanation less certain, not more. The central unresolved question is whether the alleged source-code exposure and the production-disrupting attack were connected.

Frequently Asked Questions

Did hackers publish all of Jaguar Land Rover’s source code?

No. Hellcat and APTS claimed to have obtained and leaked JLR data, and CYFIRMA reported seeing or analyzing alleged files. JLR has not publicly confirmed the completeness, authenticity or full contents of those files.

Was JLR vehicle-safety software compromised?

There is no public evidence in the reporting covered here that safety-critical vehicle control software or vehicle firmware was compromised or released. The alleged source code could have come from development tools, business applications or other internal systems.

Who attacked Jaguar Land Rover?

The 2025 data-leak claims were associated with Hellcat and APTS, while other reporting linked a separate English-speaking collective to claims about the September incident. June 2026 reporting attributed the production-disrupting attack to Russian hackers and described a separate intrusion by a Jordanian hacker called Rey. No single attribution has been publicly established for every event.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How much did the JLR cyberattack cost?

The Cyber Monitoring Centre estimated that the incident and its supply-chain effects could cost the UK economy about £1.9 billion, or approximately $2.5 billion. That is an economic-impact estimate, not JLR’s exact direct financial loss.

The Bottom Line

Bottom line: JLR source-code exposure was claimed by threat actors and analyzed in alleged leak reports, but it was not publicly confirmed as a complete repository release. The confirmed event was a major September 2025 cyber incident that disrupted JLR’s global systems, factories, retail operations and supply chain. The actors and relationship between the alleged leak and operational attack remain unresolved.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More from the Garage

  1. Entry001Date09 OCT 26Time3 minWhich Brake Pad Should You Buy From RockAuto or Elsewhere?Section: Blog
  2. Entry002Date09 OCT 26Time5 minThe Pros and Cons of Touchless Car Wash SystemsSection: Blog
  3. Entry003Date09 OCT 26Time3 minCan a Trickle Charger or Battery Tender Properly Charge a Car Battery?Section: Blog

Thanks for visiting Carcody

Carcody.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to amazon.co

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.