Russian cyber-criminals were behind the devastating cyber-attack on Jaguar Land Rover (JLR) last year that halted production for months, triggered a £1.5 billion government bailout, and cost the UK economy an estimated $2.5 billion, according to a new report.
The Kremlin Connection Under Investigation
While speculation has swirled for months regarding the perpetrators, The New York Times reports that intelligence points directly to Russian hackers. Investigators are still determining whether the group operated under direct orders from Vladimir Putin’s government, acted as independent cyber-criminals, or functioned within a grey area, operating with the Kremlin’s tacit approval.
A Global Coalition Unmasks the Threat
The breakthrough in identifying the attackers came after Microsoft tracked the Russian hacking group and alerted JLR to their identities. The investigation quickly escalated into a massive collaborative effort, drawing in resources from the FBI, Britain’s National Crime Agency (NCA), the National Cyber Security Centre (NCSC), Google’s Mandiant forensics unit, and Palo Alto Networks.
A Double Breach: The Jordanian Connection
In a rare turn of events for high-profile cybersecurity breaches, investigators discovered that the Russian group was not the only entity inside JLR’s systems. A Jordanian hacker operating under the alias “Rey” had also independently breached some of the automotive giant’s networks, adding another layer of complexity to the massive security failure.
