In recent years, cybersecurity experts have continuously warned that critical industrial sectors could face catastrophic consequences if attacked by advanced ransomware or state-backed threat groups. Today, these warnings are no longer hypothetical scenarios but are increasingly playing out in reality—large industrial suppliers have seen production capacity stalled for weeks, and supply chains have been paralyzed.

The automotive industry, which relies heavily on IoT technology and wireless connectivity and is increasingly built on artificial intelligence, has recently experienced a series of the most destructive attacks.

"The reality of modern cyber threats, especially in critical infrastructure and manufacturing, requires a fundamental shift in mindset," said Paul Shaver, global practice lead for OT security at Mandiant, part of Google Cloud. "We can no longer treat this as a pure prevention game, but rather as disaster preparedness."

The global automotive industry has become a prime target for sophisticated attacks from various threat groups, noted Matt Brady, senior principal researcher at Palo Alto Networks Unit 42.

"The automotive industry is highly susceptible because it has an extremely low tolerance for downtime, and the consequences are extremely severe," Brady told Cybersecurity Dive, citing "immediate, long-term (weeks to months) production stoppages, staggering long-term financial losses, and even potential regulatory fines and credit rating downgrades."

In recent years, the automotive industry has experienced a series of attacks that disrupted critical supply chains.

In June 2024, an attack onCDK Globalcaused widespread disruption to its systems. The company provides management software to more than 15,000 dealerships in the U.S., and the incident affected sales, inventory, customer relationship management, and vehicle repair capabilities.

That same year, a report from Rockwell Automation showed that automakers ranked cyber risk as their top external concern.

"From a cybersecurity liability perspective, the digital elements commonly used in new mass-produced vehicles are not designed securely, lacking even basic security controls, which is concerning," said Chad Humphries, cybersecurity and networking solutions consultant at Rockwell Automation.

He added that OEMs' heavy focus on connected vehicle experiences exacerbates this risk.

In one of the final major cyber-related actions of the Biden administration,the U.S. Department of Commerceissued a final rule in January banning the sale of connected vehicles and related software and hardware from Russia and China. The government cited concerns about state-linked hacking groups like Volt Typhoon, which have been targeting critical infrastructure systems for disruptive attacks, as well as concerns about mass surveillance of customer data.

These automotive software restrictions will take effect starting with the 2027 model year, while hardware restrictions will begin with the 2030 model year.

The Trump administration is also closely monitoring security issues in the automotive industry, including the safety of critical systems such as steering and braking, as well as the growing software-defined features in modern vehicles.

"While these trends support important safety features and meet consumer demands, they also provide malicious actors with the potential to cause harm," said Peter Simshauser, chief legal counsel at the U.S. National Highway Traffic Safety Administration, during a keynote speech at the SeptemberAutomotive Information Sharing and Analysis Center meeting.

Meanwhile, a wave of cyber-related disruptions targeting automakers in recent weeks has raised questions about whether the industry is being specifically targeted by threat groups.

Critical industry

The Jaguar Land Rover (JLR) attack is a stark example of how a successful hack can have catastrophic downstream effects on third-party suppliers, regional economies, and even international supply chains.

According to the UK'sDepartment for Business and Trade, JLR employs more than 34,000 people in its home country and is considered one of the UK's largest exporters and employers. The company also has one of the largest supply chains in the UK automotive industry, involving more than 120,000 workers.

In fiscal year 2025, JLR reported annual revenue of $39 billion (£29 billion) and sold nearly 429,000 vehicles,according to the company's annual report

JLR did not specify how hackers gained access to its systems, but security researchers said the automaker had been dealing with significant cyber risk issues in the months before the attack. Like many modern automakers, JLR has undergone major technology upgrades in recent years to achieve smarter, faster, and more efficient production.

The company partnered with Tata Technologies in 2023 to provide end-to-end enterprise resource planning software and transform its logistics and supply chain. Under the agreement,SAP S4 HANA was integrated into the company's existing software

Researchers at Onapsis noted that the threat groupShinyHunters leaked exploit code related to an SAP vulnerability in August, which was used in a series of attacks this year; researchers at Sophospreviously told Cybersecurity Divethat a group linked to Scattered Spider, Lapsus$, and ShinyHunters claimed responsibility for the JLR attack.

In March,researchers at Hudson Rocksaid JLR was targeted using info-stealing malware. The incident was linked to a ransomware group called Hellcat.

Supply chain disruption

The JLR cyberattack had a direct impact on vehicle production, with the company warning last week that second-quarter retail sales fell 17% year-over-year to 85,495 units.

Wholesale volumes were even worse, down 24% year-over-year to 66,165 units in the quarter ending September 30.

A key JLR supplier told Cybersecurity Dive that once JLR was forced to halt production after the attack, the company continued producing from on-hand inventory until it was largely depleted.

"At first you can keep producing with inventory, but it doesn't last long," the supplier, who spoke on condition of anonymity, told Cybersecurity Dive. "So the longer it goes on, the harder it gets."

Vertu Motors plc, a leading UK automotive dealer with 191 locations, warned in its six-month earnings report that the JLR attack would have a$7.3 million (£5.5 million) impact on its fiscal 2026 earnings, depending on recovery time. Vertu, which has 10 locations selling JLR vehicles, said it plans to file claims under business interruption insurance covering third-party disruptions.

"We will provide shareholders with a clear update in the coming months on the impact of the cyberattack, as well as the potential benefits of any insurance claims," Vertu Motors CEO Robert Forrester told analysts on a conference call.

After visiting the company and key suppliers, the UK's Department for Business and Trade said in September it would support $2 billion (£1.5 billion) in loan guarantees to help restore JLR's supply chain. The company reportedly had been in talks with insurance broker Lockton but failed to secure cyber insurance before the attack,according to The Insurer

JLR took its first step toward full recovery last week, restarting two major operations in phases at its electric propulsion manufacturing center and battery assembly center in the West Midlands region of the UK. Other key facilities also restarted, including stamping operations, body and paint shops, and a logistics operations center that sends vehicle parts to other manufacturing sites.

However, analysts warned that recovery from such a significant cyberattack remains fraught with security risks, as hackers had long-term access to JLR systems.

"The most likely issue they're dealing with now is, how far can we recover before the bad guys were in our environment," said Mike Lipinski, partner at Plante Moran, an accounting, consulting, and wealth management firm that provides advisory services including risk management.

However, Moody's warned that the cyberattack could have a significant financial impact on JLR and downgraded the company's outlook to negative. The agency now forecasts JLR's fiscal 2026 revenue could fall 14% to less than £25 billion ($33.3 billion).

Bridgestone Americas cyberattack

Bridgestone Americas, the U.S. subsidiary of Japanese tire maker Bridgestone Corp., was targeted in another incident in early September. The attack causedproduction halts at multiple plantsin the U.S., Canada, and Latin America. The company operates more than 50 sites in the region and employs over 55,000 people.

The company said Thursday it had "successfully reconnected affected plants to the network." "We are actively working to return production at these plants to pre-incident levels," a spokesperson told Cybersecurity Dive.

The cyberattack forced Bridgestone to use imported goods to help fill backlogged orders,Bloomberg reported, and will impact the company's second half of the year.

CEO Shuichi Ishibashi spoke with Bloomberg last week about tariffs, the attack, and other issues. He told the outlet that Bridgestone Americas is closely monitoring production restarts to guard against any safety and security issues stemming from the cyberattack. Bridgestone plans to report earnings in November, and the company maintained its full-year guidance, according to Bloomberg.

Stellantis N.V. has also been affected in recent weeks by a cyber intrusion at a third-party customer service center supporting its North American operations. According to Sophos researchers, hackers linked to ShinyHunters claimed to have accessed more than 18 million records.

Stellantis said the intrusion was limited to exposure of customer contact data, with no sensitive financial data stolen.

UK prioritizes cyber resilience

The cyberattack on JLR, along with previous ransomware incidents targeting Marks & Spencer and the Coop Group, prompted UK authorities to take decisive action. The UK's National Cyber Security Centre (NCSC) on Tuesdaypublished its ninth annual assessment, showing a record 204 "nationally significant" cyberattacks, with 18 classified as "highly significant."

NCSC CEO Richard Horne warned during a Mondayreport presentationthat businesses must take responsibility for managing cyber risk at the highest corporate leadership levels. He said companies must also have plans to maintain operations.

"Every leader, whether you're one person at a kitchen table or the boss of thousands, must have a plan to defend against criminal cyberattacks," Horne said. "And... there must be a continuity plan."

Horne and other UK officials alsowrote to business CEOs, urging them to take direct action to make cyber resilience a board-level priority. At the SeptemberBillington Cybersecurity Summitin Washington, D.C., Horne had said that, given a series of high-profile disruptive attacks, UK authorities planned to place new emphasis on business resilience.