According to sources close to the investigation, Russian hackers were involved in a cyber attack last year that hit Jaguar. This incident cut off the British car manufacturer for months and affected British manufacturing and employment.

According to reports, the British Government subsequently provided £1.5 billion, or approximately $2 billion, in support of the company. The damage to the British economy as a result of the attack was estimated at approximately $2.5 billion.

The investigation points to Russian hackers.

According to The New York Times, the investigation now points the attackers to Russia, but it is not clear whether their identity is under the direct command of the Russian Government or an independent criminal group, or whether they are in the middle of a hacker group that is acting with acquiescence.

This judgement put an end to speculation that had lasted for months, but the report did not give a clearer official profile. At this stage, the specific relationship between the attackers and the Russian Government has still not been made public.

Multi-agency involvement in tracking

It was mentioned that Microsoft had tracked down this Russian hacker organization and informed Jaguar Rover about the identity of the attackers. In addition to Microsoft, several United States and British law enforcement and cyber security agencies were involved in the investigation.

  • FBI. FBI.
  • British National Bureau of Crime Investigation NCA
  • NCSC British National Cybersecurity Centre

In addition, Mandiant and Palo Alto Networks, under the banner of Google, were also cited as involved in related investigations and evidence-gathering, indicating that the case was considered a major cyber-security incident in cross-agency collaboration.

There's more than one attacker.

It was also reported that Russian hackers were not the only attackers who had entered the network. The investigation found that a Jordanian hacker using the alias “Rey” also invaded part of the Jaguar Rover network.

In cybersecurity incidents, it is not uncommon, but not without precedent, for multiple attackers to enter the same target network at the same time or again. This also means that the attribution of events and the assessment of losses may be more complex than the original determination.