
How Cyberattacks Shut Down Factories Without Touching a Single Machine
Part of our guide to OT security
Jaguar Land Rover lost roughly five weeks of production and an estimated £1.9 billion, and the attackers never touched a machine on the factory floor. Here is why that has become the pattern in industrial cybersecurity.

At the end of August 2025, managers at a Jaguar Land Rover plant in Halewood noticed systems behaving strangely. Within a day, JLR's own IT teams found an intrusion in the network and made the call to shut their systems down on purpose, to contain it. The assembly lines stopped. They stayed stopped for roughly five weeks, not only at Solihull, Halewood, and Wolverhampton, but at plants in Slovakia, Brazil, and India. Staff were told to stay home. UK car production fell by more than a quarter that September. The total damage has been estimated at around £1.9 billion, which makes it the most costly cyberattack in British history.
Here is the part that should stay with anyone responsible for an industrial environment. No one reached a controller. There was no exotic industrial malware, no zero-day, no manipulated PLC. JLR has not published a full technical account, but security researchers and the attackers' own claims point to something far more mundane: stolen credentials obtained through phone-based social engineering, normal logins through normal authentication, weak segmentation, and detection that arrived too late. The machines were never the target, and they were never harmed. The company shut itself down anyway, because once it could no longer trust the systems it runs the business on, continuing was the greater risk.
This is what an OT attack looks like now
The image most people carry of an attack on operational technology is sabotage. Malware reaches into a controller and pushes a turbine past its limits, or trips a breaker in a substation. That category is real, and a short list of purpose-built tools like Stuxnet, Triton, and FrostyGoop proves it is possible. It is also rare, expensive to develop, and not the threat most industrial organizations will ever meet.
The threat they meet looks like JLR, and it is everywhere. In 2025, Dragos tracked 119 ransomware groups targeting industrial organizations, affecting roughly 3,300 of them, with manufacturing making up more than two-thirds of the victims. Almost none of those incidents required ICS-specific malware. They were ordinary break-ins into the ordinary systems that surround the process: engineering workstations, file servers, identity providers, scheduling tools, and remote-access gateways. Production stopped regardless.

Industrial security has precise language for the underlying failure. Loss of view is the point at which defenders can no longer trust what their instruments tell them about the process. Loss of control is the point at which they can no longer reliably act on it. An attacker does not have to cause either one outright. Often the suspicion that a supporting system has been compromised is enough, because no responsible operator keeps a process running when they can no longer see it clearly.
Operators run the plant through a screen. So do the attackers.
Walk into a control room and you notice something quickly. The people running the plant cannot see the plant. They see displays. Pressures, temperatures, flows, tank levels, and valve states arrive as numbers and trends, fed by sensors, historians and controllers scattered across the site. Operators act on those readings the way a driver acts on a speedometer, because acting on anything else is not possible. That trust in the view is the foundation of safe operations, and it is the single most valuable thing an attacker can take.
It is also, quietly, the thing an attacker relies on too. During an intrusion, the adversary is doing the same job the operator does. They are learning the plant through their view of it, reading the same kinds of systems, following the same paths, and building a mental model from what those systems show them.
Why catching this early is so hard
So the defender's task is to spot an intruder before trust breaks. In an industrial setting, that is genuinely difficult.
You cannot disrupt the process to investigate. Aggressive scanning and automated isolation can be as dangerous to a fragile, time-sensitive system as the attack itself, so availability and safety constrain what a defender is even allowed to do.
Normal traffic often looks abnormal. Industrial protocols, vendor-specific communication, and infrequent maintenance are hard to baseline, so tools that flag the unusual end up flagging routine work.
The assets fight back. Many were installed before modern security existed, and they offer thin logging, weak authentication, and no room for an endpoint agent.
Remote access is a trusted front door. Vendors, integrators, and engineers all need legitimate ways into sensitive zones. An attacker who steals one of those accounts arrives looking authorized and, at first, behaves exactly like the person whose credentials they took. That is precisely how JLR's attackers walked in.
Stack those constraints together and you get a steady stream of maybes that teams eventually learn to ignore. An odd connection might be an intruder, or an engineer doing maintenance. A new device might be a foothold, or a planned expansion. At Halewood, something looked off for days before anyone was sure. The hardest signals to act on are the early ones.
The reconnaissance is the attack
The intruders who do the most damage exploit all of this by moving slowly. Before touching anything important, a careful attacker studies the environment. They learn system names, watch communication patterns, work out which workstation an engineer uses, map how the zones connect, and locate the systems that matter most.
Dragos flagged this shift directly in 2025. Groups have moved beyond simply gaining a foothold and waiting. They are now mapping the control loops themselves, which signals a growing willingness to use that access for disruption rather than just hold it. Reconnaissance is the most important phase of the attack, and it is also the phase that looks the most like ordinary work.
Shape what the attacker sees
That dependence on the view is an opening.
If an intruder's understanding of your plant comes from the systems they explore, then the systems they explore can shape what they understand. You can present a version of the environment that behaves like the real one, that an attacker cannot easily tell apart from production, and that no legitimate worker ever has a reason to enter. Anyone who interacts with it has gone somewhere they should not be. The uncertainty that defines OT detection, the endless maybe, collapses into a clear signal.
This is the idea behind MirrorMire. Neural Echoes are the lures and breadcrumbs an attacker expects to find as they move, the traces of credentials, systems, and paths that lead them onward. Synthetic Cognitive Agents are the high-interaction systems those trails lead to, realistic enough to engage with and built to keep an intruder occupied while their reconnaissance, credential use, and lateral movement are captured as evidence. Our AMazeTM platform places this synthetic world along the routes attackers actually take after entry, the remote-access zones, the engineering networks, and the IT/OT boundary, while staying completely separate from the physical process.

The window was open for days
OT defense has spent years trying to keep attackers from reaching the process, and that work matters. But the lesson of JLR, and of most industrial incidents in 2025, is that attackers rarely need to reach the physical plant to halt it. They need to get inside, learn the environment, and pick their moment. The days when systems were quietly acting strange were the window. That is when an intruder is most exposed and least certain, and it is the best chance a defender will get.
Give an attacker a picture worth chasing, and the moment they start to look becomes the moment you see them.



