A cyberattack on Britain's biggest carmaker forced JLR to shut down its global IT network and halted vehicle production in the UK, China, Slovakia, India, and Brazil for five weeks β now considered the most economically damaging cyber incident in UK history.
- Victim
- Jaguar Land Rover
- Loss
- $2.40B
LockBit ransomware disrupted the U.S. broker-dealer arm of the world's largest bank, ICBC, jamming settlement of over $9 billion in U.S. Treasury trades. Bank staff sent critical settlement details by USB stick via a messenger across Manhattan. $62 billion of Treasuries failed to deliver in one day.
- Victim
- ICBC Financial Services (U.S. broker-dealer of Industrial and Commercial Bank of China)
- Loss
- $9.00B
China-based Storm-0558 forged authentication tokens using a stolen Microsoft consumer signing key and read email at approximately 25 organisations β including the US State Department, the Department of Commerce, and the U.S. Ambassador to China. The 'cascade of errors' that enabled it became a defining case for cloud-provider key custody.
- Victim
- Microsoft customers (US State Department, Department of Commerce, ~25 organisations)
A ransomware attack paralysed weaving-machine manufacturer Picanol's plants in Ieper (Belgium), Romania, and China, halting production for ~2,300 employees for over a week. Trading in Picanol shares was suspended during the disruption.
- Victim
- Picanol Group
A North Korean ransomware worm that exploited the EternalBlue SMB vulnerability to spread to ~200,000 systems across 150 countries in 24 hours. Paralysed the U.K.'s NHS and crippled manufacturing globally.
- Victim
- ~200,000 organizations worldwide (UK NHS, TelefΓ³nica, Renault, Deutsche Bahn, Honda et al.)
- Loss
- $6.00B