JLR CISO Required In-Person Password Reset After September 2025 Cyber-Attack (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Over 30,000 JLR employees required in-person password reset after cyber-attack.
- CISO aimed to ensure Microsoft 365 environment and user identity integrity.
- Scattered Spider-attributed attack caused estimated £1.9B damage.
"At Infosecurity Europe, former Jaguar Land Rover CISO Ashish Shrestha explained why he mandated in-person password resets for over 30,000 employees after the September 2025 cyber-attack. The goal was to verify user identities and rule out Microsoft 365 compromise. The attack, attributed to Scattered Spider, caused an estimated £1.9 billion in damages and affected over 5,000 supply chain organizations."
no comments yet.