Date Range: 21st August to 4th September 2025
Here’s your round-up of the biggest breaches and security incidents reported in the last 14 days
Jaguar Land Rover halts global production after cyber incident
What happened: JLR proactively shut down IT systems following a cyberattack first detected on Sunday, forcing line stoppages and retail slowdowns. The company says there’s no evidence of customer data theft so far, but operations have been “severely disrupted.” Hackers linked to “Rey”/Scattered LAPSUS$ Hunters claimed responsibility.
Why it matters: A marquee UK manufacturer experiencing multi-day disruption shows how fast operational tech and core business apps can be knocked offline when attackers gain a foothold.
Salesloft “Drift” supply-chain breach hits security vendors (and many more)
What happened: A threat actor (UNC6395) abused OAuth/refresh tokens in Salesloft’s Drift app to access connected Salesforce environments. Zscaler and Palo Alto Networks disclosed limited data exposure (business contacts/support case details) but no impact to their products or infrastructure. Google’s Threat Intelligence team warned all Drift customers to treat tokens as potentially compromised; Salesforce disabled Drift integrations.
Primary disclosures & analysis: Zscaler CISO Sam Curry’s blog (Aug 30), Palo Alto Networks disclosure (Sept 2), and Dark Reading’s roundup (Sept 2).
Why it matters: Classic SaaS supply-chain blast radius—an upstream marketing tool becomes the attacker’s bridge into many downstream CRM instances.
TransUnion: 4M+ affected via third-party customer support app
What happened: The credit bureau confirmed a breach tied to a third-party application supporting US customer operations. Impacted data did not include credit reports; affected users get monitoring.
Why it matters: Even highly regulated data environments are only as strong as the SaaS and vendors surrounding them.
Farmers Insurance: ~1M customers impacted through vendor system
What happened: Breach notifications filed in the US indicate over 1 million customers were affected after a third-party database with customer information was accessed. Specific data elements weren’t disclosed publicly.
Why it matters: Another reminder that third-party risk continues to dominate the breach landscape.
Nevada (US) shuts state offices after cyberattack
What happened: A statewide cyber incident (first detected Aug 24) forced temporary closure of in-person services and shut down some state systems. Officials said there’s no evidence of PII compromise to date.
Why it matters: Rare state-level disruption underscores resilience gaps in public-sector IT and the growing operational fallout of government attacks.
Bridgestone Americas confirms cyberattack affecting plants
What happened: Bridgestone said a “limited” cyber incident disrupted some North American manufacturing facilities; local officials reported temporary suspension of operations in Québec. No data compromise has been confirmed as of reporting.
Why it matters: Manufacturing downtime from IT incidents continues to ripple across physical operations and supply chains.
Sweden: Municipal services disrupted after supplier ransomware
What happened: Ransomware at HR-systems provider Miljödata impacted ~200 municipalities and regions, knocking out key admin platforms and raising data-exposure concerns; ransom reportedly demanded.
Why it matters: Public-sector supplier compromise can cascade into hundreds of downstream entities at once.
Fast stats & trends
- August ransomware claims rose for a second month (473 → 506 incidents), per Comparitech’s roundup.
- Multiple incidents above stem from SaaS/Salesforce ecosystem abuse—rotate tokens, review app scopes, and audit logs where third-party integrations exist.
Sources
JLR statement; Reuters; The Guardian; Dark Reading (JLR, TransUnion, Farmers, Bridgestone, Nevada); Zscaler & Palo Alto Networks blogs; Salesforce/Salesloft actions referenced in Dark Reading.