For years the standard cyberattack cost you your data. In September 2025 it cost you your output. The month's defining story had no leaked database at its centre — it had an empty car park. Jaguar Land Rover, hit by a cyberattack at the start of September, halted vehicle production across its plants and kept it halted for weeks, an outage later reckoned among the most expensive in British corporate history, bleeding an estimated tens of millions of pounds a day and rippling out through a supplier network that builds nothing when JLR builds nothing. Britain's business pages ran the unfamiliar spectacle of a cyber incident measured not in records exposed but in cars not made.
The lesson landed harder because it was physical. A stolen dataset is an abstraction most people file next to "terms and conditions." A famous factory standing dark, thousands of workers idled, a supply chain of small firms staring at cash-flow ruin through no fault of their own — that is a cyberattack the whole economy can see. September was the month the boardroom finally understood that operational resilience and cybersecurity are the same budget line, because the thing being protected was no longer information. It was the ability to function.
And if JLR proved a factory could be stopped, the airports proved a whole continent's travel could be — through a company most travellers had never heard of.
One vendor, a continent of queues
On the weekend of September 20, a cyberattack on Collins Aerospace — which supplies the check-in and boarding software behind the scenes at airports worldwide — forced Heathrow, Brussels, Berlin, and others to revert to manual check-in. Handwritten boarding passes, snaking queues, cancelled and delayed flights across Europe, all from a single compromised supplier that passengers had never chosen and couldn't name. It was the JLR lesson rewritten for aviation: in a networked economy, your resilience is only as strong as the least-defended vendor in your critical path.
Shai-Hulud eats the supply chain
Mid-September brought a genuinely novel menace: Shai-Hulud, a self-propagating worm loose in the npm ecosystem that JavaScript developers everywhere depend on. It didn't just poison packages — it harvested secrets from CI/CD pipelines, cloud metadata, and developer environments, then used the stolen credentials to publish itself into still more packages, infecting scores of them including some from major security vendors. CISA issued an alert. A self-replicating supply-chain worm was the nightmare researchers had war-gamed for a decade; September made it a headline, and a preview of the AI-toolchain compromises to come.
The dependency lesson, read from Mumbai
India watched September's carnage with unusual stake in the outcome — because India builds much of the software and staffs much of the back office that the JLRs and Collins Aerospaces of the world run on. The Shai-Hulud worm's harvest of developer secrets was an especially pointed warning for a nation whose IT and GCC sector lives in exactly those CI/CD pipelines; a poisoned dependency in a Bengaluru build server is a poisoned dependency in a hundred foreign products. For Indian IT leaders, the month reframed supply-chain security from a client's compliance checkbox into an existential feature of the national export product: trust.
⏳ Time capsule — September 2025
- "Cyberattack" made the front page of general-interest newspapers for weeks — not over stolen data, but over cars and flights.
- Scattered Spider and its affiliates remained the year's most-feared names in retail and enterprise intrusion.
- Business-interruption insurance quietly became the most-discussed line in cyber policies.
- The npm worm's Dune-derived name — Shai-Hulud, "the great maker" — gave security Twitter its meme of the month.
The physical turn
September 2025 was the hinge where cyber risk became visibly, expensively physical — and the theme never left. JLR's stopped lines became the reference case every board now cites when approving operational-resilience budgets; the Collins Aerospace weekend made "concentration risk in critical vendors" a phrase regulators started using in earnest. And Shai-Hulud was simply the overture: the supply-chain worm matured, through 2026's npm incidents and into the AI-toolchain compromises of the following summer, into the defining attack class of the era. When our current editions write about factories, airports, and poisoned dependencies, they are writing the sequel to this month.