What’s in a Norm?

July 6, 2026

What’s in a norm? The New York Times’s recent reporting linked last year’s cyber attack on Jaguar Land Rover to Russia-based actors, but the UK government has remained silent. IST’s Nicholas Leiserson calls on policymakers to act lest their silence encourage future attacks.
Abstract anonymous blur of a suited office worker passing a street sign indicating prominent addresses of Parliament Street and Whitehall in the UK civil service district of Westminster.

It’s time for His Majesty’s Government to speak up following revelations about the devastating JLR hack last year

Last week, The New York Times published a fascinating “whodunit” story on last August’s massive intrusion into Jaguar Land Rover (JLR), a UK-based subsidiary of the Tata Group. According to conventional wisdom, the hack had been carried out by a loose collective of financially-motivated criminals, some of whom were based in the UK. But as Adam Goldman, Jane Bradley, Dustin Volz, and Michael Schwirtz write, that conclusion was incorrect. They instead trace the disruptive hack to cyber operators from Russia, which caused $2.5 billion in damage to the UK economy and prompted an unprecedented government bailout of the automaker.

The Times’s story has not been confirmed by JLR, cyber forensics teams, or the governments of the UK or Russia. Nonetheless, it provides a plausible explanation for several of the more head-scratching elements of the JLR affair. Consider the following facts of the case: 

  • Lack of a ransom note – There was never any mention in public reporting of a ransom demand. Given the devastation wrought to the entire UK economy, a financially-motivated threat actor would likely have taken advantage of the press coverage to increase the pressure on JLR to pay and stop the harm from continuing to ripple across the UK manufacturing base. By contrast, a nation-state-affiliated actor focused on sabotage has none of these incentives.
  • Opacity about the incident itself – Compared to other very high-profile cyber incidents, the public knows very little about the mechanism of the JLR hack. How did the threat actors get in? Was it really through Tata Consultancy Services, as rumored last September? What did the hackers deploy, and where? Why was it so successful? Ten months into WannaCry, NotPetya, SolarWinds, and even the “Salt Typhoon” telecommunications breaches, the public already had many of the answers to these questions. This opacity signals that the public and private incident responders involved in responding to this particular case operated with a high level of operational security, which is more characteristic of classified conversations about nation-states than law enforcement conversations about cyber criminals.

These factors, combined with The Times’s track record on reporting significant cyber incidents, have certainly prompted me to change my perspective. I now consider it very likely that Russian actors carried out the JLR hack, though I am less certain of their connection to the government of the Russian Federation. Given this new reporting, and the implications for national security if true, the UK government should respond to these allegations, even if it is simply to deny The Times’s reporting.

It’s All About the Behavior

Policymakers regularly talk about “norms of responsible state behavior in cyberspace”—for good reason. The norms, articulated by the Group of Governmental Experts (GGE) convened under the auspices of the United Nations and affirmed by all UN members for over a decade, reflect a global consensus about what should and should not be allowable in peacetime cyber operations. These norms play a dual role: they are of course meant to constrain offensive operations themselves, but they also shape the political response that those operations might prompt. In theory, these norms mean that if a nation’s critical infrastructure is hit by a cyber attack that is clearly counternormative, voices in and out of government will demand a response—and in doing so, will put pressure on the government to act.

It is difficult to plausibly argue that the JLR attack does not constitute “activity contrary to [a state’s] obligations under international law that intentionally damages critical infrastructure.” Critical Manufacturing is not formally designated a UK critical infrastructure sector, but JLR is heavily involved in the UK’s defense sector. The question, then, is whether the state in question, Russia, “conduct[ed] or knowingly support[ed] ICT activity contrary to its obligations under international law”?

Of course, we may not yet know with certainty the Russian government’s involvement—and we may never know at all. But if, as The Times has reported, Russian nationals operating from Russian territory were responsible, that fact pattern clearly matches violation of another norm: that countries should not “knowingly allow their territory to be used for internationally wrongful acts using ICTs.” Given the magnitude of the JLR incident and Russia’s history of ignoring cyber criminals who target non-Russian speaking populations, the Russian Federation is, at best, negligent with respect to the JLR hackers. No responsible state can plausibly claim to have conducted any due diligence when criminals are allowed to cause billions of dollars in damage with impunity, especially when that state has a history of tolerating similar, if not quite so spectacular, criminal activity.

Unfortunately, the lack of response from the UK government, as well as its allies and partners, undermines the very system it pushed to create through the GGE. After all, norms are meant to be articulations of state behavior. In other words, they are descriptive, not prescriptive. When a government fails to act in response to seemingly flagrant violations of the aspirational norms they have agreed to, it fundamentally weakens the norm. When nationals from another country felled one of the UK’s largest manufacturers for weeks in peacetime, the UK did not publicly respond. Is that the world we want to live in?

This is not unique to the UK. Policymakers the world over attempt to avoid this kind of normative erosion by declining to attribute cyber operations. The UK seems to have engaged in exactly this strategy: according to The Times, Microsoft informed JLR and government officials of the Russia connection within days. Other than a relatively speculative article in The Telegraph last October, the UK government, whether by intentional suppression or otherwise, has kept the attribution out of the public discourse and thus avoided calling the question on how it should respond.

So, what is in a norm? Given the normative implications of the JLR attack, UK policymakers should not be rewarded for dodging the topic. Consider things from the Russian perspective: If they believe the National Crime Agency’s assertion that the UK, one of the most capable intelligence powers in the world, still cannot determine the responsible actor ten months after the attack, then Russian actors may conclude that they can act with impunity. If, on the other hand, they believe that the UK government has known the responsible actor for nearly ten months but failed to act, then Russian actors may conclude that the UK lacks the political will to respond–also incentivizing further disruptive cyber operations.

The timing does not help. The world looks different today than it did in September 2025. Reasonable foreign policy professionals may question whether now is the time to inflame tensions with Russia by responding with measures like sanctions, expelling diplomats, or cyber operations against Russian intelligence targets. 

But, in all likelihood, this is a dilemma of their own making. If foreign policy professionals advise inaction in the immediate aftermath of the attack based on privately-disclosed evidence presented by Microsoft that indicated a Russia connection, then they should not also be able to advise inaction ten months later when journalists discover that a blind eye was turned. Yet, absent some pressure on UK policymakers, inaction is exactly what seems likely to happen, to the detriment of global stability in cyberspace.

I will leave you with one of the better speeches I have heard on the topic of international law in cyberspace. Delivered in 2018, I still come back to it from time to time. One of many passages relevant to the JLR case reads:

“But for all the work I have described, both domestic and international, it remains the case that defining the appropriate principles of international law to apply to cyberspace is difficult. Around the world there are many who would not bother trying – some because they have scant regard for international law more generally and some because they see little advantage in being explicit about rules of acceptable behaviour.

“We do. The clearer we are about the boundaries of acceptable behaviour, the lower the risk of miscalculation and the clearer the consequences can be for transgressing them.” [emphasis added]

The irony, of course, is that those words were not uttered by an academic legal scholar, or even one of my former bosses (cyber luminaries, all!). No, that speech was by the UK’s then-Attorney General. I hope the UK government will heed those words or that, at the very least, Sir Jeremy Wright MP—who remains a sitting Member of Parliament today—will ask some hard questions of them.

Related Content

Topics

Share

Facebook
Twitter
LinkedIn
Print
MENU

GET IN TOUCH

Email: [email protected]
Send us a message: Contact

JOIN THE CATALINK MAILING LIST