UK car production fell 27% in September 2025, the lowest September output since 1952, according to figures published by the Society of Motor Manufacturers and Traders.
A National Statistic Recording A Single Intrusion
The comparison worth sitting with is what else appears in that series. The lowest September in seventy-three years — a period covering oil shocks, three-day weeks, recessions, industrial disputes and a pandemic.
A software intrusion at one manufacturer produced a worse month than any of them. This desk has spent much of this database arguing that cyber incidents are under-measured because the instruments are pointed at data. Here the effect was large enough to register on an instrument built for something else entirely.
Which Is Also The Reason To Be Careful With It
The 27% is not JLR alone. Monthly production figures move for many reasons — model changeovers, plant retooling, export timing, the wider condition of the industry, which was not strong in 2025.
The honest statement is that a single company’s five-week halt was the dominant contributor to an exceptionally bad month, in a sector where that company is a large share of national output. It is not that the intrusion caused a 27% decline. Attributing a whole statistical movement to one cause is precisely the error this desk criticises at 26-0425.
What It Does Establish
National-accounts data is not built to detect cyber incidents and has no field for them. When an event is large enough to be legible in a series like this one, it has passed a threshold that no security metric currently marks.
That suggests a measurement approach nobody is using: for availability incidents, the sector’s own output statistics are a better instrument than any breach register. They already exist, they are independently produced, and they measure the thing that actually happened.
Built on published industry-body statistics, listed below, read against 25-0902. We do not attribute the entire decline to a single cause. Corrections: corrections@forensicpost.com.