UK Committee Probes TCS Over Cyberattacks on Jaguar, M&S, and Co-op
Tata Consultancy Services (TCS) is under scrutiny from the UK Business and Trade Committee following major cyberattacks on its high-profile clients—Jaguar Land Rover (JLR), Marks & Spencer (M&S), and Co-op. The committee has demanded answers from TCS on its service scope, internal investigations, and cybersecurity protocols.
Of particular concern is a report suggesting the M&S breach originated from a ransomware email sent via a TCS employee’s account, raising questions about third-party risk and vendor security practices.
The attacks began as early as April 2025 for M&S and Co-op, while JLR’s disruption started on August 31, halting production until October 1. TCS, which provides critical IT services to all three firms, must respond by September 29.
The inquiry also seeks details on TCS’s contracts with firms in Critical National Infrastructure sectors. This marks a growing regulatory focus on third-party cyber risk in outsourced IT services.
The outcome could influence cybersecurity standards and accountability across the global IT services industry, especially for vendors supporting essential enterprises.

















