Tata Electronics confirmed a cybersecurity incident affecting some of its systems after threat actors advertised more than 630GB of allegedly stolen data, spanning roughly 204,300 files, on a hacker forum and dark-web leak site. Researchers linked the posting to the World Leaks ransomware group, and reviewed samples reportedly included Outlook email conversations, event logs, SAP-related information, employee passport copies, and internal documents tied to Tata’s operations. Tata said it detected the incident weeks earlier, activated response protocols, and reported that business operations were not affected.
Samples of the leaked material appeared to include confidential supplier specifications and manufacturing documents connected to Apple and Tesla, raising supply-chain security concerns because Tata is a major manufacturing partner for both companies and also works with other semiconductor and technology firms. Reuters reported that some employees at Tata’s iPhone assembly operations were informed of the breach, Apple opened an investigation, and Tata allegedly received a ransom demand, though the company did not publicly comment on that point.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A July 1 report said the leaked Tata Electronics data included logic board schematics for the unreleased iPhone 18 Pro and iPhone 18 Pro Max, plus data sheets for Apple-designed chips including the A20 Pro. AppleInsider reportedly reviewed the files and assessed them as likely legitimate.
Following the cyberattack, Tata Electronics restricted access to sensitive systems and engaged a global consultant to conduct a forensic audit. Apple was also reported to be working with Tata on longer-term security improvements.
Reuters reported that Apple was investigating the Tata Electronics breach after leaked files appeared to reference confidential Apple component designs and supplier specifications. The incident raised supply-chain security concerns because of Tata's role in Apple's India manufacturing operations.
Reuters reported that some employees at Tata's iPhone assembly operations were informed of the breach and that Tata had received a ransom demand. Tata declined to comment on the ransom aspect.
Tata Electronics disclosed that it had recently detected a cybersecurity incident affecting some of its systems. The confirmation followed reports that World Leaks had posted or advertised allegedly stolen Tata data online.
Tata Electronics said it detected a cybersecurity incident affecting some of its systems a few weeks before its public confirmation and activated response protocols. The company said business operations were not affected.
Researchers said purported stolen Tata Electronics data had been accessible on the dark web since at least June 10. The dataset was described as containing more than 200,000 files totaling over 630 GB.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
20 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcemacrumors.com
Open sourceboingboing.net
Open sourcezdnet.fr
Open sourcemacrumors.com
Open sourceteiss.co.uk
Open sourcebusinessinsurance.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.