India is investigating a suspected cyberattack on Tata Electronics after a threat actor claimed to have breached the company’s internal network and leaked more than 630 GB of data spanning over 204,300 files. The exposed material reportedly includes confidential Apple supplier specifications, component and supplier lists, internal code names, testing photos, and images tied to unreleased iPhone 18 Pro and iPhone 18 Pro Max models, along with documents linked to Tesla, TSMC, and Qualcomm. Reports said the stolen files had been circulating on the dark web since at least June 10, and the extortion and ransomware group World Leaks was identified as the actor behind the publication.
Tata Electronics said it detected a data incident on some systems weeks earlier, activated incident-response protocols immediately, and maintained that business operations were not affected. The company reportedly restricted internal access to sensitive systems and brought in a global consultant for a forensic audit, while Indian officials said the case had been reported to CERT-In and the Ministry of Electronics and Information Technology opened a probe. Apple said it was concerned, was investigating the exposure, and was working with Tata on longer-term security measures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
India’s Ministry of Electronics and Information Technology began investigating a suspected cyberattack against Tata Electronics after a threat actor claimed to have breached the company’s internal network and leaked sensitive data online. The allegedly stolen data was reported to exceed 630 GB across more than 204,300 files, including Apple supplier specifications, Tesla manufacturing documents, and images tied to unreleased iPhone 18 Pro models.
Indian officials said the Tata Electronics matter was reported to CERT-In following the suspected cyberattack and data leak. Tata also stated that business operations were not affected.
Tata Electronics said it detected a data incident on some of its systems a few weeks before the July 7 report and immediately activated incident response protocols. The company also restricted internal access to sensitive systems and hired a global consultant for a forensic audit.
Apple said it was concerned about the incident, was investigating, and was working with Tata Electronics on long-term security measures. The leaked material reportedly included information tied to unreleased iPhone 18 Pro and iPhone 18 Pro Max models.
Reporting identified the extortion/ransomware group World Leaks as the threat actor behind the Tata Electronics cyberattack. The breach was described as leading to the theft and dark web publication of confidential Apple documents.
A dataset allegedly stolen from Tata Electronics had been circulating since at least 2026-06-10. The material reportedly included more than 200,000 files containing confidential Apple-related documents and other sensitive data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.