Back to the desk

News briefing

Tata Electronics confirms cyber incident after group leaks alleged Apple and Tesla files

Severity: HighIndiaData theft2026-0804-TE03 min readBy Vivek Kumar
Conceptual illustration: a semiconductor wafer breaking into glowing fragments. Text: TATA ELECTRONICS CYBER INCIDENT.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

The Apple supplier confirmed a cyber incident after the World Leaks extortion group posted what it says is 630GB of company data. The government says nothing critical was lost; Tata has not said whether data was stolen.

01 / What happened

Tata Electronics, the Tata Group's electronics manufacturer and a major supplier to Apple, confirmed a cybersecurity incident on 22 June 2026, after files said to be stolen from it appeared on the leak site of the World Leaks extortion group. A spokesperson told TechCrunch the company had identified the incident on some of its systems "a few weeks ago", deployed its response protocols immediately, and that operations across its businesses were unaffected.

The group's listing claims more than 630GB of data in over 204,300 files. TechCrunch said a sample it reviewed contained what appear to be Apple supplier specifications and Tesla manufacturing documents. BleepingComputer described World Leaks as a rebrand of the Hunters International ransomware operation.

On 13 July, IT Secretary S. Krishnan said Tata Electronics was working closely with the Ministry of Electronics and Information Technology (MeitY) and that, based on the government's assessment so far, "nothing critical has been lost". Business Standard reported that Apple and Tata Electronics had told MeitY no significant data was lost. On 4 August, Tata Electronics told CNBC again that the incident had no impact on operations, but did not say whether any data was stolen.

02 / Why it matters

Tata Electronics assembles iPhones in India and is central to the country's push to win electronics manufacturing from China. CNBC reported that the leak became a talking point in China, where the state-run Global Times warned in July of weaknesses in "Made in India" and Chinese repair technicians shared what were said to be leaked specifications for unreleased iPhone 18 Pro models. Technicians told CNBC the drawings were of little practical use for copying the phone.

For a contract manufacturer, the most valuable data at risk often belongs to its customers.

World Leaks was also behind the June leak of Reliance Infrastructure files linked to the Kudankulam nuclear project.

03 / Who is exposed

  • Customers: Apple and Tesla material appears in samples reviewed by TechCrunch; Al Jazeera reported that Apple said it was concerned about the leak and was investigating.
  • Employees: TechCrunch reported that staff at iPhone assembly operations were told about the incident. Email conversations and SAP-related records were reported in the dataset, which could include staff details.
  • Consumers: Tata Electronics is a manufacturer, and no consumer account or payment data has been reported in the dataset.

04 / Confirmed vs. claimed

Confirmed: Tata Electronics identified a cybersecurity incident on some systems weeks before 22 June and says operations were unaffected (company statements to TechCrunch and CNBC). The IT Secretary said on 13 July that nothing critical had been lost and that CERT-In was examining the reported breach.

Claimed / unconfirmed: World Leaks' figures of 630GB and 204,300 files, and whether all of it came from Tata's systems. Reuters reported that a ransom was demanded; Tata declined to comment on this to The Record. Al Jazeera reported that the group had demanded $1.5 million from the Tata Group and published the data after the company declined to pay. Tata has not publicly confirmed any ransom figure.

05 / What to do now

  • Tata Electronics employees should watch for phishing that uses real HR, payroll or project details, change passwords reused elsewhere, and turn on multi-factor authentication for work and personal email.
  • Suppliers should confirm any change to bank details or payment instructions by phone, using a known contact.
  • If you lose money, call the national cyber-fraud helpline 1930 immediately and file a complaint at cybercrime.gov.in; the faster a fraud is reported, the better the chance of stopping the money moving on.
  • Do not download or share the leaked files; leak archives are a common malware lure.
  • Manufacturers: keep customer design data apart from general file shares and email, watch for bulk exports from ERP and mail systems, and report incidents to CERT-In within six hours, as its 2022 directions require.

Source log / 2026-0804-TE

More from the archive