Tata Electronics
World Leaks dumps 630GB from Apple's largest Indian iPhone manufacturer. Unreleased product schematics, Tesla engineering data, and active cryptographic credentials exposed.
What happened?
On June 12, 2026, World Leaks—a rebrand of the Hunters International ransomware group—published 630.4 gigabytes of data (204,341 files) stolen from Tata Electronics. The company is one of Apple's largest iPhone manufacturing partners in India and a significant Tesla supplier.
World Leaks is an extortion-only operation; they no longer encrypt data but threaten to leak it. When negotiations failed, they dumped the entire archive. Tata confirmed the incident on June 22 and stated business operations were not disrupted.
What data was actually inside?
Confidential supplier and component data for Apple's unreleased iPhone 18 Pro and iPhone 18 Pro Max. Engineering drawings tied to Tesla. Documents from TSMC and Qualcomm. Internal emails spanning corporate communications. Employee passport scans. Years of event logs documenting system activity.
The cryptographic certificates and key files are arguably the most dangerous category. These aren't historical records—they're potentially active credentials that could provide continued access or enable impersonation of Tata systems long after the initial breach was contained.
Who gets hurt and how?
Apple, whose unreleased product specifications are now public. Tesla, whose engineering designs are exposed. TSMC and Qualcomm, whose supplier documentation is in the leak. Tata employees whose passport scans and personal data were stolen. Every customer in Tata's supply chain faces secondary exposure.
Supply chain intelligence doesn't need to disrupt operations to cause damage. Competitor insight into unreleased products. Manufacturing process visibility. R&D investment exposure. The harm is strategic and long-term rather than immediately operational.
What did they think they were doing right?
Tata emphasized that business operations continued unaffected. Production lines ran. Manufacturing wasn't disrupted. From an operational continuity perspective, they contained the impact.
But World Leaks doesn't encrypt systems—they steal data. Operational continuity was never their target. The attack succeeded in its actual objective: exfiltrating 630GB of sensitive supply chain data that's now publicly available on the dark web.
What did they not know about their own data?
630GB across 204,341 files represents comprehensive organizational documentation. How much of this should have existed? How many of those files were active versus historical? Were cryptographic credentials being rotated, or had old keys accumulated alongside current ones?
Manufacturing partners accumulate customer documentation across years of relationships. Engineering specs from multiple product generations. Supplier communications from various projects. Data inventory would have revealed what sensitive customer data existed—and what should have been purged.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
Tata reported the incident to the Indian government and affected clients. They engaged global consultants for forensic audit. But 630GB is already out. Attribution to World Leaks is confirmed. The data is public.
Apple, Tesla, and other customers must now assess their own exposure through Tata. Each company needs to determine what proprietary information was in those 204,341 files. The supply chain notification cascade is just beginning.
What would have changed the outcome?
Inventorying customer intellectual property across manufacturing systems—and implementing retention policies that minimized accumulation of sensitive third-party data.
Supply chain manufacturers hold their customers' secrets. Every engineering spec, every product design, every technical document creates exposure that extends beyond the manufacturer to everyone they serve. Data inventory identifies what customer IP exists. Retention enforcement limits how much accumulates. The manufacturers that survive these incidents are the ones that knew what they held—and held only what they needed.
Tata Electronics found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.