← Blog

Tata Electronics Breach: iPhone 18 Pro Supplier List Leaked on World Leaks

Share on X

June 22, 2026: India's Tata Electronics—a cornerstone of Apple's iPhone manufacturing outside China—confirmed a cybersecurity incident as the World Leaks extortion group published an archive it claims contains more than 200,000 files (~630GB) of design documents tied to Apple and Tesla, two of the world's most secretive OEMs and Tata clients.

What happened

Tata Electronics told Reuters it detected a cybersecurity incident on some systems "a few weeks ago," deployed response protocols immediately, and stated operations across businesses remain unaffected. The same day, security researchers said World Leaks—previously linked to Nike extortion marketing—posted the stolen data on its dark-web site after Tata received a ransom demand (which Tata declined to discuss publicly).

Indian cybersecurity researcher Rajshekhar Rajaharia reviewed the leak for Reuters and described:

  • Apple material: folders titled com.apple.factorydata, a 52-page document with Apple proprietary markings on iPhone circuit-board quality inspection standards, and 181 files/folders matching "Apple" searches—including 33 tied to Hosur, Tamil Nadu, where Tata runs a major iPhone assembly plant
  • Tesla material: a folder labelled "NV36 Chargeport Controller - North America" (Model Y upgrade references), Project Highland Model 3 drawings marked TRADE SECRET, and May 2025 assembly specifications
  • HR/operational data: multi-year event logs, employee emails, and passport copies including foreign nationals

Why this matters for Apple and Tesla

Tata accounts for roughly one-third of Apple's iPhone production in India, with Foxconn supplying the remainder—a strategic pillar of Prime Minister Modi's electronics manufacturing push. A leak of factory QC standards, material specifications, and factorydata schemas is not consumer PII—it is industrial espionage fuel: counterfeit parts risk, supply-chain manipulation, and advance knowledge of unreleased hardware tolerances.

For Tesla, leaked chargeport controller and Highland assembly drawings expose manufacturing know-how for vehicles still scaling globally. Footers on published files explicitly cite Apple Inc. and Tesla Inc. confidential/trade-secret markings.

Tesla documents: what researchers say leaked

Tesla has not confirmed the breach or authenticated any files, and did not respond to Reuters requests for comment. Nevertheless, Rajaharia's review of the World Leaks database—shared with Reuters via screen recording—surfaced Tesla-tagged material distinct from the Apple factorydata corpus:

  • NV36 Chargeport Controller — North America: a folder name Reuters ties to purported components for an upgraded Model Y SUV variant
  • Project Highland (Model 3): a 2023 document marked TRADE SECRET with engineering drawings—Highland is Tesla's publicly known internal codename for the revamped Model 3 sedan (Reuters background)
  • May 2025 assembly specification and additional manufacturing specs returned when searching the archive for "Tesla"
  • Legal footers on multiple files stating content is confidential, proprietary, and a trade secret of Tesla Inc.

Industry sources told Reuters that Tata manufactures parts for Tesla in addition to Apple—meaning the leak path is almost certainly a contract-manufacturer MES/document repository, not a compromise of Tesla's Austin or Fremont corporate networks. The risk profile is industrial espionage: clone chargeport assemblies, anticipate Model 3/Y refresh tolerances, and undercut Tesla on component bids in third markets.

BreachHistory indexes Tesla's angle separately at Tesla Tata supply-chain documents 2026 with companyConfirmed: false until Tesla attests scope.

A source familiar with Apple's response told Reuters the company is investigating with a full analysis underway. Apple did not respond to Reuters comment requests at publication.

June 29 update: iPhone 18 Pro supplier list and drop-test photos

On June 29, 2026, Reuters reported new files in the same World Leaks archive mapping hundreds of iPhone 18 Pro and Pro Max components to specific suppliers—detail Apple does not disclose publicly. At least six files explicitly tie main circuit-board chips, battery parts, and camera modules to named vendors, revealing where Apple multi-sources versus single-sources components.

The leak also includes drop-test photographs from Tata plants dated early 2026 showing a slab-shaped grey handset with triple rear cameras and the Apple logo, with Apple confidential watermarks and internal iPhone 18 Pro codenames. Apple considers this material sensitive because it relates to unreleased models and could hand rivals, counterfeiters, and competing vendors intelligence on Apple's bargaining leverage.

Tata has restricted internal access to sensitive systems and hired a global forensic consultant per Reuters. BreachHistory indexes Apple's supply-chain angle separately at Apple iPhone 18 Pro supplier leak 2026.

World Leaks modus operandi

World Leaks operates as a pure data-extortion persona—similar to the January 2026 Nike campaign BreachHistory tracks—publishing large archives when ransom demands go unpaid rather than encrypting production systems. Tata's statement that factories keep running fits that pattern: exfiltration-first, operational continuity preserved.

Context: Tata's recent cyber history

This is the second high-profile cyber crisis for Tata Group in a year. A 2025 Jaguar Land Rover attack under the same corporate umbrella halted output for six weeks. The Tata Electronics incident arrives as Apple faces separate scrutiny over environmental issues near its Hosur parts plant—stacking reputational pressure on India's flagship contract manufacturer.

Who is at risk?

  • Tata employees whose passports and emails appear in the archive—identity theft and targeted spear-phishing
  • Apple and Tesla supply-chain teams—counterfeit components, clone tooling, and competitive intelligence
  • Downstream OEM security—partners should audit shared manufacturing portals and MES integrations with Tata

What to do

  1. Do not download World Leaks archives—possession may violate trade-secret and computer-fraud laws.
  2. Tata employees: watch for phishing citing real passport or project details; freeze credit if passport numbers were exposed.
  3. Apple/Tesla customers: this is not a retail account breach—no password rotation required unless you are a Tata employee or supply-chain partner.
  4. Security teams: monitor for counterfeit parts listings referencing leaked Apple/Tesla part numbers.

Bottom line

The Tata Electronics breach is a supply-chain confidentiality catastrophe more than a mass consumer data leak. With 630GB and 200,000+ files allegedly spanning two of the planet's most guarded product pipelines, it ranks among 2026's most consequential industrial cyber incidents—even with factories still running.

Canonical record: Tata Electronics World Leaks 2026 on BreachHistory.

Sources: Reuters, Economic Times