top of page

Cybersecurity incident at iPhone manufacturing plant: Alleged leak of over 630GB of Apple and Tesla data

Global supply chain security has just faced a major wake-up call. A severe cyberattack targeting an Apple manufacturing partner in India has resulted in a massive breach of internal data. Notably, this incident not only concerns Apple but also poses a risk to electric vehicle giant Tesla, highlighting critical security challenges as major corporations heavily rely on third-party vendors for product manufacturing.

Tata electronics' systems breached

The entity directly affected by this incident is the Tata Group. A spokesperson for Tata Electronics confirmed that an intrusion into their internal systems was detected a few weeks ago. Immediately following the discovery, emergency incident response protocols were activated, enabling the company to successfully avert production and operational disruptions.

One of Tata's two iPhone manufacturing plants in India
One of Tata's two iPhone manufacturing plants in India

Although the company has not specified the exact facility targeted, initial reports indicate that at least 33 files and folders are related to its manufacturing facility in Hosur, Tamil Nadu. This is the same factory that recently faced local controversy regarding water pollution issues.

Over 200,000 files leaked online by threat group

Behind this campaign is World Leaks, a cybercriminal group known for data exfiltration and extortion. The group previously made headlines with a prominent attack on Nike in January 2026. This threat group claims to have acquired and published over 200,000 data files from Tata, totaling more than 630GB.

While the authenticity of the leak has not been fully verified, the compromised repository contains highly sensitive information. This includes folders named "com.apple.factorydata", Apple material specifications, and a 52-page document outlining quality assurance procedures for iPhone circuit boards.

More concerningly, a security expert examining underground forums discovered copies of employee passports alongside years of system operation logs. If verified, this represents a severe data leak affecting both proprietary technological secrets and employee privacy.

Suspected leak of Tesla design specifications

A major surprise in this incident is the inclusion of documents allegedly belonging to Tesla. Cybersecurity researchers noted that data from both Apple and Tesla began being traded and shared within cybercriminal circles as early as June 10, 2026.

For the American EV manufacturer, the leaked repository contains engineering drawings related to Project Highland - the refreshed version of the Model 3 lineup introduced by Tesla in 2023. Additionally, the leaked data includes manufacturing assembly documentation dated May 2025, alongside component specifications for the Model Y SUV. If authentic, these documents could significantly impact the company's product development and manufacturing processes.

At present, Tata Electronics has declined to comment on whether they fell victim to a ransomware attack. However, publicly leaking data to pressure victims is a standard tactic among modern cybercriminals. As for Apple, while no official statement has been released, a source familiar with the matter revealed that the tech giant is conducting an in-depth analysis and assessment to verify the extent of the damage and the authenticity of the documents.

The large-scale data breach at Tata's manufacturing plant underscores the critical supply chain vulnerabilities that major technology corporations face globally. Information security can no longer be confined within the borders of a single organization; it demands strict, cohesive alignment across every link in the production ecosystem.

Reference: Vietnamnet

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page