Note: This piece is public-interest reporting and threat intelligence analysis of a confirmed data breach. The screenshots are redacted with the aim to establish that the dump is genuine and current, showing what it covers, rather than republishing trade secrets or individuals’ personal documents.

Tata Electronics has confirmed a cyber security incident after the extortion group World Leaks published more than 200,000 files, around 630GB, on its dark web leak site. The data includes component designs and specifications linked to Apple and Tesla. Researchers who reviewed the dump for Reuters reported employee passport scans and internal emails, alongside event logs going back several years. The files have been accessible since at least June 10th.

Tata said it identified the incident a few weeks ago and that operations across its businesses remain unaffected. Apple is investigating and has reportedly received a ransom demand, though it is said to assess limited risk, with much of the material dating to 2021.

World Leaks is the January 2025 re-brand of Hunters International, previously suspected as a successor to Hive. The same infrastructure and extortion playbook carried across the rename. The group has moved away from encryption to data theft only, a model that removes the recovery value of backups and shifts exposure onto whatever data leaves the network. Researchers most often attribute its access to valid credentials and VPNs without MFA, frequently sourced from infostealer logs.

The breach adds to scrutiny of Apple’s manufacturing base in India, where Tata produces around a third of locally made iPhones. It follows the Jaguar Land Rover attack that halted production at the Tata-owned carmaker for roughly six weeks last year.

What the file index shows

ThreatCluster independently reviewed the file index from the dump and examined a sample of the listed files. They are present and retrievable, which confirms the listing as an accurate map of what was taken. The picture departs from parts of the public account, both on authenticity and on the age of the data.

The index is a 31 MB text file of 204,341 paths, each prefixed with the Tata Electronics domain. It maps the internal Windows file servers behind the company’s iPhone manufacturing, the Apple portion of the wider leak.

Redacted view of the 31 MB file index listing Tata Electronics paths

Scope

The files come from four servers.

  • TELSRVQAFILE (111,619 files) — QA, test engineering, logistics, HR
  • TEPSNPIFILE (74,209 files) — New Product Introduction: AE, kitting, fixtures
  • TEPSHRFILENPIA (111,076 files) — MLB FAE and process
  • TSATFS0 (17,437 files) — Equipment data

Redacted view of the TSATFS0 equipment-data share

The types of data in the set

A review of around 30 files drawn from across the shares shows the range of what was taken. The set spans employee passport and identity scans, Apple circuit-board schematics and design diagrams, internal Tata memos, staff emails, procurement and process documentation, and the software and engineering files behind the production line.

What the data covers

The naming leaves little doubt about what the data covers. Apple product and board codenames run through the paths: “Leo” appears around 44,000 times, alongside “V53”, “N1” and “D37”. Manufacturing process terms recur throughout, among them “MLB” for main logic board and “FATP” for final assembly, test and pack, with the “SFIS” and “Tigris” manufacturing-execution systems named across thousands of files. Apple is referenced 513 times, Pegatron 384, Foxconn 61 and Wistron 6, the chain of contract manufacturers that have run the site. The inspection vendor Vitrox also appears around 13,000 times.

Redacted view of contract-manufacturer and vendor references across the paths

This is the working environment of a live iPhone assembly line, the one Tata took over at Hosur from Wistron and Pegatron.

Redacted view of the live iPhone assembly-line file structure

Credentials and keys

Some of the most sensitive material in the dump is credential and key data. Oracle database wallets, the “cwallet.sso” and “ewallet.p12” files that let applications log into databases without a prompt, sit in DbConfig folders across dozens of the SFIS and Tigris manufacturing applications. Private keys are present as .pem files, including ones tied to automation and credential-server components. PLC configuration backups, the “config.ini” files from BG, CG and PD line equipment, are in the set, and these routinely carry the credentials for plant-floor devices. secrets.user.json files and Windows credential blobs also appear.

Redacted view of credential and key material in the dump

Employee identity documents

The dump carries identity documents for Tata staff. Scans of Aadhaar cards and passports sit in the HR folders as PDFs, several of them named after the individual employee. KYC paperwork, offer letters and self-appraisal files are also present, and some of the passports belong to foreign nationals working at the site.

Redacted view of HR identity-document folders

Manufacturing IP

The leak exposes the manufacturing IP itself. Engineering files run to around 5,982 items, among them drawings, firmware and the .set and .iwp test programs that drive the testers. Around 4,999 source-code files are in the set, written in C#, Python, Lua and LabVIEW, amounting to the SFIS and Tigris application source together with the PLC backups. Testing and yield logs are present, along with repair records, AOI false-call images and burn-in logs, the process data Apple treats as confidential.

Redacted view of manufacturing IP, source code and process logs

Trade paperwork

A logistics share holds the trade documentation for the line. Bills of Entry, export invoices, packing lists, bonded-transfer documents for the SEZ and MOOWR schemes, e-Way bills and tax invoices are all present, and between them they set out the shipment volumes and trade flows for the iPhones moving through Hosur.

Redacted view of the logistics and trade-documentation share

Conclusion

What the index cannot show is what World Leaks does next. World Leaks holds a ransom over Tata and runs a leak site built to publish in stages, so the 630GB already posted may not be the whole of it…