Threat reportData BreachTL-2026-0929
World Leaks Ransomware Group Breaches Tata Electronics — 630GB / 200,000+ Files Including Apple 'com.apple.factorydata' and Tesla Project Highland Design Data
World Leaks Ransomware Group Breaches Tata Electronics (TL-2026-0929), also tracked as Tata Electronics Data Breach, is a high-severity data breach, first published 2026-06-24. It is attributed to World Leaks with high confidence, affects Tata Electronics Corporate IT / manufacturing and design data, maps to 22 MITRE ATT&CK techniques (T1021, T1041, T1053), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 1World Leaks
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-0929
- Threat ID
- TL-2026-0929
- Also known as
- Tata Electronics Data Breach, Tata Electronics World Leaks Leak
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution
- World Leaks
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, electronics manufacturing, technology, automotive, supply chain, consumer electronics
- Target regions
- India, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in World Leaks Ransomware Group Breaches Tata Electronics
Malware and tooling: World Leaks custom exfiltration tool (Storage Software derivative), Chrome Remote Desktop, CloudFlare Tunnel, MEGAcmd / MEGAclient, PSEXEC, Rclone - S1040
How World Leaks Ransomware Group Breaches Tata Electronics works
The World Leaks extortion group (rebrand of Hunters International) breached Tata Electronics, exfiltrating 200,000+ files totaling 630+GB and publishing them on its dark-web leak site. The trove includes employee passport copies, multi-year event logs, internal emails, and third-party design data — Apple iPhone factory-data/quality-inspection documents and Tesla NV36 Chargeport Controller and Project Highland engineering drawings.
On 22-23 June 2026, Tata Electronics — a major Indian contract manufacturer that produces roughly one-third of Apple's iPhones assembled in India and supplies automotive components to Tesla — confirmed a cybersecurity incident after the World Leaks extortion group listed the company on its dark-web leak site. World Leaks claims to have exfiltrated more than 200,000 files totaling over 630 gigabytes, which have been accessible on the dark web since at least 10 June 2026.
The leaked dataset reportedly includes employee passport copies (including those of foreign nationals), internal emails, event logs spanning several years, manufacturing specifications, and component design documents belonging to Tata's customers. Among the most sensitive material: a 52-page document containing Apple quality-inspection standards for iPhone circuit-board components, files and folders tagged 'com.apple.factorydata' and referencing 'material specification' (181 items returned for an 'Apple' search), a folder labeled 'NV36 Chargeport Controller – North America' (a component of the upgraded Tesla Model Y), and a 2023 Tesla document marked 'TRADE SECRET' showing engineering drawings for Project Highland, the codename for Tesla's revamped Model 3 sedan, plus an assembly document dated May 2025. Document footers reading 'This document contains proprietary and confidential information of Apple Inc.' were observed in the leak.
World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation (itself a successor to Hive), pivoting from double-extortion encryption to a pure hack-and-leak data-extortion model. The group inherited Hunters International's infrastructure, code, and extortion playbook, and operates a custom exfiltration utility derived from the 'Storage Software' tool used by Hunters affiliates. By June 2026 the group had claimed roughly 169 victims across 28 countries (Nike, Dell, and a UBS third-party supplier among them) with manufacturing, healthcare, and business services its top sectors. Notably, despite its extortion-only branding, Darktrace documented an early-2026 World Leaks intrusion that still ended in file encryption.
Tata reported the incident had no impact on operations, said its response protocols were deployed immediately, and confirmed it had received a ransom demand. Apple stated it was investigating and a full analysis was underway. No CVE, confirmed initial-access vector, or Tata-specific IOCs were disclosed in public reporting; the technical TTPs and indicators documented in this record are drawn from the World Leaks / Hunters International group playbook as analyzed by Darktrace and Blackpoint, and should be treated as group-level hunting leads rather than confirmed artifacts of the Tata intrusion.
MITRE ATT&CK techniques used in TL-2026-0929
Lateral Movement
T1021 Remote Services; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing
Command and Control
T1090 Proxy; T1219 Remote Access Tools; T1572 Protocol Tunneling; T1573 Encrypted Channel
Credential Access
Discovery
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
Execution
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
Affected products and versions in World Leaks Ransomware Group Breaches Tata Electronics
- Tata Electronics — Corporate IT / manufacturing and design data repositories
Vulnerable versions: Enterprise environment as of June 2026 - Apple — iPhone factory-data / quality-inspection and material-specification documents (third-party exposure via supplier)
Vulnerable versions: com.apple.factorydata documents - Tesla — Project Highland (Model 3) and NV36 Chargeport Controller (Model Y) engineering drawings (third-party exposure via supplier)
Vulnerable versions: 2023-2025 design/assembly documents
Remediation for World Leaks Ransomware Group Breaches Tata Electronics
Patches
- Apply current FortiOS / FortiGate security updates and disable unused administrative interfaces on internet-facing appliances
Immediate actions
- Enforce MFA on all VPN, remote-access, and externally exposed authentication surfaces — World Leaks specifically targets VPNs lacking MFA
- Audit Fortinet/FortiGate and other perimeter appliances for default/weak/brute-forced administrator credentials and apply latest firmware
- Hunt for unauthorized Rclone, MEGAcmd, Cloudflare Tunnel (cloudflared), Chrome Remote Desktop, and OpenSSH binaries on servers
- Block egress to consumer cloud-storage services (MEGA, Backblaze B2) from server subnets that have no business need
- Assume third-party design data shared with the supplier is compromised; notify Apple, Tesla, and other affected customers and rotate any shared credentials/keys
Workarounds
- Restrict perimeter appliance admin access to management VLANs / allow-listed IPs
- Rate-limit and alert on repeated NTLM/authentication failures from internal and external sources
Longer-term hardening
- Deploy EDR with behavioral detection for lateral movement (PsExec, WinRM, RDP) and anomalous large outbound transfers
- Implement DLP and network segmentation isolating manufacturing/design data stores from general IT
- Establish a vendor/supply-chain security program requiring MFA, logging, and breach-notification SLAs from contract manufacturers
- Monitor for protocol tunneling (Cloudflare Tunnel / argotunnel) and unsanctioned remote-access tooling as policy violations
Weaknesses (CWE) in World Leaks Ransomware Group Breaches Tata Electronics
Timeline of World Leaks Ransomware Group Breaches Tata Electronics
- World Leaks emerges as a rebrand of the Hunters International ransomware operation, pivoting to a pure data-extortion (hack-and-leak) model.
- World Leaks first observed/tracked publicly (ransomware.live first-seen date).
- World Leaks claims the Nike breach, its largest claim of 2026; Darktrace also documents an early-2026 World Leaks intrusion ending in file encryption despite the group's extortion-only branding.
- A leaked Tesla assembly document referencing the NV36 Chargeport Controller is dated May 2025; a 2023 Tesla 'TRADE SECRET' Project Highland drawing is also present in the trove.
- Tata Electronics identifies a cybersecurity incident on some of its systems 'a few weeks' before disclosure and deploys response protocols.
- Tata Electronics data (200,000+ files, 630+GB) becomes accessible on the World Leaks dark-web leak site.
- World Leaks continues active operations, listing additional victims (e.g., L'Archevêque & Rivest, Super Finishing) around this date; total claimed victims ~169 across 28 countries.
- Tata Electronics confirms the data breach; reporting surfaces Apple 'com.apple.factorydata' and Tesla design documents in the leak (TechCrunch).
- Public disclosure widens (Reuters/CNBC, Cyber Security News); Tata confirms a ransom demand was received and Apple states it is investigating.
Sources cited for World Leaks Ransomware Group Breaches Tata Electronics
- Tata Electronics Data Breach
- India's Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets
- Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach
- Tata Electronics breach exposes thousands of Apple, Tesla secret files
- When Reality Diverges From the Playbook: Darktrace Identifies Encryption in a World Leaks Ransomware Attack
- World Leaks Ransomware — Threat Profile
- Ransomware.live — World Leaks group profile
- Hunters International Ransomware Is Not Shutting Down, It's Rebranding
- Hunters International ransomware shuts down after World Leaks rebrand, releases free decryptors
- Hunters International Ransomware Gang Rebrands as World Leaks
Detection coverage for TL-2026-0929
As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0929 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0929
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.