World Leaks Ransomware Group Breaches Tata Electronics — 630GB / 200,000+ Files Including Apple 'com.apple.factorydata' and Tesla Project Highland Design Data — Threadlinqs Intelligence
As of 2026-06-24, World Leaks Ransomware Group Breaches Tata Electronics — 630GB / 200,000+ Files Including Apple 'com.apple.factorydata' and Tesla Project Highland Design Data is a high-severity data breach threat attributed to World Leaks, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0929 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: World Leaks · FINANCIAL
The World Leaks extortion group (rebrand of Hunters International) breached Tata Electronics, exfiltrating 200,000+ files totaling 630+GB and publishing them on its dark-web leak site. The trove
On 22-23 June 2026, Tata Electronics — a major Indian contract manufacturer that produces roughly one-third of Apple's iPhones assembled in India and supplies automotive components to Tesla — confirmed a cybersecurity incident after the World Leaks extortion group listed the company on its dark-web leak site. World Leaks claims to have exfiltrated more than 200,000 files totaling over 630 gigabytes, which have been accessible on the dark web since at least 10 June 2026.
The leaked dataset reportedly includes employee passport copies (including those of foreign nationals), internal emails, event logs spanning several years, manufacturing specifications, and component design documents belonging to Tata's customers. Among the most sensitive material: a 52-page document containing Apple quality-inspection standards for iPhone circuit-board components, files and folders tagged 'com.apple.factorydata' and referencing 'material specification' (181 items returned for an 'Apple' search), a folder labeled 'NV36 Chargeport Controller – North America' (a component of the upgraded Tesla Model Y), and a 2023 Tesla document marked 'TRADE SECRET' showing engineering drawings for Project Highland, the codename for Tesla's revamped Model 3 sedan, plus an assembly document dated May 2025. Document footers reading 'This document contains proprietary and confidential information of Apple Inc.' were observed in the leak.
World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation (itself a successor to Hive), pivoting from double-extortion encryption to a pure hack-and-leak data-extortion model. The group inherited Hunters International's infrastructure, code, and extortion playbook, and operates a custom exfiltration utility derived from the 'Storage Software' tool used by Hunters affiliates. By June 2026 the group had claimed roughly 169 victims across 28 countries (Nike, Dell, and a UBS third-party supplier among them) with manufacturing, healthcare, and business services its top sectors. Notably, despite its extortion-only branding, Darktrace documented an early-2026 World Leaks intrusion that still ended in file encryption.
Tata reported the incident had no impact on operations, said its response protocols were deployed immediately, and confirmed it had received a ransom demand. Apple stated it was investigating and a full analysis was underway. No CVE, confirmed initial-access vector, or Tata-specific IOCs were disclosed in public reporting; the technical TTPs and indicators documented in this record are drawn from the World Leaks / Hunters International group playbook as analyzed by Darktrace and Blackpoint, and should be treated as group-level hunting leads rather than confirmed artifacts of the Tata intrusion.
Weaknesses (CWE)
CWE-1392, CWE-308, CWE-522, CWE-307
Target sectors: manufacturing, electronics manufacturing, technology, automotive, supply chain, consumer electronics
Target regions: India, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1595, T1595, T1590, T1190, T1078, T1133, T1566, T1110, T1569, T1053