Threat reportData BreachTL-2026-0929

World Leaks Ransomware Group Breaches Tata Electronics — 630GB / 200,000+ Files Including Apple 'com.apple.factorydata' and Tesla Project Highland Design Data

highACTIVE

World Leaks Ransomware Group Breaches Tata Electronics (TL-2026-0929), also tracked as Tata Electronics Data Breach, is a high-severity data breach, first published 2026-06-24. It is attributed to World Leaks with high confidence, affects Tata Electronics Corporate IT / manufacturing and design data, maps to 22 MITRE ATT&CK techniques (T1021, T1041, T1053), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
1World Leaks
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0929

Threat ID
TL-2026-0929
Also known as
Tata Electronics Data Breach, Tata Electronics World Leaks Leak
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution
World Leaks
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
manufacturing, electronics manufacturing, technology, automotive, supply chain, consumer electronics
Target regions
India, North America, Europe
Detection rules
9
Indicators of compromise
22

Malware and tooling in World Leaks Ransomware Group Breaches Tata Electronics

Malware and tooling: World Leaks custom exfiltration tool (Storage Software derivative), Chrome Remote Desktop, CloudFlare Tunnel, MEGAcmd / MEGAclient, PSEXEC, Rclone - S1040

How World Leaks Ransomware Group Breaches Tata Electronics works

The World Leaks extortion group (rebrand of Hunters International) breached Tata Electronics, exfiltrating 200,000+ files totaling 630+GB and publishing them on its dark-web leak site. The trove includes employee passport copies, multi-year event logs, internal emails, and third-party design data — Apple iPhone factory-data/quality-inspection documents and Tesla NV36 Chargeport Controller and Project Highland engineering drawings.

On 22-23 June 2026, Tata Electronics — a major Indian contract manufacturer that produces roughly one-third of Apple's iPhones assembled in India and supplies automotive components to Tesla — confirmed a cybersecurity incident after the World Leaks extortion group listed the company on its dark-web leak site. World Leaks claims to have exfiltrated more than 200,000 files totaling over 630 gigabytes, which have been accessible on the dark web since at least 10 June 2026.

The leaked dataset reportedly includes employee passport copies (including those of foreign nationals), internal emails, event logs spanning several years, manufacturing specifications, and component design documents belonging to Tata's customers. Among the most sensitive material: a 52-page document containing Apple quality-inspection standards for iPhone circuit-board components, files and folders tagged 'com.apple.factorydata' and referencing 'material specification' (181 items returned for an 'Apple' search), a folder labeled 'NV36 Chargeport Controller – North America' (a component of the upgraded Tesla Model Y), and a 2023 Tesla document marked 'TRADE SECRET' showing engineering drawings for Project Highland, the codename for Tesla's revamped Model 3 sedan, plus an assembly document dated May 2025. Document footers reading 'This document contains proprietary and confidential information of Apple Inc.' were observed in the leak.

World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation (itself a successor to Hive), pivoting from double-extortion encryption to a pure hack-and-leak data-extortion model. The group inherited Hunters International's infrastructure, code, and extortion playbook, and operates a custom exfiltration utility derived from the 'Storage Software' tool used by Hunters affiliates. By June 2026 the group had claimed roughly 169 victims across 28 countries (Nike, Dell, and a UBS third-party supplier among them) with manufacturing, healthcare, and business services its top sectors. Notably, despite its extortion-only branding, Darktrace documented an early-2026 World Leaks intrusion that still ended in file encryption.

Tata reported the incident had no impact on operations, said its response protocols were deployed immediately, and confirmed it had received a ransom demand. Apple stated it was investigating and a full analysis was underway. No CVE, confirmed initial-access vector, or Tata-specific IOCs were disclosed in public reporting; the technical TTPs and indicators documented in this record are drawn from the World Leaks / Hunters International group playbook as analyzed by Darktrace and Blackpoint, and should be treated as group-level hunting leads rather than confirmed artifacts of the Tata intrusion.

MITRE ATT&CK techniques used in TL-2026-0929

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing

Command and Control

T1090 Proxy; T1219 Remote Access Tools; T1572 Protocol Tunneling; T1573 Encrypted Channel

Credential Access

T1110 Brute Force

Discovery

T1135 Network Share Discovery

Impact

T1486 Data Encrypted for Impact; T1657 Financial Theft

Execution

T1569 System Services

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in World Leaks Ransomware Group Breaches Tata Electronics

  • Tata Electronics — Corporate IT / manufacturing and design data repositories
    Vulnerable versions: Enterprise environment as of June 2026
  • Apple — iPhone factory-data / quality-inspection and material-specification documents (third-party exposure via supplier)
    Vulnerable versions: com.apple.factorydata documents
  • Tesla — Project Highland (Model 3) and NV36 Chargeport Controller (Model Y) engineering drawings (third-party exposure via supplier)
    Vulnerable versions: 2023-2025 design/assembly documents

Remediation for World Leaks Ransomware Group Breaches Tata Electronics

Patches

  • Apply current FortiOS / FortiGate security updates and disable unused administrative interfaces on internet-facing appliances

Immediate actions

  • Enforce MFA on all VPN, remote-access, and externally exposed authentication surfaces — World Leaks specifically targets VPNs lacking MFA
  • Audit Fortinet/FortiGate and other perimeter appliances for default/weak/brute-forced administrator credentials and apply latest firmware
  • Hunt for unauthorized Rclone, MEGAcmd, Cloudflare Tunnel (cloudflared), Chrome Remote Desktop, and OpenSSH binaries on servers
  • Block egress to consumer cloud-storage services (MEGA, Backblaze B2) from server subnets that have no business need
  • Assume third-party design data shared with the supplier is compromised; notify Apple, Tesla, and other affected customers and rotate any shared credentials/keys

Workarounds

  • Restrict perimeter appliance admin access to management VLANs / allow-listed IPs
  • Rate-limit and alert on repeated NTLM/authentication failures from internal and external sources

Longer-term hardening

  • Deploy EDR with behavioral detection for lateral movement (PsExec, WinRM, RDP) and anomalous large outbound transfers
  • Implement DLP and network segmentation isolating manufacturing/design data stores from general IT
  • Establish a vendor/supply-chain security program requiring MFA, logging, and breach-notification SLAs from contract manufacturers
  • Monitor for protocol tunneling (Cloudflare Tunnel / argotunnel) and unsanctioned remote-access tooling as policy violations

Weaknesses (CWE) in World Leaks Ransomware Group Breaches Tata Electronics

CWE-1392, CWE-308, CWE-522, CWE-307

Timeline of World Leaks Ransomware Group Breaches Tata Electronics

  • World Leaks emerges as a rebrand of the Hunters International ransomware operation, pivoting to a pure data-extortion (hack-and-leak) model.
  • World Leaks first observed/tracked publicly (ransomware.live first-seen date).
  • World Leaks claims the Nike breach, its largest claim of 2026; Darktrace also documents an early-2026 World Leaks intrusion ending in file encryption despite the group's extortion-only branding.
  • A leaked Tesla assembly document referencing the NV36 Chargeport Controller is dated May 2025; a 2023 Tesla 'TRADE SECRET' Project Highland drawing is also present in the trove.
  • Tata Electronics identifies a cybersecurity incident on some of its systems 'a few weeks' before disclosure and deploys response protocols.
  • Tata Electronics data (200,000+ files, 630+GB) becomes accessible on the World Leaks dark-web leak site.
  • World Leaks continues active operations, listing additional victims (e.g., L'Archevêque & Rivest, Super Finishing) around this date; total claimed victims ~169 across 28 countries.
  • Tata Electronics confirms the data breach; reporting surfaces Apple 'com.apple.factorydata' and Tesla design documents in the leak (TechCrunch).
  • Public disclosure widens (Reuters/CNBC, Cyber Security News); Tata confirms a ransom demand was received and Apple states it is investigating.

Sources cited for World Leaks Ransomware Group Breaches Tata Electronics

Detection coverage for TL-2026-0929

As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0929 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-0929

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats