# World Leaks Ransomware Group Breaches Tata Electronics — 630GB / 200,000+ Files Including Apple 'com.apple.factorydata' and Tesla Project Highland Design Data

> The World Leaks extortion group (rebrand of Hunters International) breached Tata Electronics, exfiltrating 200,000+ files totaling 630+GB and publishing them on its dark-web leak site. The trove includes employee passport copies, multi-year event logs, internal emails, and third-party design data — Apple iPhone factory-data/quality-inspection documents and Tesla NV36 Chargeport Controller and Project Highland engineering drawings.

- **Published:** 2026-06-24T00:00:00Z
- **Last reviewed:** 2026-06-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0929
- **ID:** TL-2026-0929
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Actor:** World Leaks
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 22-23 June 2026, Tata Electronics — a major Indian contract manufacturer that produces roughly one-third of Apple's iPhones assembled in India and supplies automotive components to Tesla — confirmed a cybersecurity incident after the World Leaks extortion group listed the company on its dark-web leak site. World Leaks claims to have exfiltrated more than 200,000 files totaling over 630 gigabytes, which have been accessible on the dark web since at least 10 June 2026.

The leaked dataset reportedly includes employee passport copies (including those of foreign nationals), internal emails, event logs spanning several years, manufacturing specifications, and component design documents belonging to Tata's customers. Among the most sensitive material: a 52-page document containing Apple quality-inspection standards for iPhone circuit-board components, files and folders tagged 'com.apple.factorydata' and referencing 'material specification' (181 items returned for an 'Apple' search), a folder labeled 'NV36 Chargeport Controller – North America' (a component of the upgraded Tesla Model Y), and a 2023 Tesla document marked 'TRADE SECRET' showing engineering drawings for Project Highland, the codename for Tesla's revamped Model 3 sedan, plus an assembly document dated May 2025. Document footers reading 'This document contains proprietary and confidential information of Apple Inc.' were observed in the leak.

World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation (itself a successor to Hive), pivoting from double-extortion encryption to a pure hack-and-leak data-extortion model. The group inherited Hunters International's infrastructure, code, and extortion playbook, and operates a custom exfiltration utility derived from the 'Storage Software' tool used by Hunters affiliates. By June 2026 the group had claimed roughly 169 victims across 28 countries (Nike, Dell, and a UBS third-party supplier among them) with manufacturing, healthcare, and business services its top sectors. Notably, despite its extortion-only branding, Darktrace documented an early-2026 World Leaks intrusion that still ended in file encryption.

Tata reported the incident had no impact on operations, said its response protocols were deployed immediately, and confirmed it had received a ransom demand. Apple stated it was investigating and a full analysis was underway. No CVE, confirmed initial-access vector, or Tata-specific IOCs were disclosed in public reporting; the technical TTPs and indicators documented in this record are drawn from the World Leaks / Hunters International group playbook as analyzed by Darktrace and Blackpoint, and should be treated as group-level hunting leads rather than confirmed artifacts of the Tata intrusion.

## MITRE ATT&CK

- T1595 Active Scanning
- T1590 Gather Victim Network Information
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1133 External Remote Services
- T1566 Phishing
- T1110 Brute Force
- T1569 System Services
- T1053 Scheduled Task/Job
- T1547 Boot or Logon Autostart Execution
- T1135 Network Share Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1210 Exploitation of Remote Services
- T1219 Remote Access Tools
- T1572 Protocol Tunneling
- T1573 Encrypted Channel
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1657 Financial Theft

## Sources

- [Tata Electronics Data Breach](https://cybersecuritynews.com/tata-electronics-data-breach/)
- [India's Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets](https://www.cnbc.com/2026/06/23/indias-tata-electronics-hit-by-cyber-breach-claiming-to-expose-apple-tesla-trade-secrets.html)
- [Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach](https://techcrunch.com/2026/06/22/tata-electronics-a-major-tech-supplier-to-apple-and-tesla-confirms-data-breach/)
- [Tata Electronics breach exposes thousands of Apple, Tesla secret files](https://cybernews.com/security/tata-electronics-breach-apple-tesla-secret-files/)
- [When Reality Diverges From the Playbook: Darktrace Identifies Encryption in a World Leaks Ransomware Attack](https://www.darktrace.com/blog/when-reality-diverges-from-the-playbook-darktrace-identifies-encryption-in-a-world-leaks-ransomware-attack)
- [World Leaks Ransomware — Threat Profile](https://blackpointcyber.com/threat-profile/world-leaks-ransomware/)
- [Ransomware.live — World Leaks group profile](https://www.ransomware.live/group/worldleaks)
- [Hunters International Ransomware Is Not Shutting Down, It's Rebranding](https://www.infosecurity-magazine.com/news/ransomware-hunters-international/)
- [Hunters International ransomware shuts down after World Leaks rebrand, releases free decryptors](https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-shuts-down-after-world-leaks-rebrand/)
- [Hunters International Ransomware Gang Rebrands as World Leaks](https://hackread.com/hunters-international-ransomware-rebrands-world-leaks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0929
