Tata Electronics says its operations were not disrupted by a recent cyberattack. For Apple and Tesla, that may be the least complicated part of the story.
The larger risk sits in the files that a ransomware-linked group claims to have taken from the Indian manufacturer. World Leaks says it published a cache of more than 200,000 documents totaling more than 630GB, with alleged material tied to Apple, Tesla, Tata employees, and other Tata Electronics customers.
‼️🚨 BREAKING: CONFIDENTIAL DOCUMENTS OF APPLE AND TESLA HAVE BEEN LEAKED.
— International Cyber Digest (@IntCyberDigest) June 22, 2026
Tata Electronics, which builds about a third of Apple's iPhones in India, has confirmed a cyberattack after the extortion group World Leaks posted what it claims are confidential Apple and Tesla files —… pic.twitter.com/Q6W0fvba2l
Tata confirmed it identified a cybersecurity incident on some systems several weeks ago and said response protocols were activated, according to TechCrunch. The company said its businesses continued to operate normally. It has not publicly detailed which systems were affected, what data may have been accessed, how many customers were involved, or whether employee identity documents were exposed.
Reuters reported that World Leaks’ dark web listing included purported Apple and Tesla files, including Apple-related factory data folders, material specification documents, and a 52-page Apple-marked file tied to iPhone circuit-board inspection standards.
The alleged Tesla-linked material is also potentially sensitive. Reuters reported that one folder name referred to a North American chargeport controller associated with an upgraded Model Y, while another 2023 file carried Tesla trade-secret language and appeared connected to Project Highland, Tesla’s internal name for the revamped Model 3.
A ransomware group’s claim is not proof. But Tata’s confirmation that a cyber incident occurred changes the market question from “Did hackers post something?” to “What customer-controlled information was inside Tata’s systems, and who is responsible for protecting it?”
Aside from commercial implications, the personal-data angle may be the more immediate legal and regulatory issue. Reuters cited cybersecurity researcher Rajshekhar Rajaharia as saying the files he reviewed included emails, long-running event logs, and passport copies belonging to employees, including foreign nationals. Another researcher, Rakesh Krishnan, told Reuters the dump had been visible on the dark web by June 10.
If employee identity documents are confirmed to be part of the leak, Tata could face questions that go beyond customer contracts. Those include employee notification, cross-border data handling, privacy compliance, and whether the company can map which files were accessed.
Apple has been building a larger India manufacturing footprint as it reduces reliance on China and Tata has become central to that shift. Reuters has reported that Tata accounts for roughly one-third of Apple’s iPhone production in India, with Foxconn handling the rest. Tata also acquired a 60% stake in Pegatron Technology India in 2025, expanding its control over iPhone manufacturing assets in the country.
That makes the alleged breach more consequential than a vendor IT issue. Apple’s India strategy depends not only on capacity, labor, tariffs, and geopolitics, but also on whether new manufacturing partners can meet the data-security standards required for high-volume consumer electronics production.
Meanwhile, Tesla’s publicly reported exposure appears smaller than Apple’s, but the alleged file types are still commercially sensitive if authentic.
The reported Tesla-marked files concern manufacturing specifications, assembly information, a chargeport controller, and Project Highland material.
Tata’s statement that operations were unaffected answers one question. It does not answer the more expensive ones. The company still has to establish what was taken, how the attackers gained access, whether customer files were compromised, whether employee documents were exposed, whether the ransom demand was connected to authentic data, and whether the material has spread beyond the original dark web listing.