A ransomware attack on Tata Electronics has exposed confidential details about Apple's upcoming iPhone 18 Pro, including supplier lists, component specifications, and photos of the devices during drop tests, according to Reuters reporting confirmed by multiple outlets.
The Breach
The cyberattack, claimed by the ransomware group World Leaks, first surfaced on June 10 when the group posted more than 200,000 files totaling over 630 gigabytes of data on the dark web. Tata Electronics, an Indian electronics and semiconductor manufacturer that serves as a key supplier to Apple and Tesla, confirmed the incident in late June, stating it had detected the breach "a few weeks ago" and immediately activated its response protocols.
A review of the leaked files by Reuters found at least six documents that map iPhone 18 Pro and iPhone 18 Pro Max components to their specific suppliers, detailing chips on the main circuit board, battery parts, and camera modules. The documents reportedly carry confidential Apple watermarks and internal codenames, and include images of the phones during drop tests. In total, hundreds of parts for the upcoming Pro models are detailed in the leak, revealing where Apple sources components from multiple vendors versus single suppliers.
Response and Fallout
Tata Electronics stressed that operations remained unaffected by the incident but has since tightened security controls. The company restricted remote access to sensitive internal tools such as purchasing systems and hired a global consultant to conduct a forensic audit. Tata also notified the Indian government about the intrusion.
Apple is "concerned" about the leak and is investigating the incident while coordinating with Tata on both immediate and long-term security measures, according to MacRumors citing Reuters. The breach also exposed documents reportedly linked to TSMC and Qualcomm, as well as Tesla engineering drawings.
Wider Implications
The incident strikes at the heart of Apple's supply chain diversification strategy. Tata Electronics has become central to Apple's efforts to shift manufacturing away from China to India, making the breach particularly sensitive. Beyond product secrets, the leaked cache reportedly includes employee emails, system logs, and passport copies of staff, raising additional privacy concerns. Reuters reported that a ransom demand was made to Tata Electronics, though the company has not publicly commented on whether it engaged with the attackers.