International Threats: Major Tech Supplier Tata Electronics Suffers Data Breach Exposing Apple And Tesla Data
May - June 2026

Tata Electronics confirmed a cyber incident affecting some of its systems after the extortion group, ‘World Leaks’, claimed it had stolen and published more than 200,000 files. The alleged 630GB data set reportedly included engineering documents, manufacturing specifications, emails, system logs, and employee records. However, the company stated that response protocols were activated immediately and that business operations remained unaffected.
Researchers reviewing the leaked data identified documents appearing to contain confidential information belonging to Apple and Tesla. The Apple-related files included manufacturing and quality inspection documentation for iPhone components, while the Tesla-related material appeared to contain engineering drawings and component specifications. Employee passports and other sensitive operational information were also exposed.
Tata Electronics has not disclosed how the attackers gained access, which systems were affected, or whether the incident directly led to the alleged data exposure. World Leaks reportedly issued a ransom demand before releasing the files via its darkweb leak site. Unlike traditional ransomware attacks that encrypt systems, this incident appears to have focused primarily on data theft and extortion.
The incident serves as a reminder of the cyber security risks associated with global supply chains. As a major manufacturing partner for Apple and supplier to Tesla, a compromise of Tata Electronics could expose information belonging to multiple organisations. Even where companies maintain strong internal security controls, sensitive information may still be at risk when shared with suppliers and other trusted third parties.
Organisations should treat suppliers with access to sensitive information as an extension of their security environment. Controls should include due diligence, clearly defined security requirements, restrictions on supplier access, and regular reviews. Organisations should also understand what information is held by third parties and ensure contracts provide clear arrangements for incident notification, investigation, and recovery. While supplier incidents may not disrupt operations directly, the exposure of intellectual property, personal information, or internal documentation can still lead to fraud, impersonation, and further targeted attacks.
Vishing Scam Causes Aurora to Lose Nearly $1.1 Million from City Bank Accounts
The City of Aurora in the United States lost nearly US$1.1 million from its payroll bank accounts after an employee received a phone call from an attacker impersonating a bank representative. The caller appeared legitimate and created a false sense of urgency, persuading the employee to disclose sensitive account information that was subsequently used to make fraudulent transfers from the city’s accounts.
City officials became aware of the fraudulent payments shortly after the transactions occurred and immediately began efforts to limit the impact and recover the funds. Law enforcement and the city’s financial institution were notified, while external cyber security specialists were brought in to support the investigation. Authorities are working with financial institutions to identify those responsible and recover as much of the stolen money as possible. The city also maintains insurance intended to help reduce financial losses from incidents of this kind.
Officials stated that there was no evidence the city’s network or data systems had been compromised. However, the financial institution was conducting a forensic audit to establish whether any employee information held on its systems had been affected. The city said employees would be notified promptly if the investigation found that their information had been exposed.
The incident demonstrates how social engineering and vishing attempts can bypass technical protections by targeting people rather than systems. Fraudsters may impersonate banks or other trusted contacts and pressure victims into sharing account details, credentials, security codes, or information needed to authorise payments. A convincing caller and an urgent request can make it difficult for employees to recognise the warning signs, particularly where the attacker already possesses information about the organisation.
Organisations should require independent verification of unexpected financial requests using trusted contact details, particularly where sensitive information or payments are involved. Strong approval processes, transaction alerts, transfer limits, and separation of financial duties can reduce the risk of a single employee authorising or enabling fraudulent activity. Staff should also receive regular training on vishing tactics and be encouraged to pause, challenge urgent requests, and report suspicious calls immediately.