The documents surfaced on the dark web with the precision of a corporate filing: supplier confidentiality lists, component specifications and a map of which vendor builds which part of a phone Apple has not announced. The files, stolen from Tata Electronics, the Indian conglomerate’s contract manufacturing arm, are now the subject of a government investigation, according to Reuters, which first reported the probe.
Indian authorities have opened an inquiry into the data breach, which exposed confidential supplier documents related to the production of Apple’s iPhone 18 Pro. The stolen material includes information about the companies that make the phone’s components and the specifications those suppliers work to, and it has been circulating in full on the dark web rather than being held for ransom, according to people familiar with the matter.
The breach is the second major leak from Apple’s supply chain in roughly a year. Confidential Apple documents were first exposed last July, and security researchers said at the time that the volume of material suggested an attacker with deep access to vendor systems. The new incident, involving Tata Electronics, shows that the problem has not been solved; it has moved.
Tata Electronics has become central to Apple’s India strategy. The conglomerate operates a plant in Hosur, in the southern state of Tamil Nadu, that assembles iPhones, and it has been expanding its role from components toward full device manufacturing as Apple shifts production away from China. The company has described its relationship with Apple as a partnership, and the breach lands at a sensitive moment in that relationship.
The timing compounds the damage. The iPhone 18 Pro has not been announced, and Apple treats unreleased product details as among its most closely guarded secrets. The leaked documents describe not just the phone itself but the structure of Apple’s sourcing decisions, information that competitors, component makers and copycat manufacturers would all find useful.
The leak’s form is notable. The documents were posted openly rather than held behind a ransom demand, which security researchers said suggests either a group seeking notoriety, one that already failed to extract payment, or one with motives beyond money. The distinction matters for the investigation, because it affects how the attackers are likely to behave and what they might release next.
The investigation will focus on how the attackers got in and how long they were inside. Security researchers who examined the posted files said the material appeared genuine, and that the depth of the haul suggested access that predated the public leak by some time. Indian authorities have not said which agency is leading the probe or what enforcement tools they plan to use.
The case tests India’s ability to police the supply chain it is trying to build. The government has courted Apple and other manufacturers with subsidies and infrastructure, positioning India as the next hub of global device production. A high-profile breach at a flagship supplier raises questions about the security practices that come with that expansion, and about whether Indian law enforcement can investigate digital crimes of this complexity.
The incident also exposes the limits of Apple’s control. The company audits its suppliers and requires strict confidentiality agreements, but it cannot watch every server in every factory across every country. The two breaches in a year have prompted questions inside the industry about whether Apple’s model of sharing detailed technical information with manufacturers, necessary for them to build its products, has reached the limits of what any security program can protect.
Apple has not commented publicly on the breach, and Tata Electronics has said it is cooperating with authorities. People familiar with Apple’s practices said the company would expect a detailed accounting of how the data was exfiltrated, and that it has been pressing suppliers to tighten access controls since last year’s incident.
The broader industry is watching for a pattern. Apple’s manufacturing network spans dozens of companies across several countries, and each one holds sensitive data about products in development. Security experts have argued for years that the weakest link in any hardware launch is the supplier base, and the two breaches in a year lend weight to that argument.
For Tata, the stakes are commercial as well as legal. The company has been expanding its Apple business, and its position as a trusted partner depends on secrecy as much as on manufacturing skill. A second leak, at any supplier, would give Apple reason to reconsider how much of its roadmap it shares, and where it draws the boundaries of its confidence.
The July leak last year was dismissed by some as a one-off, the work of an unusually skilled attacker. The Tata breach suggests otherwise, and the Indian government’s decision to investigate signals that the stakes are now understood beyond Apple’s own security teams. The documents are out; the question is what happens to the information they contain, and to the supply chain that let them escape.
The investigation is early, and the outcome uncertain. The files are already public, the damage already done. What the probe will determine is who is accountable, and whether India’s ambition to host the world’s device manufacturing is matched by the security apparatus such a role requires.


