Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
4JUL

Leak crews squeeze Tata and Nidec

2 min read
11:00UTC

World Leaks dumped 630GB stolen from Tata Electronics, including purported Apple and Tesla design files, while Blackfield demanded $2m from Japan's Nidec.

TechnologyDeveloping
Key takeaway

Extortion crews are hitting suppliers whose most sensitive stolen data belongs to Apple and Tesla.

World Leaks posted more than 200,000 files, over 630GB, stolen from Tata Electronics to its leak site, including purported Apple manufacturing specifications and Tesla engineering drawings marked TRADE SECRET tied to Project Highland, the codename for the revamped Model 3. Tata restricted remote access to its purchase-order systems and hired a forensic consultant. 1 Separately, Blackfield demanded $2m from Nidec, the $17.2bn-revenue electric-motor maker, after breaching a Chaun Choung Technology server around 22 June, offering immediate download of the data for $400,000. 2

Both crews run the publish-or-pay leak-site play that Rhysida used against Stuttgart in May : steal the data, threaten to release it, name a price. World Leaks and Blackfield are aiming that tactic at tier-1 manufacturing suppliers whose chief assets are their customers' unreleased designs, which is what sharpens the leverage.

A supplier cannot indemnify Apple's product roadmap or Tesla's engineering choices, because the exposed value sits on a balance sheet that is not its own. That is what makes extortion at this layer so hard to price, and why restricting remote access, as Tata did, treats the symptom rather than the exposure.

Deep Analysis

In plain English

Some cyber-criminal groups no longer bother locking up a victim's computers with ransomware; instead, they steal huge amounts of confidential files and threaten to publish them unless paid. That is what happened to Tata Electronics, an Indian company that manufactures parts for Apple and, according to the leaked files, drawings related to a future Tesla car project. A group called World Leaks says it stole more than 200,000 files, around 630 gigabytes, some marked as trade secrets. Separately, another group called Blackfield demanded $2 million from Nidec, a Japanese electronics maker, after breaking into a server belonging to one of Nidec's smaller suppliers. Both cases show how criminals now target the weaker links in a big brand's supply chain rather than the brand itself, since a supplier is often easier to break into but still holds the brand's secrets.

Deep Analysis
Root Causes

World Leaks operates a pure data-extortion model, with no encryption payload, a deliberate shift by its operators, previously behind Hunters International, after ransomware-specific prosecutions and sanctions made deploying and monetising encryptors legally riskier than simply stealing and threatening to publish data.

Electronics contract manufacturers like Tata Electronics sit inside a dense subcontracting chain for Apple and Tesla, where design files marked confidential pass through several tiers of suppliers with uneven security standards. A breach at any one tier can expose a prime brand's intellectual property without the prime ever being directly compromised.

What could happen next?
  • Risk

    Apple and Tesla face reputational and intellectual-property exposure from a breach neither company suffered directly, illustrating how supply-chain leverage can reach a prime brand without compromising its own network.

  • Precedent

    World Leaks' pure data-extortion model, without an encryption payload, may signal more operators shifting away from encryptors as law-enforcement pressure on deploying and monetising malware increases.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

Business Standard· 4 Jul 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.