Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster


One of Apple's key manufacturing partners in India has confirmed it was recently the target of a cyberattack that has resulted in confidential Apple documents being leaked on the dark web.

apple-education-hub-india-factory.jpg

Tata Electronics said on Monday it had detected a "cybersecurity incident," after security researchers told Reuters that ransom group World Leaks had shared more than 200,000 files belonging to Apple and Tesla, both of which are customers of the Indian group.
"A few weeks ago, Tata Electronics identified a cybersecurity incident on some of our systems. Our response protocols were deployed immediately, and the incident has had no impact on our operations across businesses, which remain unaffected," Tata Electronics told Reuters in a statement.
Apple has not commented on the leak, but a source familiar with the matter told the outlet that Apple was investigating the breach and a "full analysis was going on." Tata is believed to have received a ransom demand related to the incident, but the group declined to comment.

Many of the leaked files allegedly contain component design and specification papers. For example, one 52-page document has Apple's proprietary markings and purportedly details quality inspection standards ⁠for iPhone circuit board components. The files are ⁠also said to contain emails, event logs spanning several years, and passport copies of employees including foreign nationals.

Reuters wasn't able to independently verify the documents, which have been available on the dark web – which is beyond the reach of search engines – since at least June 10, according to researchers.

Tata is emerging as one of Apple's most important manufacturing partners outside China, and the breach is another setback for the group. It is also currently facing a health probe over alleged contamination of farmlands near one of its iPhone parts plants.

Article Link: Confidential Apple Files Leaked on Dark Web After Supplier Cyberattack
 
Truly pointless theft. Other than gossiping about leaked schematics.

The 3 or 4 factories that can develop any of the stolen plans into finished product are all under contract to the original IP owners either way.
 
any factory software, or just boring schematics? 👀

i'd love to see some more com.apple.ist.* things in my life.
 
What is the dark web, and what is its URL?

Where does someone who wants to access this dark web even go?

Stop using hand-wavy terms and be specific. No way to verify any of the claims made here without a direct link and citation of the source. Writing is going downhill!
Why would MR want to be liable for disclosing how to find illegal content? If you really cared that much, I'd sure a smart person like you could figure it out.
 
Sounds like the confidential documents spill the beans on the proprietary methods Apple uses to take forever to release anything new. Maybe actual details on how just popping in a new chip and leaving everything else the same, makes it a brand new model! Some really secretive stuff here...
 
  • Like
Reactions: Lukomaldini

While writing about a data leak is protected under the first amendment, the legal landscape changes when you provide a functional link to the source files. Plaintiffs and prosecutors can weaponize several US statutes:

1. Computer Fraud and Abuse Act (CFAA)
A hyperlink to a repository of stolen data (such as a hacker's website or an open cloud storage bucket) can be interpreted as "conspiracy" or "aiding and abetting" a computer intrusion.
By providing a direct path to the data, a news organization might be seen as actively facilitating unauthorized access to protected computers.

2. Defend Trade Secrets Act (DTSA) & State Laws
If the leaked content contains proprietary corporate data, trade secrets, or intellectual property, linking to it can trigger civil claims for misappropriation of trade secrets.
While reporting on corporate malfeasance is protected, providing a link that allows competitors or the public to easily download corporate source code, blueprints, or internal strategies crosses into commercial harm.

3. Copyright Infringement (Contributory Liability)
If the leak contains copyrighted material, linking to it can expose the publication to contributory copyright infringement.
US courts have ruled that knowingly linking to a website that hosts infringing material to help users access it can constitute infringement, even if the news site doesn't host the files.
 
I have come close to giving up on any sort of trust in any company protecting data, mine or theirs.

I have had my personal data stolen probably 7 times in the last 5 years from 3rd parties that stored that data for health care facilities and other businesses.
 
I have come close to giving up on any sort of trust in any company protecting data, mine or theirs.

I have had my personal data stolen probably 7 times in the last 5 years from 3rd parties that stored that data for health care facilities and other businesses.
Pretty much this. Once things went digital, it was game over for privacy and security and so much more.
 
  • Like
Reactions: SFjohn and FatLouie
Pretty much this. Once things went digital, it was game over for privacy and security and so much more.
I don't think the issue is digital specifically, the issue is internet services. Back in my day criminals would have to physically and geographically infiltrate computers to steal their secrets. Now hackers sit on their fat asses from their homes eating cheetos. 😉
 
Wow, that's awful. No wonder Apple is slowly developing things in-house.
Developing in house changes nothing. They still have to share those documents with the factories or else each will make an iphone to different specs. Until Apple start manufacturing in house, this will always be a risk.
 
Back in 2009
I don't think the issue is digital specifically, the issue is internet services. Back in my day criminals would have to physically and geographically infiltrate computers to steal their secrets. Now hackers sit on their fat asses from their homes eating cheetos. 😉
Back in 2009 I holidayed in Utah for the new year with my then partner and met a few of his friends, one of whom worked for McAfee. After many drinks I jokingly said I wonder how all these people making viruses and malware make their money as it’s a time consuming game of cat and mouse. I insinuated the antivirus guys were funding the viruses and malware to create demand. He looked at me and just took a large swig of Guinness. To this day, I don’t know if he was being sarcastic or not.

It always made me wonder how these people support themselves financially when most of the time they’re not gaining anything from their work - unless they’re privately funded esp government intelligence operations (and as former intelligence that is absolutely true).

It’s capitalism - without increased demand profits drop. Basic supply and demand.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.