Apple suffered a major data breach in June after an attack on Tata Electronics, its Bengaluru partner for iPhone components and assembly, with more than 200,000 files exposed on the dark web — an incident analysts are calling the largest leak in the company’s history. The scale of the breach raises a critical question: can India not only scale up production, but also guarantee the security and trust required to replace China in global supply chains?
The biggest Apple leak to date
In June, the hacking group World Leaks posted over 200,000 files originating from Tata Electronics on the dark web. The content of the documents and the exfiltration techniques used led industry observers to label the incident the largest Apple-related leak reported so far. Tata Electronics is a key partner for iPhone parts and assembly in the Bengaluru region.
A strategic bet under scrutiny
In February 2023, Tim Cook made clear that Apple’s India strategy would mirror the China model — combining retail and manufacturing to capture a fast-growing market. The shift to India was also driven by geopolitics: reducing exposure to trade tensions and potential tariffs on China-made products. Counterpoint Research data showed India producing roughly 6% of iPhones in 2022 and projected to exceed 25% by 2026. Foxconn, Tata and other suppliers have ramped up output, supported by government incentives.
Security gaps highlighted by experts
Christopher Tang, a professor of global supply chain management at UCLA, says India has proven it can scale production but must now “prove it can scale trust.” Tang points to three critical areas exposed by the breach: information governance, supplier discipline, and cyber-operational integration. In short, industrial capacity alone isn’t enough if data controls and supply-chain security practices lag behind.
What the leak means for China diversification
The incident is a reality check for companies looking to reduce dependence on China. It doesn’t negate India’s manufacturing capabilities, but it does spotlight operational and digital-security risks accompanying onshoring or nearshoring. In the short term, decision-makers may postpone sensitive transfers, demand concrete remediation from suppliers, or ramp up cyber audits and contractual security requirements. Over the medium term, companies and governments are likely to push for stronger cybersecurity standards, tighter governance of supplier ecosystems, and increased investment in secure operational integration to restore confidence in alternative supply bases.

