Apple’s iPhone 18 Pro leaked because a supplier got hacked

Apple’s iPhone 18 Pro leaked because a supplier got hacked

 

Every year, the next iPhone leaks. Usually it’s a blurry render, a case-maker’s CAD file, or a supply-chain whisper passed to a reliable tipster. This year is different. The most detailed look at the iPhone 18 Pro didn’t come from a leaker at all. It came from a ransomware group that broke into Tata Electronics, Apple’s largest iPhone assembler in India, and posted the stolen files on the dark web.

A group calling itself World Leaks claimed the breach on June 12, publishing more than 200,000 files totaling over 630GB, according to Reuters. Tata Electronics confirmed the incident and said it detected the intrusion on some systems a few weeks earlier. Apple said it’s concerned and is investigating. The iPhone 18 Pro isn’t due until September.

What was actually in the dump

The headline items are the ones Apple guards most closely. Reuters reviewed at least six files that map individual iPhone 18 Pro components to the specific suppliers that make them. Chips on the main logic board, battery parts, camera modules, each tied to a vendor.

That mapping is the sensitive part. Apple publishes an annual supplier list, but it never says which company builds which part for which model. The leaked files do exactly that. They also show where Apple leans on a single supplier for a critical part versus where it spreads orders across several, which is a clear read on Apple’s bargaining power and its pressure points. It’s the kind of intelligence a competitor or counterfeiter would normally spend years assembling.

The dump wasn’t Apple-only. Reuters and others found documents tied to Tesla, plus at least 16 files and folders linked to TSMC and 23 to Qualcomm. World Leaks appears to have grabbed whatever it could reach inside Tata’s network rather than targeting Apple specifically.

The specs the leak locked in

 Diagram comparing Apple's new WMCM chip packaging to the older InFO-PoP design, beside a leaked iPhone 18 Pro spec sheet.
How the leaked files describe the A20 Pro‘s new WMCM packaging, and the specs they confirmed. Illustration: techinsightzone

Buried in the files were details on the phone’s internals, and a few of them settle rumors that had been floating for months.

The A20 Pro chip, codenamed Borneo, is the star. According to AppleInsider’s analysis of the documents, it’s built on TSMC’s first-generation 2nm process and uses a new packaging design called WMCM, short for Wafer-Level Multi-Chip Module.

In plain terms, that means the CPU, GPU, and Neural Engine sit side by side on separate dies instead of being stacked with memory on top, the way Apple’s current InFO-PoP design does. Apple’s own internal projections in the files claim up to 15 percent more performance and 30 percent better power efficiency over the last generation.

That packaging change isn’t just trivia. Apple Insider’s read of the schematics shows the chip pushed toward the outer edge of a dual-layer logic board, with storage tucked deeper between the layers. That layout affects how heat moves through the phone and how repairable it is. Both matter to anyone who’s watched Apple fight thermal throttling on recent Pro models. [link to prior coverage]

The modem question got answered too. The files confirm Apple’s in-house C2 modem, codenamed Ganymede. But there’s a twist: analysis reported by Apple Insider points to a regional split, with US models keeping a Qualcomm modem for mm Wave 5G while international units get the Apple C2.

Beyond that, the leak points to LPDDR6 memory on a 96-bit bus with 12GB of RAM, and a redesigned 48-megapixel main camera with a variable aperture that forces a thicker back panel. There’s even a single passing reference to the foldable iPhone, codenamed V68.

The photos Apple tried to pull down

Specs are one thing. Photos of an unreleased phone are another, and those leaked too.

Images and short videos dated to early 2026 show what appear to be iPhone 18 Pro units getting drop-tested inside a Tata facility. The devices are flat and silver-gray, with a more uniform rear design than the current two-tone Pro. The clips first spread through an account using the @EvLeaks handle and got reposted by the leaker known as Ice Universe.

Apple has been chasing them down. The company filed takedown requests to pull the drop-test footage, which tells you how badly it wanted these particular files to stay buried. And some of the leaked configuration files had their color options redacted because of NDAs, a sign Tata took stricter-than-usual precautions on the newest model even as older iPhone data spilled out more freely.

Why this landed on India, not just Apple

 Bar chart showing Tata's $26.3B in India-made iPhone exports narrowly ahead of Foxconn's $25.6B, FY22 to FY26.
India-made iPhone exports, FY22–FY26. Tata now assembles roughly a quarter of all iPhones worldwide. Chart: techinsightzone

Here’s the part that turns a product leak into a bigger story. Tata now assembles more than a quarter of all iPhones sold worldwide. Vendor data submitted to India’s government showed Tata exported India-made iPhones worth $26.3 billion between FY22 and FY26, edging past Foxconn’s $25.6 billion.

That’s the payoff of Apple’s long push to move production out of China. It’s also what makes this breach sting. Apple spent years de-risking its supply chain geographically, and the reward was a fresh digital attack surface at the edge of that chain. The secret didn’t walk out of Cupertino. It walked out of a contractor’s network in India.

Security researchers made the same point. Speaking to Al Jazeera, one analyst said a breach this size usually isn’t a smash-and-grab, and that pulling this much data means the attackers had a real foothold inside the organization. His larger argument was simple: a supply chain is only as secure as its weakest supplier, and that supplier doesn’t have to be Apple. It just has to touch Apple.

Where the investigation stands now

The immediate panic has cooled. India’s government confirmed a formal probe, with the incident reported to CERT-In, the country’s computer emergency response team. On July 13, IT Secretary S. Krishnan said the assessment had found no evidence of critical information loss so far, and that both companies were satisfied they hadn’t lost much on commercial terms. The evaluation is still ongoing.

Tata says it restricted internal access, brought in an outside cybersecurity firm for a forensic review, and notified affected customers. Its manufacturing never stopped. That fits World Leaks’ playbook. The group is a data-extortion operation that skips file encryption entirely, a rebrand of the older Hunters International crew, which itself traced back to the disrupted Hive ransomware operation. It hit Nike before this.

The leak Apple can’t blame on a hacker

iPhone 18 Pro with a CONFIDENTIAL stamp, marking the Tata Electronics breach that leaked Apple's supply-chain data.
(social card — usually no visible caption needed)

The Tata breach isn’t the only supply-chain secret bleeding out of Apple right now. On July 10, Apple sued OpenAI in federal court in California, accusing it of trade-secret theft tied to its hardware ambitions.

The complaint names OpenAI’s chief hardware officer Tang Tan, a 24-year Apple veteran, and former Apple engineer Chang Liu, who Apple says kept a company laptop and used it to pull confidential files on unreleased products. Apple’s language is blunt.

The complaint says the alleged conduct ran through OpenAI at every level and calls the company “rotten to its core.” OpenAI denies it, saying it has no interest in other companies’ trade secrets.

Put the two stories side by side and a pattern shows up. One secret got stolen from the outside by hackers. The other, Apple alleges, walked out the door with people. Both point at the same weakness: the more hands a product passes through, the harder its secrets are to keep.

What to watch next

The iPhone 18 Pro still launches in September, and now it launches with its headline specs already public. That changes the keynote math for a company that sells surprise as hard as it sells silicon. Watch whether CERT-In’s final assessment stays as calm as its July update, and whether any of those leaked supplier maps start turning up in counterfeit parts or competitor teardowns.

The hardware was always going to ship. The real question is what a rival does with a blueprint it didn’t have to earn.

Leave a Reply

Your email address will not be published. Required fields are marked *