TL;DR
This week saw three major cyber incidents with direct lessons for every business: a ransomware group leaked 630 GB of Apple and Tesla supplier data from Tata Electronics, a supply chain attack through competitive intelligence platform Klue compromised customer data at hundreds of companies including LastPass and Huntress, and two Scattered Spider members were convicted for a $38 million attack on Transport for London. The common thread: attackers are targeting suppliers, integrations, and identity — not your perimeter.
1. Tata Electronics: Ransomware Leaks Apple and Tesla Trade Secrets
On June 22, Indian electronics manufacturer Tata Electronics confirmed a cybersecurity incident after ransomware group World Leaks published over 200,000 files totalling more than 630 GB on the dark web. The stolen data includes proprietary and confidential documents belonging to both Apple and Tesla — two of Tata's largest manufacturing clients.
The leaked files contain employee passport copies (including foreign nationals), multi-year event logs, manufacturing and component design specifications, and engineering drawings. A 52-page Apple document detailing quality inspection standards for iPhone circuit board components was among the files, carrying the footer "This document contains proprietary and confidential information of Apple Inc." Tesla files included a folder labelled "NV36 Chargeport Controller – North America" referencing components for an upgraded Model Y, plus engineering drawings for Project Highland — Tesla's codename for the revamped Model 3 — marked "TRADE SECRET" and dated 2023.
How bad is it: Tata Electronics manufactures approximately one-third of Apple's iPhone production in India. A single compromise exposed the intellectual property of multiple Fortune 500 clients simultaneously. This is the second major Tata Group incident — its subsidiary Jaguar Land Rover suffered ransomware in 2025 that halted production for six weeks.
How it could have been prevented: Supplier-side data isolation is critical. Tata should have segmented client data so that a single intrusion could not traverse across Apple, Tesla, and other customer environments. Encryption of trade-secret documents at rest, strict access controls on engineering repositories, and continuous monitoring for mass data exfiltration would have limited the blast radius. The fact that 630 GB left the network undetected suggests insufficient data loss prevention controls.
What your business should do: Map every third-party supplier that holds your intellectual property or customer data. Ask them: What segmentation exists between your data and other clients? What DLP controls monitor for exfiltration? If they cannot answer, you have a supply chain risk you do not control.
2. Klue Supply Chain Attack: When Your CRM Integration Becomes the Attack Vector
On June 23, competitive intelligence platform Klue disclosed a supply chain attack that compromised Salesforce customer data belonging to hundreds of organisations. The threat actor exploited a compromised Klue Battlecards app to access OAuth tokens used for third-party integrations, including Salesforce connections. From there, they exfiltrated CRM data — customer names, email addresses, phone numbers, physical addresses, support case data, and sales information — from every company that had Klue connected to their Salesforce instance.
The victims list reads like a cybersecurity industry directory: LastPass, Huntress, Recorded Future, Tanium, and others all confirmed customer data exposure. The threat group "Icarus" claimed responsibility and has begun directly contacting affected companies, threatening to publish their data unless ransoms are paid.
How bad is it: LastPass alone was fined £1.2 million by the UK Information Commissioner's Office in 2025 over its 2022 breach, which ultimately cost Ripple co-founder Chris Larsen $150 million in stolen cryptocurrency when attackers exploited vault data. This new Klue-related exposure adds another layer of customer data leakage for a company already under regulatory scrutiny.
How it could have been prevented: OAuth token scope was the root cause. The Klue app had OAuth tokens with broad read access to Salesforce objects — access far wider than what the app needed to function. Principle of least privilege on API tokens, regular token rotation, and monitoring of integration data access patterns would have either prevented the exfiltration or detected it far earlier. Salesforce has since disabled the Klue Battlecards app connection entirely.
What your business should do: Audit every OAuth-connected third-party app in your SaaS stack this week. In Salesforce, Microsoft 365, Google Workspace, and your CRM — review which apps have access, what data scopes they hold, and revoke any that are unnecessary or over-privileged. Set a calendar reminder to repeat this audit quarterly.
3. Scattered Spider Conviction: $38 Million TfL Attack Yields Guilty Verdict
On June 24, two members of the Scattered Spider hacking group were convicted for their roles in the Transport for London (TfL) attack, which caused approximately $38 million in damages. Scattered Spider, known for sophisticated social engineering and SIM-swapping attacks, has targeted major organisations including MGM Resorts, Caesars Entertainment, and Okta in recent years.
How bad is it: The TfL attack disrupted one of the world's largest public transport networks, compromised staff data, and required months of remediation. The $38 million figure covers direct response costs, system rebuilds, and operational disruption — a number that would bankrupt most small to medium businesses many times over.
How it could have been prevented: Scattered Spider's primary attack vector is social engineering — tricking help desk staff into resetting credentials or MFA tokens. The single most effective control against this attack pattern is mandatory callback verification for any password or MFA reset, combined with rigorous help desk training on social engineering indicators. Organisations that verify identity through a secondary channel before processing credential changes stop this attack cold.
What your business should do: Review your password reset and MFA enrolment procedures. If your IT help desk can process a credential reset based on a phone call or email alone — without callback verification — you are vulnerable to the same technique that cost TfL $38 million.
ISO 27001 SMB Starter Pack — $147
Threat intelligence is one thing — having the policies and controls to respond is another. Get the complete ISO 27001 starter kit for SMBs.
Get the Starter Pack →Weekend Action Items
Before Monday morning, take these three steps:
- Audit OAuth integrations — Pull the connected apps list from your critical SaaS platforms. Remove anything you do not recognise or no longer use. This takes 15 minutes and addresses the Klue attack pattern directly.
- Map your top five suppliers' security posture — Send a brief security questionnaire to your highest-risk vendors. Ask about segmentation, encryption, breach history, and incident response timelines.
- Tighten help desk verification — Add a mandatory callback step to your password and MFA reset procedures. Document it. Train staff on why it matters.
FAQ
Q: My business is too small to be targeted by ransomware groups. Should I still worry? A: Yes. Attackers like World Leaks and Scattered Spider target suppliers precisely because smaller organisations often have weaker controls but hold data belonging to larger clients. If you are in any enterprise's supply chain, you are a target.
Q: We use Salesforce. Was our data affected by the Klue breach? A: Only if your organisation had the Klue Battlecards app connected to your Salesforce instance. Check your Salesforce Setup under Connected Apps OAuth Usage. If Klue appears and you have not already been contacted, review your login history and data export logs for the period since June 11, 2026.
Q: What is the single most cost-effective security control for a small business? A: Multi-factor authentication on all external-facing accounts, combined with mandatory callback verification for credential resets. These two controls would have prevented or mitigated all three incidents covered this week.
Q: Should we be concerned about AI-enabled attacks? A: A Five Eyes joint statement this week warned that AI models capable of devastating automated attacks on governments and businesses are "months away." The immediate threat is AI-enhanced social engineering — phishing emails, deepfake voice calls, and synthetic identity attacks are already increasing. Staff awareness training is your first line of defence.
Conclusion
The pattern this week is unmistakable: attackers are not breaking down your front door. They are walking through your suppliers (Tata Electronics), your software integrations (Klue), and your help desk (Scattered Spider). The organisations that survive these attacks are the ones that assume breach and focus on limiting blast radius — segmenting data, minimising OAuth scopes, and verifying identity at every trust boundary.
Start with the three weekend action items above. They cost nothing but time and address the exact vulnerabilities exploited this week. If you need help assessing where your business stands, we can help.
Visit consult.lil.business for a free cybersecurity assessment.
References
- Tata Electronics Data Breach Exposes Confidential Apple and Tesla Documents — CyberSecurity News, June 23, 2026
- Klue Investigating Supply Chain Attack That Targeted Salesforce Integrations — Cybersecurity Dive, June 23, 2026
- LastPass Customer Info Leaked Again After Third-Party Data Breach — Protos, June 24, 2026
- Australian Cyber Security Centre (ACSC) — Essential Eight Mitigation Strategies — Australian Signals Directorate
- NIST Cybersecurity Framework 2.0 — National Institute of Standards and Technology