03 Indian Manufacturers, 03 Ransomware Attacks. The Attacker Never Went to the Factory.

The Silent Breach infographic by Skeletos IT Services showing how ransomware targets India's technology subsidiaries across 18 months and three confirmed attacks: January 2025 Tata Technologies IT assets, June 2026 Tata Electronics Apple specifications, and June 2026 Bajaj Auto IT and BATL, with attacker logic diagram showing technology subsidiaries as selected target due to connections to global OEM clients parent company IT vendors and partners and cloud infrastructure, architecture gap analysis covering lack of enforced segmentation poor IP classification slow or no real-time visibility and ineffective incident response, and five actions Indian manufacturing CTOs must take including govern tech subsidiaries independently, enforce architectural segmentation with EasyNAC, classify IP by sensitivity, test incident response plans regularly, and audit vendor and OEM contracts.

Share This Post

On a Tuesday morning in January 2025, Tata Technologies filed a regulatory disclosure with the National Stock Exchange of India regarding a ransomware attack.

The filing, submitted under Regulation 30 of SEBI’s Listing Obligations and Disclosure Requirements, stated: “The Company has become aware of a ransomware incident that has affected a few of our IT assets. As a precautionary measure, some IT services were temporarily suspended and have now been restored. Our Client delivery services have remained fully functional and unaffected throughout.”

The response was professional and fast. The SEBI filing was made. External cybersecurity experts were brought in. IT systems were restored. Client delivery continued without interruption.

Two months later, in March 2025, the Hunters International ransomware group published 1.4 terabytes of data on their dark web leak site. The dataset contained 730,000 files. Excel spreadsheets. PowerPoint presentations. PDFs of purchase orders and client agreements information about current and former Tata Technologies employees.

The professional response had not determined the outcome. The architecture that allowed the breach had.

Seventeen months after Tata Technologies filed with the NSE, Tata Electronics confirmed a cybersecurity incident on June 22, 2026. World Leaks, a separate ransomware group, had posted 630 gigabytes of data, including Apple manufacturing specifications and Tesla engineering documents marked as trade secrets.

One day later, on June 23, 2026, Bajaj Auto filed with BSE and NSE confirming ransomware affecting its primary IT infrastructure and its technology subsidiary BATL. Shares fell 2% before the trading session closed.

Three confirmed ransomware attacks. Eighteen months. Three of India’s most recognised manufacturing groups.

The attacker in each case did not go to the factory floor.


The Target They Keep Choosing

Look at what was actually hit in each of the three incidents.

  • Tata Technologies is not a factory. It is the engineering and digital solutions arm of Tata Motors, the entity that provides product development, digital transformation, and IT services to automotive, aerospace, and industrial original equipment manufacturers across 27 countries. It is the intellectual engine behind the manufacturing operations of some of the world’s largest vehicle makers.
  • Tata Electronics is not just a factory either. It is the entity that manufactures Apple iPhones and holds the production documentation, quality specifications, technical drawings, and process data that Apple and Tesla have entrusted to their Indian manufacturing partner. It is a node in the global technology supply chain, not just an assembly building.
  • Bajaj Auto Technology Limited is Bajaj Auto’s technology subsidiary, responsible for engineering, research and development, and the digital systems that connect corporate IT to the factory floor. It is the layer between the business and the production line.

None of these are the factory. All three are the technology layer that makes the factory work, that holds the intellectual property that makes the factory valuable, and that connects the manufacturing operation to its global clients.

This is the selection logic that ransomware groups have understood and that their victims have been slower to recognise. The factory floor has hardened over years of operational technology security investment. The production systems are isolated, air-gapped where possible, and monitored by teams that take physical security seriously. But the technology subsidiary, the engineering services arm, the digital transformation unit: these entities often sit in a security gap between the OT security model and the enterprise IT security model. They are too IT-intensive to be governed by OT security frameworks alone. They hold too much sensitive IP to be governed by standard enterprise IT security frameworks. And they are connected to both the parent company’s corporate network and the clients whose data they hold.

The attacker goes where the data is most valuable and the security is least mature. For India’s manufacturing conglomerates in 2025 and 2026, that intersection is the technology subsidiary every time.


The Hunters International Lineage and What It Reveals

The Tata Technologies attack carries a specific thread that is worth pulling.

Hunters International is widely believed to be a rebrand of the Hive ransomware gang, which was disrupted by the FBI and European law enforcement agencies in 2023. This matters because Hive had previously targeted Tata Power in 2022, leaking stolen data after ransom negotiations failed.

The sequence is: Hive targets Tata Power in 2022. Law enforcement disrupts Hive in 2023. The group re-emerges as Hunters International. Hunters International targets Tata Technologies in January 2025.

The same ransomware group family, operating under a different name after law enforcement disruption, returned to the same conglomerate within three years. This is not a coincidence. It reflects a deliberate pattern of researching and targeting organisations that have previously demonstrated vulnerability and value.

The industrial sector was the most attacked in 2024. Tata Technologies’ breach exemplifies the ongoing risk.

The implication for Indian manufacturing conglomerates is uncomfortable but important. A ransomware attack that is successfully contained and recovered from is not a closed chapter. It is a documented proof of concept that the organisation holds data worth stealing and has pathways that can be exploited. Other groups see the same leak site claims. The same internal connections. The same supply chain relationships.

A successfully contained ransomware incident that does not result in a fundamental security architecture review is a breach with consequences that extend beyond the initial incident.


Three Attacks, Three Lessons

Each of the three confirmed incidents teaches a specific lesson that applies across India’s manufacturing sector.

  • Tata Technologies: The technology subsidiary carries more risk than its security posture reflects.

Tata Technologies serves automotive and aerospace OEMs across 27 countries. Its work product is engineering IP: design files, product specifications, client project documentation, process methodologies. This is extraordinarily sensitive data from the perspective of the global clients whose products depend on it.

The security posture applied to that data was commensurate with a professional IT services company, not with a custodian of global automotive and aerospace intellectual property. The gap between the sensitivity of what was stored and the security governance applied to how it was stored is what Hunters International found and used.

    • The lesson: A technology subsidiary that handles global OEM data must be governed to a security standard proportionate to the most sensitive data it holds, not to the average standard of its industry category.
  • Tata Electronics: Supply chain IP is only as secure as the contractor’s network.

Apple’s manufacturing specifications and Tesla’s engineering drawings are marked as trade secrets. Both companies invest heavily in protecting this IP within their own operations. When that IP moves to a contract manufacturer’s network in India, it carries whatever security that manufacturer has built around it.

World Leaks found the gap between what the IP required and what the network provided. They extracted 630 gigabytes before detection. The Apple and Tesla IP that leaked did not leave Apple’s or Tesla’s own systems. It left the system of the partner they trusted to build their products.

    • The lesson: Every global OEM IP holder that uses Indian contract manufacturers must treat the contractor’s network security as an extension of their own IP protection programme. Indian manufacturers must treat the security of their network as a client service obligation, not just an internal IT matter.
  • Bajaj Auto BATL: IT and OT convergence is the attack path, not the production floor.

Bajaj Auto’s core production line was not encrypted. Vehicles continued to be manufactured. But the technology subsidiary that manages the digital layer between corporate IT and the factory floor was compromised. The ransomware spread from the IT environment into BATL because the connection between them was not adequately governed.

    • The lesson: Segmentation between corporate IT and technology subsidiaries, and between technology subsidiaries and operational technology, is the specific architectural control that limits how far a ransomware attack can travel. EasyNAC provides the network access governance layer that makes those boundaries enforceable rather than theoretical.

The Security Architecture Gap That All Three Incidents Share

Reading the three incidents together, a common structural failure emerges.

The technology subsidiary in each case was connected to:

  • The parent company’s corporate IT network
  • Global client systems and data environments
  • Vendor and partner networks
  • Cloud infrastructure for project delivery

These connections exist because they are operationally necessary. A technology subsidiary cannot do its work without connecting to the systems it serves and the clients it supports.

What was missing in each case was governance of those connections proportionate to what they protect. Specifically:

  • Network segmentation that enforces boundaries, not just policies. A segmentation policy written in a document and a segmentation boundary enforced at the network layer are fundamentally different things. The former describes where data should not go. The latter prevents it from going there. In all three incidents, the ransomware moved from its initial entry point across network boundaries that policy described, but architecture did not enforce.
  • Real-time visibility of every device and connection. In the Tata Technologies case, the Hunters International group had access to the network before the company was aware. In the Tata Electronics case, World Leaks had assembled 630 gigabytes before detection. In the Bajaj Auto case, ransomware was spreading through the BATL network before the 8 AM detection. In every case, the attacker had time because detection was not real-time.

A network access control layer that identifies every device connected to the environment the moment it connects, flags unusual connection patterns between network segments, and monitors East-West traffic within the technology subsidiary’s environment does not prevent every breach. It compresses the window between intrusion and detection. That compression is what changes the outcome.

  • IP classification that triggers specific handling requirements. Engineering drawings, product specifications, client design files, and manufacturing process documentation are not the same category of data as email or shared drives. They require classification, access control, and handling requirements that reflect their actual sensitivity. In each of the three incidents, some of the most valuable data on earth Apple’s iPhone manufacturing specifications, Tesla’s trade-secret engineering drawings, and Tata Technologies’ automotive client project data was stored in environments whose security posture did not reflect that value.

The Broader Manufacturing Sector Risk in India

These three incidents are not isolated events in an otherwise secure landscape. They are documented examples of a pattern that extends across India’s entire manufacturing sector.

India’s manufacturing output is growing rapidly. Digital transformation in manufacturing, the very investments that create technology subsidiaries and digital product development arms, is accelerating. Global OEMs are shifting more production to India, bringing their most sensitive IP with them. And the attack surface that this creates is growing faster than the security governance applied to it.

The World Economic Forum’s Global Risk Report 2026 ranks cybersecurity as India’s number one national risk, above economic downturns, climate-related disasters, and armed conflict. That ranking reflects what regulators, risk assessors, and now three confirmed breach victims have demonstrated across 2025 and 2026.

India’s manufacturing sector is uniquely exposed because of its position in global supply chains. An Indian automotive components manufacturer holds designs from a European OEM. An Indian electronics manufacturer holds specifications from an American technology company. An Indian engineering services firm holds product development files from a Japanese aerospace company. All of that IP is only as secure as the Indian company’s network.

Ransomware groups understand this. They understand that one successful breach of an Indian technology subsidiary can yield IP from multiple global clients simultaneously. The data density per successful attack is higher at an Indian manufacturing conglomerate’s technology subsidiary than at most other categories of target.


What Indian Manufacturing CTOs Must Do Now

The pattern across three confirmed incidents points to specific, operational priorities.

  • Govern technology subsidiaries as distinct security entities with their own posture assessments. A technology subsidiary connected to the parent company’s corporate network should have its own security posture assessment, separate from the parent company’s. The subsidiary’s connections to clients, vendors, and cloud services create an exposure profile that is different from the parent’s. That exposure profile requires its own assessment, its own controls, and its own monitoring.
  • Enforce segmentation between parent company, technology subsidiary, and OT environments at the architecture level. Not as policy. As enforced network boundaries. Every connection between the parent company’s corporate network and the technology subsidiary should be visible, governed, and audited. Every connection between the technology subsidiary and the operational technology environment should require specific, documented authorisation. EasyNAC provides the network-level visibility and access enforcement that makes these boundaries real rather than aspirational.
  • Classify IP by its actual sensitivity and apply proportionate controls. Engineering documents, client specifications, and manufacturing process files should not live in the same security tier as general corporate documents. An IP classification framework that identifies the most sensitive data categories, restricts access to specific, named individuals, logs all access events, and monitors for bulk exports or unusual access patterns reduces the data exposure in any breach that occurs.
  • Build and test an incident response plan specific to the technology subsidiary environment. As we covered in our tested incident response plan blog, a plan that has never been tested is not a capability. For technology subsidiaries specifically, the IR plan must cover SEBI disclosure timelines, client notification requirements where OEM IP may have been accessed, and forensic preservation that maintains the evidence needed to determine the full scope of data access.
  • Review contracts with global OEM clients for security requirements and audit rights. The Tata Electronics incident makes this especially urgent. If your company holds IP from global OEM clients under manufacturing or engineering services agreements, those clients are now evaluating whether their IP is adequately protected in your environment. Getting ahead of that evaluation, conducting your own assessment and communicating the results proactively, is the stronger commercial position.
  • Commission an independent security assessment of the technology subsidiary specifically. Not a general corporate VAPT. A specific assessment of the technology subsidiary’s network architecture, its connections to parent and client systems, the data it holds and how that data is classified and protected, and whether the current security posture matches the sensitivity of what it holds. The gap between those two is what Hunters International, World Leaks, and the unidentified Bajaj attacker found and used.

The Pattern Will Continue Without Architectural Change

The three incidents described in this blog span 18 months. The pattern they represent is not new. Tata Power was hit by Hive ransomware in 2022. Jaguar Land Rover, owned by Tata Motors, suffered a significant cyberattack in 2024. The frequency and severity of attacks on India’s manufacturing conglomerates have been increasing every year during this period.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment undetected.

The implication of that statistic is that the three confirmed incidents represent a visible fraction of the actual attack activity targeting India’s manufacturing sector. For every confirmed SEBI filing, there are incidents that never reached the regulatory disclosure threshold, were contained before full exfiltration, or were not publicly disclosed.

The organisations that will navigate the next 18 months better than the last 18 months are not necessarily the ones that invest more in security tools. They are the ones that invest differently. Specifically, in the architecture that makes technology subsidiaries defensible: network segmentation that is enforced rather than described, device visibility that is real-time rather than periodic, IP classification that matches the actual sensitivity of what is held, and an incident response capability that is practiced rather than documented.

The attacker’s logic is consistent. They will keep going to the technology subsidiary because that is where the valuable data is, and the security is thinnest. The question for every Indian manufacturing CTO is not whether they will be targeted. It is whether the architecture they have built will determine the outcome differently than it did for the three organisations that filed with BSE and NSE in 2025 and 2026.


Final Thought

The Tata Technologies SEBI filing was textbook. Fast, accurate, appropriately scoped. The external investigation was engaged immediately. Client delivery continued. IT systems were restored.

Two months later, 730,000 files were on the dark web.

The response was right. The architecture that made the response necessary was the problem.

India’s manufacturing sector is not going to become less connected. The technology subsidiaries are not going to hold less sensitive data. The global OEM relationships are not going to become less complex. The direction of travel on all of these dimensions is toward more connectivity, more IP, and more sensitivity.

The security architecture has to move in the same direction. Not as a compliance exercise. Not as a response to the last incident. As a design principle applied to every new connection, every new technology subsidiary, every new client engagement that brings global IP into an Indian network.

The three incidents documented here were foreseeable. SEBI said exactly this about CDSL. The controls that would have changed the outcome existed. The architecture that enforces those controls was not in place.

That architecture is available. The question is whether the next filing with BSE happens before it is built or after.


At Skeletos IT Services, we help Indian manufacturing companies and technology subsidiaries build the network access governance layer that makes segmentation enforceable, device visibility real-time, and lateral movement detectable before an attacker reaches the data that matters most. EasyNAC deploys without switch changes or network reconfiguration, giving your team visibility into every device on the network and policy enforcement across every connection boundary. If you want to understand whether your technology subsidiary’s current architecture would have changed the outcome in any of the three incidents described here, we can help you find out.

Note: All incident details are sourced from SEBI regulatory filings, official company statements, and verified reporting from BleepingComputer, SecurityWeek, SC Media, and TechTimes. Tata Technologies’ SEBI filing is a public record under Regulation 30 of the SEBI LODR Regulations, 2015. Hunters International’s claim and subsequent data publication were reported by BleepingComputer and independently corroborated by multiple security research outlets. This blog is for awareness and educational purposes.

Do You Want To Boost Your Business?

drop us a line and keep in touch

Skeletos IT Services