Apple data breach: what happened and what to do
Last reviewed August 22, 2026 · 5 records on file · sources listed below
A hacking group named World Leaks breached one of Apple's manufacturing facilities in India, stealing over 630GB of data across more than 200,000 files, including sensitive iPhone 18 Pro series schematics, chip manuals, production workflows, and test videos. All the stolen data was subsequently posted on the dark web.
If you have an account with Apple, assume the exposed details are circulating. The practical risk today is rarely the leak itself — it is the calls and messages that use those details to sound legitimate.
What we have on file
Every entry below is a catalogued record with its original source. We do not paraphrase beyond what the source reports.
Personal Information · Unknown
An opinion piece describes ongoing attempts by an unknown party to break into the author's Apple account, with regular email and text notifications of the attempts. No confirmed data exposure is mentioned, but the account access attempts indicate potential unauthorized access to personal data.
Personal Information · Unknown
Apple experienced a significant data leak, exposing personal information. The breach was reported in a Forbes article summarizing Apple news, including the data leak. Specific details about the breach method and exact data exposed are limited, but it involves unauthorized exposure of user or customer data.
Personal Information · Unknown
A data breach at an Apple supplier allegedly led to the leak of design details and drop test videos of the unreleased iPhone 18 Pro, representing a significant exposure of confidential product information.
Personal Information · Unknown
Apple announced a security breach that could allow other parties to bypass passcodes and pull data from locked iPhones. Users are advised to update their devices to mitigate the risk.
What to do
- Change the password anywhere you reused itThe exposure matters most when the same password protects your email, because email is how everything else gets reset.
- Treat every call and text about this breach as a scam until proven otherwiseNo company will ask you for a one-time code, a PIN or a password. Hang up and call the number printed on your card.
- Read your statements for the next three monthsCard fraud usually starts with a small test charge. Catching that one is what stops the large one.
- Give your email account a password nothing else usesIt is the account that can reset all the others, so it is the one worth protecting first.
Questions people ask
Was my data in the Apple breach?
Having an account alone does not confirm exposure. The reliable check is whether your email address appears in the leaked datasets in circulation — that takes seconds and does not require your password.
Is it too late to do anything?
No. Leaked personal details do not expire, and neither does the defence: a unique password on your email, and a fraud alert on your credit file, still work years later.
Will Apple contact me?
They may. But scammers contact people too, using exactly these breach details to sound convincing. Never act on an inbound call or text — call back on a number you already had.
701 organisations catalogued
Records are catalogued from public reporting and linked to their original source. iTellYou is not affiliated with the organisations listed. If you represent one of them and something here is inaccurate, write to us and we will correct it.