
The Hive ransomware-as-a-service (RaaS) group, which claimed responsibility for a cyber attack against Tata Power less than two weeks ago and allegedly comprised signed client contracts, agreement documents, and other sensitive information, has been observed leaking stolen data on its HiveLeaks dark web portal after the company likely refused to pay a ransom.
Mumbai-based Tata Power is India’s largest integrated power company and is part of the Tata Group conglomerate. The company had previously disclosed in a filing with the National Stock Exchange (NSE) of India on October 14 that an intrusion on the company’s IT infrastructure, which is believed to have occurred on October 3, impacted “some of its IT systems.”
According to details shared by security researcher Rakesh Krishnan, the leak contains personally identifiable information (PII) of Tata’s 12 million customers, including Aadhaar identity numbers, emails, permanent account numbers (PAN), driver’s licenses, phone numbers, passport numbers, taxpayer data, salary specifics, and engineering drawings.
Hive, which surpassed AvosLocker, BlackByte, BlackCat, and Vice Society, was the third-most prevalent ransomware family seen in Q3 2022, according to Digital Shadows and Intel 471. It ranked only behind LockBit 3.0 and Black Basta.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543