Data Breaches

India's Kudankulam Nuclear Plant Faces Alleged Data Leak

July 21, 2026 00:08 · 12 min read
India's Kudankulam Nuclear Plant Faces Alleged Data Leak

India's state-owned nuclear operator, Nuclear Power Corporation of India Limited (NPCIL), has stated that recently leaked documents related to the Kudankulam Nuclear Power Plant (KKNPP) contain no information that could compromise safety or security.

Leaked Documents and Response

The leaked documents, which were published online by the cybercrime group World Leaks, appear to include engineering drawings, supplier information, inspection records, and insurance documents related to Units 3 and 4 of the plant, currently under construction. However, NPCIL claims that these documents pertain only to the conventional Balance of Plant (BoP) package, which covers support infrastructure separate from the reactors and their safety systems.

Science and Technology Minister Jitendra Singh has also dismissed reports suggesting that sensitive nuclear information had been compromised, stating that there is no immediate need for a broader security review.

Third-Party Contractor Breach

The leaked documents were labeled as originating from Reliance Group, whose subsidiary Reliance Infrastructure is building non-nuclear infrastructure for the new Kudankulam reactors. Reliance Group has confirmed that it suffered a "partial breach" involving data stored on infrastructure hosted by Indian data center provider Yotta.

Yotta detected suspicious activity on a Reliance Infrastructure server it hosts in late May and immediately terminated the activity, preventing a suspected ransomware execution. Yotta has shared the results of its forensic investigation with Reliance Infrastructure and continues to support the investigation.

Investigation and Possible Attack Vector

Independent cybersecurity researcher Rakesh Krishnan, who first documented the purported leak, believes that World Leaks published the data on June 11 after the expiration of the group's typical countdown timer. Krishnan suggests that the attackers may have gained access through exposed remote desktop services, phishing, or exploitation of a Fortinet vulnerability, although there is no public evidence confirming the intrusion vector.

According to Krishnan, nearly 19,000 files totaling about 14.3 GB related to Kudankulam were published by World Leaks. The documents, dated between 2016 and mid-2025, include what appear to be engineering drawings, supplier information, meeting records, inspection reports, and insurance documents. However, the authenticity of the documents could not be independently verified.

Prior Cyber Incidents at Kudankulam

This is not the first cyber incident involving Kudankulam. In 2019, malware later linked to North Korea's Lazarus Group was discovered on an internet-connected administrative network at the plant. NPCIL stated that the infected system was isolated from reactor control and operational networks, and India's CERT-In concluded that plant operations were unaffected.

World Leaks' Targets and Tactics

Kudankulam became the second high-profile Indian victim publicly claimed by World Leaks in recent weeks. Last month, the group claimed responsibility for breaching Tata Electronics, an Indian manufacturer that supplies Apple, Tesla, and Qualcomm, and demanded $1.5 million. World Leaks later published what it said were confidential engineering documents after alleging that the company had refused to pay.

World Leaks emerged in early 2025 following the rebranding of the Hunters International ransomware operation. Unlike traditional ransomware groups that prioritize file encryption, it has increasingly focused on stealing and publishing data to pressure victims into paying extortion demands.

World Leaks' tactics highlight the evolving nature of cyber threats and the importance of robust cybersecurity measures to protect sensitive information.

Source: The Record

Source: The Record

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free