Data Breach Exposes Sensitive Files of India's Largest Nuclear Power Plant

ALN NEWS DESK
ALN NEWS DESK
Updated : Jul 15, 2026, 04:11 PM IST
7 min read
  • linkedin
  • twitter
  • facebook
  • instagram
  • whatsapp

A ransomware group has leaked sensitive documents related to the Kudankulam Nuclear Power Plant, raising security concerns over India's nuclear infrastructure.

In a significant cybersecurity incident, the ransomware group known as World Leaks has made public a large cache of sensitive files related to the Kudankulam Nuclear Power Plant, which is the largest nuclear facility in India. This breach raises serious concerns about the safety and security of one of the country's critical energy infrastructures, especially given its strategic importance in India's nuclear energy ambitions.

The Kudankulam Nuclear Power Plant, situated in Tamil Nadu, has been at the forefront of India's nuclear energy expansion plans under Prime Minister Narendra Modi. The plant is not only vital for meeting the country's growing energy demands but also plays a key role in India's broader strategy to enhance its energy independence and reduce reliance on fossil fuels. The plant currently has two operational units, with additional units under construction that are expected to significantly increase its capacity.

The files released by World Leaks include purported blueprints for various parts of the plant, along with sensitive supplier information. Allegedly linked to the Reliance Group, one of the contractors involved in the plant's construction and operation, these documents could provide malicious actors with critical insights into the plant's infrastructure and operational protocols.

Reliance Group, which is led by Indian businessman Anil Ambani, confirmed that there had been a "partial breach" of its data, stating that the compromised information was hosted on a server managed by Yotta, a third-party data center service provider. While Reliance acknowledged the breach and stated that the government had been informed, it has not disclosed the specific nature of the data that was compromised, which raises further concerns about the extent of the breach.

Experts in nuclear security, such as Nickolas Roth from the Nuclear Threat Initiative, have warned that the breach poses a serious risk to the safety of the Kudankulam plant. Roth emphasized that the leaked information could potentially be exploited to identify vulnerabilities in the plant's security systems. This incident highlights a growing trend of cyberattacks in India, where many organizations still struggle to implement effective cybersecurity measures.

The leaked documents, which date from 2016 to mid-2025, reportedly include not only blueprints and supplier details but also meeting records, inspection reports, equipment evaluations, and insurance policies. While the authenticity of these documents has not been independently verified, their potential implications are alarming. The files are said to represent the most sensitive subset of a total of 858,000 files associated with Reliance that were made public on the World Leaks platform.

One of Reliance's subsidiaries, Reliance Infrastructure, secured a contract in 2018 to design and construct infrastructure for the plant's forthcoming Unit 3 and Unit 4. These units, which are still under construction, are expected to add a combined capacity of 2,000 megawatts to India's energy grid by 2027. The ramifications of a data breach at such a critical juncture could be profound, not only for the contractors involved but also for the national energy security of India.

World Leaks has gained notoriety for its cybercriminal activities, having previously targeted high-profile companies such as Nike and India's Tata Group. The group typically releases stolen corporate data on its platform after companies refuse to meet their ransom demands. Access to their website is restricted and requires specialized browsing tools, making it a dark corner of the internet where sensitive information can be traded or exposed.

In a previous case involving Tata Group, World Leaks demanded a ransom of $1.5 million for files containing confidential designs for components used by major companies like Apple and Tesla. The group ultimately released the data after Tata allegedly ignored their demands, illustrating the lengths to which these cybercriminals will go to exert pressure on corporations.

Investigation and Response

Following the breach, the Nuclear Power Corporation of India (NPCIL), which is responsible for commissioning and operating nuclear power plants in the country, has been in communication with Reliance regarding the incident. India's primary cybersecurity agency, the Indian Computer Emergency Response Team (CERT-In), is also investigating the breach. However, both NPCIL and CERT-In have not publicly commented on the specifics of the investigation.

Yotta, the data center involved, reported that it detected suspicious activity on May 29 on a server belonging to Reliance Infrastructure. Although Yotta claims to have terminated the suspicious activity and prevented the execution of ransomware, Reliance informed them of the breach claims by external threat actors at the end of June. Yotta has since stated that it is cooperating with the ongoing investigation but has not confirmed the validity of the claims made by the threat actor.

The Indian government has remained largely silent on the matter, with the Department of Atomic Energy and Prime Minister Modi's office not providing comments when approached by media outlets. This lack of transparency raises questions about how such incidents are managed at a national level, especially when they involve critical infrastructure.

Contents of the Breached Data

The documents leaked by World Leaks do not appear to include information related to the core systems of the nuclear reactors, which are supplied by Rosatom, a state-owned enterprise from Russia. However, the leaked files reportedly contain blueprints for ventilation and cooling systems for both Unit 3 and Unit 4, as well as layouts for a common control room. Such information could be invaluable to adversaries seeking to exploit weaknesses in the plant's operational framework.

Additionally, the documents include vendor proposals, lists of approved suppliers, and records of meetings between the Nuclear Power Corporation and Reliance, including photographs of equipment. One particularly concerning document reportedly outlines an insurance policy that would provide $112 million in coverage in the event of a terrorist attack on either Unit 3 or Unit 4. This highlights the potential risks and the financial implications associated with the security of nuclear facilities.

Cybersecurity experts warn that the data in the wrong hands could allow adversaries to map out the plant's support systems, identify key suppliers, and pinpoint vulnerabilities in the security infrastructure. Roth from the Nuclear Threat Initiative noted that such information could reveal not only who has access to the project but also the extent of that access, potentially compromising the integrity of the entire operation.

India has been grappling with a rising number of data breaches, ranking third globally in terms of compromised accounts, with nearly 29 million accounts affected last year alone, trailing only the United States and France. A report from the Data Security Council of India and cybersecurity firm Seqrite indicated that a staggering 73% of surveyed organizations were unaware of whether they had ever been attacked, while 57% lacked basic cyber hygiene practices. This lack of preparedness raises significant concerns about the resilience of India's critical infrastructure against cyber threats.

This incident marks the second time that the Kudankulam plant has been associated with a cyber incident. In 2019, malware linked to a North Korean hacking group was discovered on the plant's administrative network. At that time, the Nuclear Power Corporation asserted that the matter was investigated promptly and that core plant systems remained unaffected. However, the recurrence of such incidents highlights the persistent vulnerabilities faced by critical infrastructure in India.

As the investigation into this latest breach continues, it underscores the urgent need for enhanced cybersecurity measures across India's critical infrastructure sectors. The implications of such breaches extend beyond immediate data loss; they pose risks to national security, public safety, and the integrity of vital energy resources. As cyber threats evolve, so too must the strategies employed by organizations to safeguard sensitive information and maintain operational resilience in the face of increasing cyber challenges.

Get More Updates

To learn more about the latest developments in Crime & Law, stay updated with our exclusive reports and analyses on AiLensNews.

Related News