Data breach at Kudankulam Nuclear plant raises security alarm Thousands of files go online

Thousands of project-related files linked to the Kudankulam Nuclear Power Plant have reportedly been leaked in a ransomware attack. While officials say reactor operations remain secure, Indian agencies are investigating the breach and its potential implications for critical infrastructure security.

Jul 15, 2026 - 22:07
 0
Data breach at Kudankulam Nuclear plant raises security alarm Thousands of files go online
The alleged ransomware attack that led to the leak of thousands of files belonging to the Kudankulam Nuclear Power Plant (KNPP), India’s largest nuclear power plant, has triggered a massive cybersecurity scare. The incident has raised concerns about the security of critical infrastructure, but officials said the plant's operational and reactor control systems were secure.
 
The leak involves documents concerning the construction of units 3 and 4 of Kudankulam, which are being constructed with Russian cooperation. Now, authorities are investigating how the leak happened and if any sensitive information could threaten national security.
 
Nearly 19,000 Files Purportedly Leaked
 
The ransomware group World Leaks has reportedly claimed responsibility for publishing nearly 19,000 files, totalling about 14.3 GB of data. The files reportedly include engineering drawings, contracts with suppliers, inspection reports, insurance records, project schedules and internal correspondence related to the Kudankulam expansion project.
 
The hackers are believed to have attacked systems linked to the Reliance Group, one of the contractors on the project. While the authenticity of each leaked document is still being evaluated, cybersecurity experts say the volume of data indicates a significant compromise of project-related information.
 
Plant Operations Continue As Is
 
Officials said the breach did not affect the plant's reactor control systems or safety mechanisms. The Nuclear Power Corporation of India Limited (NPCIL) has stated that the critical operational networks are segregated from external internet-connected systems and cannot, therefore, be attacked to interfere with the operation of the reactors.
 
However, experts caution that even non-operational documents can contain valuable information about infrastructure, contractors, logistics, and security procedures that could be exploited by cybercriminals or hostile actors.
 
Investigation Ongoing
 
Reliance Group has admitted to a minor breach involving a third-party server that was used for project-related data. India’s Computer Emergency Response Team or CERT-In, Nuclear Power Corporation of India Limited or NPCIL and other cybersecurity agencies are probing the incident to find out how the breach happened and whether any other systems were affected.
 
The incident has shifted focus to ramping up cyber security across India’s strategic infrastructure. The Kudankulam plant was also in the spotlight in 2019 when malware was found on an administrative network, although officials said the reactor systems were unaffected.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0