Advertisement

Kudankulam data leak: What hackers stole, how they got in and why nuclear reactors are safe

Thousands of files linked to India’s Kudankulam Nuclear Power Project surfaced on the dark web after a breach at a private contractor’s cloud server. Nuclear Power Corporation of India Limited (NPCIL) insists nuclear safety systems were not compromised. The leaked files were related to conventional Balance of Plant (BoP) facilities

Advertisement
The Kudankulam Nuclear Power Project in Tamil Nadu has come under scrutiny after a ransomware group allegedly leaked thousands of project-related files online. (Wikimedia)
The Kudankulam Nuclear Power Project in Tamil Nadu has come under scrutiny after a ransomware group allegedly leaked thousands of project-related files online. (Wikimedia)
FP News Desk|Jul 16, 2026, 11:08:52 IST

India’s largest nuclear power project, the Kudankulam Nuclear Power Project (KKNPP) in Tamil Nadu, has become the focus of a major cybersecurity investigation after a ransomware group allegedly leaked thousands of files linked to the facility on the dark web.

The leak has triggered concern among project officials, with local sources describing the situation as a cause of “commotion”. However, the state-run Nuclear Power Corporation of India Limited (NPCIL) has sought to reassure the public, stating that there has been no breach of nuclear safety systems or reactor operations.

Advertisement

NPCIL clarified that the leaked information relates only to conventional infrastructure associated with the project and does not involve critical nuclear control systems.

19,000 files and 14.3 GB of data leaked online

The data leak was reportedly carried out by a ransomware and extortion group called World Leaks, which published a large cache of stolen files on its dark web platform.

explainersMore from Explainers

Cybersecurity researchers said the group released a collection of around 19,000 files, totalling nearly 14.3 GB of data, with references linked to KKNPP.

The leaked documents reportedly cover a period between 2016 and mid-2025 and provide details about different aspects of the project’s construction and operations.

The files allegedly include:

Advertisement

  • Engineering drawings related to cooling and ventilation systems

  • Layout plans of a common control room

  • Minutes from meetings and joint inspection reports involving Indian and Russian engineers

  • Vendor details, equipment proposals and supplier information

  • Internal insurance documents, including a reported $112 million joint terror indemnity policy for under-construction units

The data has reportedly been available on the dark web since June, according to independent security researchers cited by Reuters.

How did the breach happen?

Investigators believe the attackers did not directly penetrate the highly protected systems that control the nuclear reactors. Instead, the breach appears to have occurred through a third-party contractor.

The leaked data was reportedly taken from the systems of Reliance Infrastructure, part of the Reliance Group, which was awarded a contract in 2018 to build key common infrastructure for Kudankulam’s Units 3 and 4.

Reliance Infrastructure acknowledged a partial data breach involving an enterprise server hosted by Yotta, an Indian cloud data centre provider.

According to Yotta’s technical assessment, its systems detected suspicious ransomware activity on May 29. While the immediate malware threat was contained, attackers had already extracted a large volume of project-related files before being stopped.

The hackers later allegedly used the stolen data as part of an extortion attempt.

NPCIL says nuclear safety systems were not affected

Amid concerns over a possible threat to India’s nuclear infrastructure, NPCIL issued a statement clarifying that the leaked documents were not connected to reactor safety systems.

The company said the information related only to Balance of Plant (BoP) common service facilities for Kudankulam Units 3 and 4, which are currently under construction.

Advertisement

“These facilities are of a conventional nature and are typically found in thermal power plants as well as other process industries. They are not related to nuclear safety or nuclear security systems,” NPCIL said.

Officials explained that such infrastructure includes facilities like external ventilation systems, water supply networks and other support services, whose designs are often shared with civilian contractors during large construction projects.

The core reactor systems, including the Russian-designed VVER-1000 pressurised water reactors, remain isolated from contractor networks, officials said.

Kudankulam has faced cyber threats before

The latest incident is not the first cybersecurity challenge faced by the Kudankulam facility.

In 2019, the plant reported a cyber intrusion involving Dtrack malware, which cybersecurity firms linked to North Korea’s state-sponsored Lazarus Group.

The malware was discovered on an administrative computer connected to the plant’s local network. Investigators said it was capable of collecting system information, keystrokes and network details.

At the time, NPCIL initially denied reports of a breach but later confirmed that an administrative system had been affected.

The company maintained that the reactor control systems were protected through separate, isolated networks that were not connected to the internet.

Third-party contractors emerge as cybersecurity challenge

The latest breach has renewed questions about cybersecurity risks beyond the reactor control room.

While India’s Department of Atomic Energy maintains strict safeguards around nuclear operations, large infrastructure projects often involve multiple private companies, contractors and cloud service providers.

Cybersecurity experts say these external links can become weak points if security standards are not equally strong across the entire supply chain.

The Indian Computer Emergency Response Team (CERT-In), along with nuclear security experts, is now investigating how attackers gained access to the contractor’s systems and managed to extract the data.

The probe will focus on identifying security gaps and strengthening safeguards around third-party networks connected to India’s strategic infrastructure.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jul 16, 2026, 11:08:52 IST
Advertisement
Advertisement
Trending Stories

Why is India seeing 95% cloud cover despite a Super El Niño?

India is witnessing nearly 95 per cent cloud cover despite a Super El Niño, a climate event usually linked to weaker monsoons. Regional weather systems, cyclonic circulations, the monsoon trough and moisture from two seas are temporarily overpowering one of the world's strongest climate phenomena
5 min read
Advertisement
Advertisement
Up Next