Kudankulam Nuclear Plant Data Breach: What the Leaked Files Reveal and Why It Matters
Maryam Tariq
A ransomware group known as World Leaks has published a massive cache of stolen files on the dark web, claiming they originated from Reliance Group, a contractor involved in expanding India’s largest nuclear facility. The Kudankulam Nuclear Power Plant, located in Tamil Nadu and central to Prime Minister Narendra Modi’s plans to grow India’s atomic energy capacity, is now at the center of a cybersecurity incident that experts say could carry real safety implications.
What the Leaked Kudankulam Files Contain
Of roughly 858,000 total files World Leaks claims to hold from Reliance, around 19,000 files, totalling 14.3 gigabytes, are specifically linked to the Kudankulam project, based on searches for the acronym KKNP. The documents, dated from 2016 to mid 2025, reportedly include purported blueprints for the ventilation and cooling systems tied to Units 3 and 4, along with what appears to be the complete floor layout of a shared control room. Also included are vendor proposals, a list of approved suppliers, records from a 2024 joint inspection meeting with photos of equipment, and a document suggesting Reliance Infrastructure and the Nuclear Power Corporation held an insurance policy that would pay out 112 million dollars if either unit suffered an act of terrorism. Reuters reviewed the documents but could not independently verify their authenticity.



How the Reliance Group Data Breach Happened
The breach did not originate inside Kudankulam’s own systems. It traces back to Reliance Infrastructure, the Reliance Group subsidiary that won a 2018 contract to design and build infrastructure for the plant’s Units 3 and 4, both still under construction and expected to add 2,000 megawatts of combined capacity by 2027. Reliance confirmed to Reuters that a partial breach occurred on a server hosted by third party Indian data centre provider Yotta, though the company did not disclose what specific data was taken. Yotta said it detected suspicious activity on the server on May 29, immediately terminated it, and believed it had prevented a ransomware execution. However, Reliance Infrastructure informed Yotta at the end of June that external threat actors were claiming a data breach had still occurred. Yotta said it could not independently verify those claims but has shared its technical investigation with Reliance and is supporting an ongoing probe. India’s Nuclear Power Corporation, CERT-In, and the government’s main press office either declined to comment or did not respond to requests for comment.
Why Nuclear Security Experts Are Concerned
Nickolas Roth, a senior director at the Nuclear Threat Initiative, an organization that advises governments and benchmarks nuclear security preparedness, said the breach could pose a serious risk to the plant’s safety. Roth explained that files like these, in the wrong hands, could be used to map a facility’s support systems, identify its suppliers, and pinpoint weaknesses across its security chain. As he put it, the data doesn’t just reveal who has access to a project, it can reveal exactly which systems that access actually reaches.
What Wasn’t Exposed in This Nuclear Data Leak
Importantly, the leaked documents do not appear to involve the reactors’ core systems, which are supplied by Russia’s state owned Rosatom. The exposed material centers on support infrastructure rather than the reactors themselves. This is also not the first time Kudankulam has faced a cybersecurity scare. In 2019, malware linked to a North Korean hacking group was discovered on the plant’s administrative network, though the Nuclear Power Corporation said at the time that the matter was investigated and core plant systems were unaffected.
India’s Broader Cybersecurity Gap



This incident lands within a larger pattern. India currently ranks third globally for data breaches, behind only the United States and France, with 28.9 million accounts compromised last year according to cybersecurity firm Surfshark. A separate industry report from the Data Security Council of India and Seqrite found that 73 percent of Indian organisations surveyed did not know whether they had ever been attacked, and 57 percent lacked basic cyber hygiene practices. World Leaks itself has a track record of targeting major companies, having previously published data allegedly stolen from Nike and India’s Tata Group, the latter reportedly containing confidential Apple and Tesla component designs after Tata declined to pay a 1.5 million dollar ransom.
Sources:
· Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach — Reuters: https://www.tradingview.com/news/reuters.com,2026:newsml_L4N43G0FA:0-files-relating-to-india-s-largest-nuclear-power-plant-kudankulam-exposed-in-data-breach/
· India’s nuclear files leaked on dark web, 858,000 files from Kudankulam plant out, Reliance Group admits partial breach — The Week: https://www.theweek.in/news/india/2026/07/15/india-s-nuclear-files-leaked-on-dark-web-858000-files-from-kudankulam-plant-out-reliance-group-admits-partial-breach.html
· Files relating to Kudankulam nuclear power plant exposed in data breach — Business Standard: https://www.business-standard.com/technology/tech-news/files-relating-to-kudankulam-nuclear-power-plant-exposed-in-data-breach-126071500819_1.html · 858,000 Files and Confidential Blueprints, Inside Data Breach at India’s Largest Nuclear Plant in Tamil Nadu’s Kudankulam — Republic World: https://www.republicworld.com/tech/858000-files-and-nuclear-plant-blueprints-inside-data-breach-at-kudankulam-india-s-largest-nuclear-plant-reliance-2026-07-15-132391









