Ransomware group ‘World Leaks’ has posted an enormous cache of recordsdata associated to India’s largest nuclear energy plant, Kudankulam, on the darkish net. This consists of purported blueprints of components of the ability and provider particulars, with data labeled as coming from Reliance Group.
The Kudankulam nuclear energy plant in Tamil Nadu is the biggest of India’s seven nuclear energy crops and is on the coronary heart of Prime Minister Narendra Modi’s bold plans to broaden the nation’s nuclear vitality capability.
stated industrialist Anil Ambani’s Reliance Group, one of many manufacturing unit contractors. Reuters It stated in a press release {that a} “partial breach” of knowledge occurred on servers hosted by India’s third-party knowledge heart service supplier Yotta, and that the federal government had been knowledgeable of the incident.
Reliance has not disclosed what knowledge was compromised.
‘Important danger’ to nuclear energy security
Nicholas Ross, senior director of the Nuclear Menace Initiative, which advises governments and benchmarks international locations’ nuclear safety preparedness, stated the info breach may pose a “critical” danger to the protection of nuclear energy crops. The breach additionally highlights how widespread hacking has turn out to be in India, the place many corporations are unprepared to take care of such threats.
Rakesh Krishnan, an unbiased cybersecurity researcher who first raised the alert, stated a complete of practically 19,000 recordsdata showing for the search time period “KKNP” (an acronym for nuclear energy crops within the knowledge) have been on-line since June 11, totaling 14.3 gigabytes. Reuters For leaks.
Reuters We examined paperwork dated from 2016 to mid-2025, however have been unable to confirm their authenticity. Along with some blueprints and provider particulars, assembly and inspection data, gear evaluations and insurance coverage insurance policies are additionally stated to be proven.
These 19,000 recordsdata are believed to be probably the most delicate of the full 8,58,000 Reliance recordsdata on the World Leaks web site.
Reliance Infrastructure, one of many conglomerate’s subsidiaries, was awarded the contract in 2018 to design and assemble the infrastructure for models 3 and 4 of the facility plant. Each models are nonetheless beneath development and are anticipated to be operational by 2027, offering a mixed capability of two,000 MW.
World Leaks, a widely known ransomware group that has beforehand focused Nike and India’s Tata Group, didn’t reply. Reuters Reliance knowledge breach questions. The group usually posts stolen firm knowledge on its web site after the corporate refuses to pay the demanded ransom. The web site can solely be accessed with a devoted browser.
In line with World Leaks in June, Reuters The corporate is demanding $1.5 million in ransom for Tata Group recordsdata containing delicate element designs from prospects Apple and Tesla, it stated, including that it posted the info after Tata “ignored” its calls for.
There was suspicious exercise on the server in Could.
Sources stated the Atomic Vitality Company of India, which commissions and operates India’s nuclear energy crops, has been in contact with Reliance in regards to the breach, and India’s essential cybersecurity company, Laptop Emergency Response Workforce of India (CERT-In), is investigating the incident. The supply declined to be recognized given the sensitivity of the matter.
Atomic Vitality Authority Chairman Rajesh Veeraraghavan, CERT-In, and main authorities media shops didn’t reply to repeated requests for remark.
Yotta stated in a press release that on Could 29, it observed suspicious exercise on a server hosted by the corporate that belongs to Reliance Infrastructure. Though the operation was instantly halted and the suspected ransomware execution was thwarted, Reliance Infrastructure notified the corporate in late June of an alleged knowledge breach by an “exterior risk actor.”
Yotta added that whereas he can’t affirm the “risk actor” claims, he has shared detailed technical analysis with Reliance Infrastructure and helps the continued investigation.
India’s Atomic Vitality Ministry declined to remark, whereas Mr. Modi’s workplace didn’t reply. Reuters question.
Blueprint and insurance coverage coverage
The paperwork printed in World Leaks don’t look like associated to the core programs of the reactor, which is equipped by Russia’s state-run Rosatom firm.
These included what gave the impression to be blueprints for the air flow and cooling programs utilized in Items 3 and 4, in addition to what gave the impression to be the entire ground format of the “widespread management room.”
The recordsdata additionally included what gave the impression to be vendor proposals, an inventory of permitted suppliers, and data of a 2024 assembly concerning joint inspections by the Atomic Vitality Company and Reliance, with images of the gear.
One other doc reveals that Reliance Infrastructure and the Atomic Vitality Company had an insurance coverage coverage that would supply them with $112 million if reactors 3 or 4 have been hit by an act of terrorism.
Within the incorrect palms, these recordsdata may theoretically be used to map a manufacturing unit’s help programs, establish suppliers and pinpoint weaknesses within the safety chain, researchers stated.
Ross, of the Nuclear Menace Initiative, stated they “may present an adversary not solely who has entry to a venture, but additionally what programs that entry would attain.”
India and knowledge breaches
In line with cybersecurity agency Surfshark, India ranks third on the record of nations with probably the most knowledge breaches, with 28.9 million accounts compromised final yr, simply behind the USA and France.
A report launched final yr by the Knowledge Safety Council of India and cybersecurity agency Seqrite discovered that of 204 organizations surveyed throughout India, about 73% have been “not conscious if that they had been attacked”, whereas 57% had uncared for cyber hygiene measures.
That is additionally the second time that the Kudankulam energy plant has been linked to a cyber incident, with malware linked to a North Korean hacker group being found on the plant’s administration community in 2019. On the time, the Atomic Vitality Authority stated the problem was instantly investigated and the plant’s programs weren’t affected.
issued – July 15, 2026 7:51 PM IST
