World Leaks, a ransomware hacktivist gang, has released millions of files in a dump on the dark web, where they claim that the dumped data is related to Reliance Group. But from the data dump, a specific part of the leaked information apparently relates to Kudankulam Nuclear Power Plant (KNPP), which is India's largest nuclear plant located in Tamil Nadu.
As per a Reuters report, which examined the leaked data, the hacked information includes some engineering designs, suppliers' information, meeting details, and inspection details of machinery. According to a statement issued by the Reliance Group to Reuters, there was a "partial breach of servers hosted with a third-party Indian data centre company Yotta".
Based on the analysis of the reports on this leak, World Leaks says to have a total of 858,000 files in its possession, out of which 19,000 are estimated to have information related to the Kudankulam plant. The documents are alleged to be dated between 2016 and mid-2025 and allegedly include drawings for ventilation and cooling systems, drawings for the common control room, proposals from vendors, lists of approved vendors, and documentation of meetings between Reliance and NPCIL. One of the documents from 2024 is allegedly about a joint inspection between these two firms and includes pictures of equipment. Another document from 2024 is alleged to have the information about an insurance policy that covers Reliance Infrastructure and NPCIL for $112 million in case Units 3 and 4 are affected by acts of terrorism.
This relation goes back to 2018, when Reliance Infrastructure bagged the deal to provide supporting infrastructure for Units 3 & 4 of the Kudankulam nuclear power project, two new 1,000 MW reactors being built and set to come online in 2027, thus increasing the total generation capacity of the power plant by 2,000 MW. Importantly, the leaked documents seem not to contain any information about the systems of the reactors themselves, which are provided by the Russian state corporation Rosatom, nor any data that would suggest that the World Leaks team managed to penetrate the computer system of the Kudankulam power plant directly.
According to Yotta, the data center that hosts the impacted server, the company spotted some unusual activity on its infrastructure used by Reliance Infrastructure as early as May 29. As soon as that happened, it stopped the suspicious activity and managed to prevent the execution of the suspected ransomware attack.
Nevertheless, Reliance Infrastructure told Yotta at the end of June that "external threat actors" claimed that there was a data breach. It should be mentioned that Yotta claims that it has not yet independently verified the claims made by the threat actor, but it has passed its detailed technical report of the situation to Reliance Infrastructure.
India's Computer Emergency Response Team (CERT-In), the primary cybersecurity body of the country, is investigating the matter, says a person familiar with the matter. NPCIL, the body that commissions and runs all nuclear power plants in India, is reportedly communicating with Reliance about the aftermath. Representatives of NPCIL, CERT-In, and the central press department have not provided any comments on the matter, and neither has India's Department of Atomic Energy.
While the files apparently do not include any design blueprints for the reactors' cores, experts from the field of both cybersecurity and nuclear security have warned that this should not be seen as a mitigating factor. According to Nickolas Roth, the Senior Director at the Nuclear Threat Initiative – the organization that serves governments and provides nuclear security analysis all around the world – such kind of data would provide adversaries with more information than just a list of people who have acInitiative—theects in question. Specifically, information about suppliers, facility's layouts, and documenworld—such provide them with a clear understanding of all possible systems they can use to launch an attack.
However, this is not the first time when Kudankulam has faced the problems of this kind. Back in 2019, a malware created by the hackers associated with North Korea was discovered on the network of the facility.
At the time NPCIL stated that the issue was immediately addressed and did not affect any operating systems of the plant. This pattern that security experts have noted a few times already—criticize the facility's structure. Facilities can be only as safe as their least protected vendor.
The Kudankulam data breach is not an exceptional one for World Leaks, which is a group of hackers using ransomware attacks to attack companies like Nike, but especially Tata Group of India. In June, World Leaks told Reuters that it demanded a $1.5 million ransom from the Tata Group files that supposedly held secret components of Apple and Tesla. Moreover, World Leaks revealed that it published those documents after the refusal to pay the ransom by Tata Group. As a rule, World Leaks starts by hacking into a company’s network, then demands money, and publishes the information on its dark-web website if the ransom is not paid.
The breach incident comes at a time when there is an increasing number of data breach incidents in India. According to statistics provided by cybersecurity company Surfshark, India was ranked third globally last year in the number of compromised accounts, which stood at 28.9 million accounts, second only to the US and France.
In another study conducted by Data Security Council of India and Seqrite, a cybersecurity company, 204 companies across India were surveyed, and it was revealed that nearly 73 percent of them did not know if they have ever been hacked, while 57 percent lacked basic cyber hygiene.
Under such conditions, a data breach incident involving any part of the strategically significant nuclear power plant of Kudankulam is sure to raise questions regarding the security of the systems used by contractors.












