Friday, September 4, 2026 02:10:47 AM
The Indian Post Live

Files Tied to India's Largest Nuclear Plant Surface on Dark Web After Ransomware Breach at Reliance Contractor

Nearly 858,000 files, reportedly stolen from a Reliance Group firm headed by billionaire businessman Anil Ambani, have surfaced on the dark web via a ransomware hacking outfit, with more than 19,000 files reportedly being related to Kudankulam Nuclear Power Plant, raising new queries about India's critical infrastructure protection against cyber threats on its private contractors.

T
By The Indian Post Live
Published Jul 16, 2026, 2:45:49 PM | Updated Jul 16, 2026, 2:45:49 PM
Google Preferred Source Badge
Police patrol on a beach near Kudankulam nuclear power project in the southern Indian state of Tamil Nadu
Police patrol on a beach near Kudankulam nuclear power project in the southern Indian state of Tamil Nadu
@Reuters
Summary
The Kudankulam hacking incident, at least for now, seems to be a case involving a contractor’s server and not the control room of the nuclear plant since the reactor core technology provided by the Russian firm Rosatom remains untouched and there are no signs that the servers of NPCIL have been breached.

However, the breach serves to highlight a security issue that can easily get ignored: even on large scale infrastructure projects, there is sensitive data stored away from the premises of the actual infrastructure, often in the networks belonging to the contractors, data center providers, and subcontractors, which means that each one of them presents the risk of being breached. As CERT-In continues its investigation and Reliance tries to assess the damage done by the hackers, we should find out the extent of the threat posed by this breach. Regardless of the outcome, one thing is clear: this is yet another data breach on Indian companies, such as the Tata Group and Reliance, indicating that cybercriminals view them as interesting targets for a ransomware attack.

World Leaks, a ransomware hacktivist gang, has released millions of files in a dump on the dark web, where they claim that the dumped data is related to Reliance Group. But from the data dump, a specific part of the leaked information apparently relates to Kudankulam Nuclear Power Plant (KNPP), which is India's largest nuclear plant located in Tamil Nadu.

As per a Reuters report, which examined the leaked data, the hacked information includes some engineering designs, suppliers' information, meeting details, and inspection details of machinery. According to a statement issued by the Reliance Group to Reuters, there was a "partial breach of servers hosted with a third-party Indian data centre company Yotta".

What Was Leaked and What Was Its Source

Based on the analysis of the reports on this leak, World Leaks says to have a total of 858,000 files in its possession, out of which 19,000 are estimated to have information related to the Kudankulam plant. The documents are alleged to be dated between 2016 and mid-2025 and allegedly include drawings for ventilation and cooling systems, drawings for the common control room, proposals from vendors, lists of approved vendors, and documentation of meetings between Reliance and NPCIL. One of the documents from 2024 is allegedly about a joint inspection between these two firms and includes pictures of equipment. Another document from 2024 is alleged to have the information about an insurance policy that covers Reliance Infrastructure and NPCIL for $112 million in case Units 3 and 4 are affected by acts of terrorism.

This relation goes back to 2018, when Reliance Infrastructure bagged the deal to provide supporting infrastructure for Units 3 & 4 of the Kudankulam nuclear power project, two new 1,000 MW reactors being built and set to come online in 2027, thus increasing the total generation capacity of the power plant by 2,000 MW. Importantly, the leaked documents seem not to contain any information about the systems of the reactors themselves, which are provided by the Russian state corporation Rosatom, nor any data that would suggest that the World Leaks team managed to penetrate the computer system of the Kudankulam power plant directly.

The Alleged Details of the Data Breach

According to Yotta, the data center that hosts the impacted server, the company spotted some unusual activity on its infrastructure used by Reliance Infrastructure as early as May 29. As soon as that happened, it stopped the suspicious activity and managed to prevent the execution of the suspected ransomware attack.

Nevertheless, Reliance Infrastructure told Yotta at the end of June that "external threat actors" claimed that there was a data breach. It should be mentioned that Yotta claims that it has not yet independently verified the claims made by the threat actor, but it has passed its detailed technical report of the situation to Reliance Infrastructure.

India's Computer Emergency Response Team (CERT-In), the primary cybersecurity body of the country, is investigating the matter, says a person familiar with the matter. NPCIL, the body that commissions and runs all nuclear power plants in India, is reportedly communicating with Reliance about the aftermath. Representatives of NPCIL, CERT-In, and the central press department have not provided any comments on the matter, and neither has India's Department of Atomic Energy.

Why Experts Say the Risk Extends Beyond the Documents Themselves

While the files apparently do not include any design blueprints for the reactors' cores, experts from the field of both cybersecurity and nuclear security have warned that this should not be seen as a mitigating factor. According to Nickolas Roth, the Senior Director at the Nuclear Threat Initiative – the organization that serves governments and provides nuclear security analysis all around the world – such kind of data would provide adversaries with more information than just a list of people who have acInitiative—theects in question. Specifically, information about suppliers, facility's layouts, and documenworld—such provide them with a clear understanding of all possible systems they can use to launch an attack.

However, this is not the first time when Kudankulam has faced the problems of this kind. Back in 2019, a malware created by the hackers associated with North Korea was discovered on the network of the facility.

At the time NPCIL stated that the issue was immediately addressed and did not affect any operating systems of the plant. This pattern that security experts have noted a few times already—criticize the facility's structure. Facilities can be only as safe as their least protected vendor.

An Extended Instance of Corporate Data Leakages in India

The Kudankulam data breach is not an exceptional one for World Leaks, which is a group of hackers using ransomware attacks to attack companies like Nike, but especially Tata Group of India. In June, World Leaks told Reuters that it demanded a $1.5 million ransom from the Tata Group files that supposedly held secret components of Apple and Tesla. Moreover, World Leaks revealed that it published those documents after the refusal to pay the ransom by Tata Group. As a rule, World Leaks starts by hacking into a company’s network, then demands money, and publishes the information on its dark-web website if the ransom is not paid.

The breach incident comes at a time when there is an increasing number of data breach incidents in India. According to statistics provided by cybersecurity company Surfshark, India was ranked third globally last year in the number of compromised accounts, which stood at 28.9 million accounts, second only to the US and France.

In another study conducted by Data Security Council of India and Seqrite, a cybersecurity company, 204 companies across India were surveyed, and it was revealed that nearly 73 percent of them did not know if they have ever been hacked, while 57 percent lacked basic cyber hygiene.

Under such conditions, a data breach incident involving any part of the strategically significant nuclear power plant of Kudankulam is sure to raise questions regarding the security of the systems used by contractors.