India's Largest Nuclear Project Breached, Thousands of Secret Documents Leaked
A data breach has reportedly hit the Kudankulam Nuclear Power Plant project, India’s largest nuclear power station. The World Leaks ransomware group uploaded nearly 19,000 files to the dark web, which it claims were obtained from Reliance Group, one of the project’s contractors. The leaked documents are said to include blueprints of several facilities, supplier data, inspection records, and other technical documents related to the Kudankulam project. The breach has sparked concerns over the security of one of India’s most strategic energy infrastructures. Reliance Group confirmed a “partial breach” of data stored on servers managed by third-party data centre provider Yotta. “There has been a partial breach of our data residing on servers hosted by Yotta, and the government has been notified of this incident,” the company said in a statement. However, the company did not specify the type of data accessed by the perpetrators. Nickolas Roth, Senior Director at the Nuclear Threat Initiative, assessed that the leak could pose a serious risk to the plant’s safety. “The files could show a hostile actor not only who has access to the project, but also which systems that access can reach,” he said. Independent cyber security researcher Rakesh Krishnan revealed that approximately 19,000 files, totalling 14.3 gigabytes, have been available online since 11 June. Reuters reviewed the documents, which date from 2016 to mid-2025, but could not independently verify their authenticity. The files reportedly contain blueprints for ventilation and cooling systems, supplier lists, meeting notes, inspection results, equipment evaluations, and project insurance policies. Kudankulam is the largest of India’s seven operating nuclear plants and is central to Prime Minister Narendra Modi’s ambition to expand national nuclear energy capacity. Reliance Infrastructure secured a contract in 2018 to build the infrastructure for Units 3 and 4, which are targeted to begin operations in 2027 with a combined capacity of 2,000 megawatts. A source familiar with the investigation said the Nuclear Power Corporation of India has coordinated with Reliance regarding the incident, while the national cyber security agency, CERT-In, is conducting an investigation. Yotta stated it detected suspicious activity on 29 May on Reliance Infrastructure’s server and that the attempted ransomware execution was prevented. Reliance later informed Yotta of the data leak claim by an external threat actor. Yotta said it could not verify the claim but has submitted its technical investigation results to Reliance. The leaked documents reportedly do not relate to the core reactor systems supplied by Russian nuclear company Rosatom. However, the files are said to contain layouts of the joint control room, support system designs, vendor proposals, approved supplier lists, and joint inspection notes with photographs of equipment. One document also reportedly shows an insurance policy worth US$112 million held by Reliance Infrastructure and the Nuclear Power Corporation for protection in the event of a terrorist act on Units 3 or 4. Researchers warn such information could be used to map the plant’s support systems, identify supply chains, and find security gaps. This incident adds to a series of cyberattacks targeting India’s strategic sectors. According to cyber security firm Surfshark, India ranked third globally for data breaches last year, with approximately 28.9 million accounts compromised. In 2019, the administrative network of the Kudankulam plant was previously infiltrated by malware linked to a North Korean hacking group, though the operator confirmed at the time that core systems were unaffected.