Secrets of India's Largest Nuclear Plant Stolen by Hackers, Nation at Risk
The ‘World Leaks’ ransomware group has uploaded secret details about India’s largest nuclear facility to a dark web page. The details include blueprints of the interior parts of the nuclear facility and its suppliers. According to the label, the classified information was obtained from Indian conglomerate Reliance Group. The Kudankulam Nuclear Power Plant, located in the southern state of Tamil Nadu, is the largest of India’s seven nuclear facilities. Kudankulam plays a central role in Prime Minister Narendra Modi’s plan to expand the country’s atomic energy capacity. Anil Ambani of Reliance Group, one of the plant’s contractors, told Reuters in a statement that the company experienced a ‘partial data breach’ on a server hosted by a third-party data centre. He said the government has been informed of the incident. Reliance did not disclose what data was compromised. Nickolas Roth, Senior Director at the Nuclear Threat Initiative, said the data leak could pose a serious risk to the continuity of India’s largest nuclear plant. The incident also shows how hacking is becoming increasingly common in India, with many companies considered to lack adequate defence systems to counter cyber threats. Independent cyber security researcher Rakesh Krishnan, who first alerted Reuters to the leak, said nearly 19,000 files totalling 14.3 gigabytes appeared when searching for the keyword ‘KKNP’, the plant’s acronym. The classified data has been available online since 11 June 2026. Reuters reviewed the documents, which span from 2016 to mid-2025, but could not verify their authenticity. Besides containing several blueprints and supplier details, the documents also reportedly include meeting and inspection records, equipment reviews, and insurance policies. The 19,000 files appear to be the most sensitive part of a total of 858,000 Reliance files posted on the World Leaks website. A subsidiary of the conglomerate, Reliance Infrastructure, won a contract in 2018 to design and build infrastructure for Units 3 and 4 of the plant. Both units, currently under construction, are scheduled to begin operations in 2027 and are projected to generate a combined capacity of 2,000 megawatts. World Leaks, a veteran ransomware group that previously targeted Nike and Tata Group, did not respond to Reuters’ request for comment on the Reliance data leak. India’s Nuclear Power Corporation, which oversees the country’s nuclear facilities, has previously communicated with Reliance about the data breach incident. Yotta, the data centre operator for Reliance, stated that it detected suspicious activity on 29 May 2026 on a server dedicated to Reliance Infrastructure. The activity was immediately halted when Yotta detected the ransomware suspicion. Among the leaked data were vendor proposals, approved supplier lists, and records of a 2024 meeting about a joint inspection by the Nuclear Power Corporation and Reliance. According to researchers, the leaked files could allow criminals to exploit maps of the nuclear plant’s support systems, identify suppliers, and discover weaknesses in the facility’s security chain. India ranks third globally in data breaches, with 28.9 million accounts compromised last year, behind only the United States and France, according to cyber security firm Surfshark. A report last year from the Data Security Council of India and cyber security firm Seqrite noted that of 204 organisations surveyed across India, about 73% were unaware if they had been attacked, while 57% did not implement cyber hygiene practices. This is the second time the Kudankulam facility has been linked to a cyber incident. In 2019, malware connected to a North Korean hacking group was found on the plant’s administrative network. The Nuclear Power Corporation stated at the time that the issue was investigated and the facility’s systems were not affected.