Drooid Logo
Back to story perspectives

Full Breakdown

Ransomware Leak Exposes Sensitive Files from India’s Largest Nuclear Plant

7/15/2026, 9:44:05 PM

Core Incident: Massive Data Dump from Kudankulam Facility

On June 11, the ransomware group World Leaks posted on the dark web a cache of roughly 19,000 files (about 14.3 GB) labeled “KKNP,” an acronym for the Kudankulam Nuclear Power Plant in Tamil Nadu. The documents, dated from 2016 to mid-2025, were claimed to have been taken from Reliance Group, a contractor on the plant’s expansion. The leak includes purported blueprints of ventilation and cooling systems for Units 3 and 4, a floor layout of a common control room, supplier lists, inspection records, equipment reviews and an insurance policy worth $112 million for terrorism-related damage.

Background & Cybersecurity Landscape

Kudankulam’s breach follows a 2019 incident in which malware linked to a North Korean hacking group was found on the plant’s administrative network; officials said operational systems were unaffected. India now ranks third globally for data-breach volume, with 28.9 million compromised accounts reported last year by cybersecurity firm Surfshark. A survey by the Data Security Council of India and Seqrite found 73 % of 204 surveyed organisations were unsure whether they had ever been attacked, and 57 % lacked basic cyber-hygiene practices.

Key Actors

  • World Leaks – ransomware gang that typically publishes stolen data after ransom demands are refused.
  • Reliance Group (led by Anil Ambani) – contractor responsible for design and construction of Units 3 and 4.
  • Nuclear Power Corporation of India (NPCIL) – operator of India’s nuclear plants.
  • Indian Computer Emergency Response Team (CERT-In) – government cyber-security agency investigating the breach.
  • Yotta – Indian data-centre provider hosting the compromised server.
  • Nickolas Roth – senior director, Nuclear Threat Initiative (NTI), commenting on security implications.

Data & Documents Released

  • 19,000 files selected from a larger archive of 858,000 Reliance documents posted on World Leaks.
  • Files cover ventilation and cooling system designs, a control-room floor plan, vendor proposals, approved-supplier lists, inspection photos (2024) and a $112 million terrorism-insurance policy.
  • No documents appear to involve the reactor cores, which are supplied by Russia’s state-owned Rosatom.

Official Statements & Responses

Reliance Group confirmed a “partial breach” of data stored on a server hosted by Yotta and said the Indian government had been notified, but it did not specify which files were accessed. Yotta reported detecting suspicious activity on May 29, immediately terminating the attempted ransomware execution and sharing its technical findings with Reliance. NPCIL, CERT-In, India’s Department of Atomic Energy and Prime Minister Narendra Modi’s office declined to comment on the investigation.

Criticism & Security Concerns

Cyber-security experts warn that, even without reactor-core designs, the leaked infrastructure documents could enable adversaries to map support systems, identify contractors and expose supply-chain vulnerabilities. Roth of NTI described the breach as a “serious” risk to plant safety, emphasizing that attackers might target peripheral systems rather than the heavily isolated reactor controls.

Conflicting Reports & Gaps

Researchers could not independently verify the authenticity of the posted files. While the documents contain detailed engineering data, officials have not confirmed any compromise of operational reactor systems. The extent to which the breach affects overall plant security therefore remains uncertain.

Verbatim Quotes

  • “show an adversary not just who has access to the project but which systems that access reaches,” — Nickolas Roth, Nuclear Threat Initiative
  • “In a statement to Reuters, the company said the incident affected data stored on a server hosted by Yotta, a third-party Indian data centre service provider.” — Reliance Group statement
  • “According to the company, the activity was immediately halted and suspected ransomware execution was prevented.” — Yotta statement