Data Security

    NPCIL Says Reactor Systems at Kudankulam Were Unaffected

    Pooja Tikekar (@PoojaTikekar) •
    July 17, 2026    

    Breach Exposes Files Linked to India's Largest Nuclear Plant
    Image: Magnific

    India-based infrastructure and utility contractor Reliance Infrastructure confirmed a “partial breach” after an extortion-only group published on its leak site thousands of files tied to India’s largest power plant.

    “As a routine check-up on ransomware data leak sites, I found that Reliance Infra had been listed as a victim on the website of World Leaks,” independent cybersecurity researcher Rakesh Krishnan told ISMG. “As I already know about Kudankulam Nuclear Power from a 2019 hack incident, while listing the directory in the data leak, the “KKNP” folder quickly grabbed my attention.”

    World Leaks is the rebranded Hunters International operation and part of a growing shift toward extortion-only attacks that rely on data theft rather than file encryption, according to threat intelligence company Group-IB. The approach allows attackers to pressure victims by threatening to leak sensitive information instead of deploying ransomware.

    Krishnan, who reviewed the leaked dataset, said the Reliance Infrastructure dataset is 1.2TB, but the data pertaining to the Kudankulam Nuclear Power Project comprises 18,997 files totaling 14.3GB. He said the exposed records include employee information, personally identifiable information, financial records, tender documents, vendor details, email conversations, technical specifications and equipment layout drawings.

    The Kudankulam-linked files, first flagged by Krishnan, have reportedly been accessible on the leak site since June 11, and represent a subset of a much larger, roughly 858,000-file Reliance Group cache posted by the group. Krishnan said the files were likely obtained because Kudankulam was a Reliance client whose project records resided within the contractor’s network.

    Reliance told Reuters the compromised data was hosted on infrastructure operated by third-party Indian data center provider Yotta.

    The Nuclear Power Corporation of India, which operates the Kudankulam plant, said the leaked material relates only to conventional balance-of-plant facilities and does not include reactor operations, nuclear safety systems or nuclear security infrastructure. The leaked documents reportedly include material related to Kudankulam Units 3 and 4, which remain under construction.

    Yotta told Reuters it detected suspicious activity on a Reliance Infrastructure server in May and contained the activity before ransomware encryption occurred. The company said Reliance later informed it that threat actors had claimed responsibility for a data breach.

    Krishnan said he found no evidence that industrial control systems or operational technology environments had been directly compromised. He added that among the vendors referenced in the leaked files are suppliers of air-handling systems, centrifugal fans and cable trays used in the project – information that could still provide useful intelligence to future attackers even without direct system access.

    This is not the first cybersecurity incident tied to Kudankulam. NPCIL disclosed in 2019 that malware infected a system connected to the plant’s administrative network, but said the incident was isolated from operational systems.

    Share.

    Comments are closed.