New Delhi: A major cybersecurity incident has raised fresh concerns over the security of India’s critical infrastructure after a ransomware group allegedly published thousands of sensitive files linked to the Kudankulam Nuclear Power Plant (KNPP) on the dark web.
According to reports, the ransomware group World Leaks has released more than 19,000 sensitive files, part of a larger cache of nearly 8.58 lakh documents allegedly stolen from Reliance Group, one of the contractors involved in the expansion of the nuclear power plant.
The Kudankulam Nuclear Power Plant, located in Tamil Nadu, is India’s largest nuclear power facility and plays a crucial role in the country’s plans to significantly expand nuclear energy generation.
What has reportedly been leaked?
According to Reuters, the leaked documents allegedly include engineering blueprints, supplier information, inspection records, insurance documents and internal project-related files connected to Units 3 and 4 of the Kudankulam project, which are currently under construction. Reuters reviewed the documents but said it could not independently verify their authenticity.
The 19,000 files are believed to represent the most sensitive portion of the total data allegedly stolen by the hackers.
Cybersecurity experts have warned that such information could potentially help malicious actors understand the facility’s infrastructure and identify possible vulnerabilities if the documents are genuine.
Reliance Group confirms partial breach
Reliance Group acknowledged that there had been a partial data breach involving one of its servers hosted by third-party data centre provider Yotta.
The company said the incident had been reported to the relevant government authorities but did not disclose the exact nature of the compromised information.
There has been no official confirmation that the operational systems of the Kudankulam Nuclear Power Plant itself were compromised.
Authorities launch investigation
Following reports of the breach, India’s cybersecurity agencies and nuclear authorities have initiated an investigation into the incident.
According to Reuters, the Indian Computer Emergency Response Team (CERT-In) and the Nuclear Power Corporation of India Limited (NPCIL) are examining the scope of the breach and assessing whether any national security risks have arisen from the leaked data.
However, there has been no official statement from the Prime Minister’s Office or the Department of Atomic Energy regarding the reported leak.
Experts warn of security implications
Cybersecurity specialists have described the reported breach as a matter of serious concern.
Nickolas Roth, Senior Director at the Nuclear Threat Initiative, said exposure of such documents could create significant risks by enabling adversaries to map infrastructure and understand sensitive systems associated with the nuclear facility.
Experts note that while operational control systems may remain isolated from administrative networks, information leaks involving infrastructure layouts and supplier details can still present security challenges.
Kudankulam’s strategic importance
The Kudankulam Nuclear Power Plant is one of India’s most important energy projects and forms a key pillar of the government’s nuclear expansion programme.
Units 3 and 4, currently under construction, are expected to generate a combined 2,000 megawatts of electricity once operational, strengthening India’s clean energy capacity.
The project has previously faced cybersecurity concerns. In 2019, NPCIL confirmed that malware had infected an administrative network at the plant, although it maintained that critical operational systems remained unaffected.
Growing focus on cybersecurity
The latest incident highlights increasing cybersecurity risks facing India’s critical infrastructure.
As digital systems become more integrated into infrastructure projects, experts have repeatedly called for stronger cyber resilience, enhanced monitoring and stricter safeguards for contractors handling sensitive government projects.
Authorities are expected to continue their investigation to determine the authenticity of the leaked files, assess their impact and strengthen cybersecurity measures where necessary.
Conclusion
The reported leak of thousands of files linked to the Kudankulam Nuclear Power Plant has raised fresh questions about cybersecurity at critical infrastructure facilities. While investigations are underway and there is no confirmation that operational systems were compromised, the incident underscores the growing importance of protecting sensitive infrastructure data from increasingly sophisticated cyber threats.
