Bengaluru: A ransomware group calling itself World Leaks has posted on the dark web a substantial cache of files connected to India's largest nuclear power facility, in what cybersecurity researchers and nuclear-safety experts are describing as one of the more serious infrastructure-linked data breaches to hit the country in recent years. The leaked material, which the group has labelled as originating from Reliance Group, includes purported engineering blueprints of parts of the plant's facilities alongside detailed supplier information. The facility at the centre of the breach is the Kudankulam Nuclear Power Plant, located on the coast of Tamil Nadu in southern India. Kudankulam is not merely one of India's nuclear installations; it is the largest of the country's seven operating nuclear plants and occupies a central place in Prime Minister Narendra Modi's ambitious plans to expand India's atomic energy generation capacity in the years ahead, as the country pushes toward a long-term target of dramatically scaling up its nuclear power fleet. Reliance Group, the Anil Ambani-led conglomerate that has served as one of the contractors on the Kudankulam project, confirmed to Reuters that a partial breach had occurred affecting data hosted on a server operated by Yotta, a third-party Indian data centre provider. In its statement, the company said the government had been informed of the incident, though it stopped short of specifying precisely what data had been compromised or the full extent of the exposure. According to independent cybersecurity researcher Rakesh Krishnan, who first flagged the leak and alerted Reuters, the exposed data set is substantial in scale: nearly 19,000 files totalling roughly 14.3 gigabytes, all indexed under the search term 'KKNP,' an acronym referring to the nuclear plant, have reportedly been accessible online since as early as June 11. Reuters, which reviewed the leaked documents directly, reported that the files carried dates spanning from 2016 through to mid-2025, though the authenticity of every individual document has not been independently verified.
The contents of the leaked material, as reported, are wide-ranging. They reportedly include engineering blueprints, supplier information, meeting records, inspection reports, equipment evaluation documents and insurance policy details. Crucially, the exposed blueprints appear to relate specifically to the ventilation and cooling systems of Unit 3 and Unit 4 of the plant, along with the floor layout of a shared control room, rather than the reactor core systems themselves — an important distinction, given that the reactor technology at Kudankulam's newer units is supplied by Rosatom, the Russian state-owned nuclear firm, and does not appear to feature among the compromised documents. Beyond the technical schematics, the leaked cache reportedly also contained a list of approved suppliers for the project, vendor proposals, and records of a 2024 joint inspection carried out by the Nuclear Power Corporation of India and Reliance Group, complete with accompanying equipment photographs. In a detail that has drawn particular attention, one leaked document is said to reference an insurance policy arranged to provide $112 million in compensation in the event either of the two units suffered an act of terrorism — a figure that underscores the scale of risk contingency planning built into projects of this nature. World Leaks is not a newcomer to India's corporate cybersecurity landscape. The group has previously targeted major companies including Nike and, notably, the Tata Group, whose systems it claimed to have breached in June, alleging it had obtained confidential files that included component designs belonging to Apple and Tesla. In that earlier case, the group reportedly demanded a ransom of $1.5 million, and when Tata declined to pay, proceeded to publish the stolen data — a pattern of behaviour cybersecurity analysts say the group has now repeated with the Reliance-linked Kudankulam files, having reportedly received no response to its ransom queries in this instance either.
The safety implications of the breach have drawn sober assessments from nuclear security specialists. Nickolas Roth, a senior director at the Nuclear Threat Initiative, a body that advises governments and benchmarks countries on nuclear security preparedness, characterised the breach as potentially posing a serious risk to the safety of the plant. Researchers who reviewed the leak noted that such files, even when they do not touch the reactor core itself, could in principle be used by malicious actors to map a facility's support systems, identify its suppliers, and potentially pinpoint security weaknesses in ancillary infrastructure surrounding the reactor. Officially, Indian authorities have offered limited public comment. The Department of Atomic Energy declined to comment on the breach when approached, and the Prime Minister's Office did not respond to queries on the matter. However, subsequent reporting indicated that the Nuclear Power Corporation of India Limited, which operates the plant, stated that the breach did not reveal any sensitive information related to nuclear security specifically — a somewhat reassuring, if narrowly framed, official position that contrasts with the broader unease expressed by independent security researchers reviewing the same material.
NPCIL has reportedly since entered discussions with Reliance Group to better understand the seriousness and scope of the breach, a process that will likely determine what remedial steps, if any, need to be taken regarding physical security protocols, supplier vetting procedures, or digital infrastructure hardening at the plant and its associated contractor networks.
The incident also lands against a backdrop of broader concern about India's overall cybersecurity posture. According to figures cited in industry reporting, India ranks third globally for data breaches, with 28.9 million accounts compromised in 2025 alone, while a striking 73 per cent of surveyed Indian organisations reported being unaware of whether they had even been targeted by an attack — a statistic that speaks to a significant preparedness gap across corporate India, even as the country pushes ahead with ambitious critical infrastructure expansion in sectors ranging from energy to defence to telecommunications.
The breach also highlights a structural vulnerability increasingly recognised in critical infrastructure cybersecurity circles worldwide: attackers frequently do not need to breach the primary operator of a sensitive facility directly. Instead, they can target the wider ecosystem of contractors, subcontractors and third-party data centre providers that support such projects, any one of which can become the weak link through which sensitive information ultimately leaks. In this case, the exposure reportedly occurred not at NPCIL itself, but through a server operated by Yotta on behalf of contractor Reliance Group — precisely the kind of indirect vector that security professionals warn is becoming more common as large infrastructure projects rely on sprawling networks of external vendors.
For India's broader nuclear expansion ambitions — including a newly floated tender for a 2,800 MW nuclear facility in Rajasthan worth over ₹28,000 crore, among other planned projects — the Kudankulam breach serves as a pointed reminder that physical and engineering security must now be matched by equally rigorous digital security across the entire contractor and supply chain ecosystem, not just at the level of the primary state-owned operator.
As investigations into the scope and impact of the leak continue, the episode is likely to intensify scrutiny of how India's expanding portfolio of strategic infrastructure projects manages data security among its web of private contractors, and whether current regulatory frameworks are adequate to enforce consistent cybersecurity standards across an increasingly complex and interconnected project ecosystem.
World Leaks, for its part, did not respond to queries from Reuters regarding the Reliance-linked breach, consistent with its pattern in the earlier Tata Group incident, leaving many of the specifics of how the initial intrusion occurred, and how long the attackers may have had access before the leak was detected, still unresolved.
Cybersecurity analysts note that ransomware groups such as World Leaks typically follow a well-established playbook: infiltrate a target's network, exfiltrate as much sensitive data as possible before detection, encrypt or disrupt the victim's systems to maximise pressure, and then issue a ransom demand with a deadline, threatening public release of the stolen data should payment not be made. The group's stated pattern of publishing data after ransom demands go unanswered, as seen in both the Tata Group and now the Reliance-linked incidents, is a deliberate reputational strategy designed to pressure future victims into paying quickly rather than risk a similar public exposure of their own sensitive files.
For critical infrastructure operators specifically, the calculus around ransom payments is considerably more fraught than for a typical commercial enterprise. Paying a ransom to a criminal group carries obvious ethical and legal complications, potentially funding further criminal activity and inviting regulatory scrutiny, while refusing to pay — as both Tata Group and, seemingly, Reliance Group have done in these instances — accepts the near-certainty of a public data leak in exchange for not directly rewarding the attackers. Neither path is without significant cost, a dilemma that is becoming increasingly common as ransomware groups expand their targeting to include contractors and vendors serving strategic national infrastructure.
The specific vulnerability exploited in this case — a breach occurring through a third-party data centre provider rather than through NPCIL's own systems directly — highlights what security professionals term the 'extended attack surface' problem facing large infrastructure projects. Modern nuclear, energy and defence projects typically involve dozens or even hundreds of contractors, subcontractors, equipment vendors and service providers, each maintaining their own IT systems, data storage arrangements and security practices. Even if the primary operator maintains rigorous cybersecurity standards, the overall security of the project is only as strong as the weakest link across this entire contractor ecosystem — a reality that has repeatedly been exploited by sophisticated attackers targeting critical infrastructure worldwide, not just in India.

India's Computer Emergency Response Team and other national cybersecurity bodies have, in recent years, pushed for stricter data handling and cybersecurity compliance requirements for contractors working on strategic infrastructure projects, though enforcement and implementation across the vast and varied contractor ecosystem serving India's infrastructure build-out remains an ongoing challenge. Incidents such as the Kudankulam-linked breach are likely to intensify calls for more standardised and rigorously audited cybersecurity requirements to be built directly into future contractor agreements for sensitive national infrastructure projects, including the substantial pipeline of new nuclear capacity currently being planned across the country.
For Reliance Group, the breach also arrives at a commercially sensitive moment, as the conglomerate continues rebuilding its standing as a credible infrastructure and engineering partner following a challenging period for the broader group in preceding years. How transparently and effectively the company manages the fallout from this breach — including any remediation steps taken to secure its systems and reassure both NPCIL and the broader public regarding the safety implications of the leak — is likely to factor into its ongoing and future engagements on similarly sensitive government and infrastructure contracts.
The broader question of nuclear facility cybersecurity is one that extends well beyond India's borders. Nuclear security experts globally have, for years, warned that nuclear facilities and their extended contractor networks represent particularly attractive and consequential targets for both criminal ransomware operators and more sophisticated state-linked threat actors, given the potential for even seemingly minor data exposures to be pieced together over time into a more complete picture of a facility's physical layout, security protocols and operational vulnerabilities. International bodies such as the International Atomic Energy Agency have increasingly emphasised cybersecurity as a core pillar of nuclear security frameworks, alongside more traditional physical security and safeguards measures.
As India continues to pursue one of the world's most ambitious nuclear capacity expansion programmes, with new projects such as the recently tendered Mahi Banswara facility in Rajasthan joining an already substantial pipeline of planned reactors, the Kudankulam data breach serves as a timely, if unwelcome, reminder that securing this expanding nuclear footprint will require sustained investment not just in reactors, turbines and civil construction, but in the digital security infrastructure and contractor governance frameworks that increasingly underpin the safe and secure operation of any modern nuclear facility.

Cybersecurity professionals reviewing the incident have also pointed to the value of independent researchers such as Rakesh Krishnan, who first identified the exposed files and alerted international media before the full scale of the breach became widely known. Their work highlights the growing role that independent security researchers play in surfacing breaches that might otherwise go unnoticed for extended periods, particularly in cases where the affected organisations themselves may be slow to detect or publicly acknowledge an intrusion into their systems.
Public reaction to the breach within India has been a mixture of concern and measured reassurance, shaped in large part by the official position that no core reactor-security information was among the exposed files. Even so, opposition political voices and independent security commentators have called for a more transparent public accounting of the breach's full scope, the timeline of when it was first detected internally, and the specific remedial measures being implemented, arguing that greater transparency around such incidents ultimately strengthens rather than undermines public confidence in the safety of the country's nuclear programme.
As the investigation into the breach continues, both NPCIL and Reliance Group are expected to face continued scrutiny over their respective roles in preventing, detecting and responding to the intrusion, with the eventual findings likely to shape not just the immediate remedial response but the broader cybersecurity standards that India's expanding roster of nuclear contractors will be expected to meet going forward.



