ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

NPCIL denies sensitive data breach at Kudankulam nuclear plant, says leaked files involve only conventional systems

The Nuclear Power Corporation of India Limited on Wednesday rejected characterizations of a sensitive data breach at the Kudankulam Nuclear Power Project, saying that information said to be circulating publicly relates only to conventional balance-of-plant service facilities rather than nuclear safety or security systems.


In a statement issued late Wednesday, Prateek Agarwal, executive director of corporate communications for the corporation in Mumbai, said the engineering, procurement and construction contract covering common service facilities at the plant was awarded to Reliance Infrastructure Limited through a public tender process. Agarwal said the contract’s scope covers engineering, procurement, construction and commissioning of service facilities of a conventional nature, comparable to those found in thermal power plants and other process industries, and unconnected to nuclear safety or security systems.


The statement said the corporation supplied indicative drawings and technical specifications to bidders during the tendering process, and that Reliance Infrastructure then developed detailed engineering drawings in consultation with equipment manufacturers, with designs accepted by the corporation following review.


The denial followed reporting that a ransomware group calling itself World Leaks had posted a large cache of files on the dark web labeled as originating from Reliance Group, the conglomerate led by businessman Anil Ambani, which holds a contract at the plant. The material purportedly included blueprints of facility components and supplier information.


Reliance Group told Reuters there had been a partial breach of its data on a server hosted by third-party Indian data center provider Yotta, and that the Indian government had been informed of the incident. The company did not disclose what data had been affected.


Nickolas Roth, a senior director at the Nuclear Threat Initiative, which advises governments and evaluates nuclear security preparedness worldwide, said the breach could pose a serious risk to the plant’s safety, and said the material could show an adversary not just who has access to the project but which systems that access reaches.


Independent cybersecurity researcher Rakesh Krishnan identified nearly 19,000 files totaling 14.3 gigabytes, appearing under the search term "KKNP," an acronym for the plant, as having been online since June 11. The files were reportedly the most sensitive portion of a larger set of roughly 858,000 Reliance-linked files posted to the World Leaks site.


The documents, dated from 2016 to mid-2025, have not been independently verified. They purportedly included meeting and inspection records, equipment reviews, insurance policies, vendor proposals, a list of approved suppliers and a record of a 2024 joint inspection meeting between the Nuclear Power Corporation and Reliance, along with photographs of equipment. Another document purportedly showed that Reliance Infrastructure and the Nuclear Power Corporation held an insurance policy that would pay out $112 million if either of two units under construction suffered an act of terrorism.


Reliance Infrastructure, a Reliance Group subsidiary, won a contract in 2018 to design and build infrastructure for the plant’s Unit 3 and Unit 4, which remain under construction and are due to become operational by 2027, together adding 2,000 megawatts of capacity. The reactors’ core systems are supplied by Russia’s state-owned Rosatom, and the leaked material did not appear to relate to those core systems, though it purportedly included blueprints for ventilation and cooling systems in Unit 3 and Unit 4 and a floor layout of a common control room.


Yotta said in a statement that it detected suspicious activity on May 29 on a server it hosts on behalf of Reliance Infrastructure, and that the activity was terminated and a suspected ransomware execution was prevented. The company said Reliance Infrastructure later informed it, at the end of June, of claims of a data breach made by external actors. Yotta said it has been unable to verify those claims but has shared a detailed technical investigation with Reliance Infrastructure and supports the ongoing inquiry.


World Leaks, which has previously targeted Nike and India’s Tata Group, did not respond to questions about the Reliance breach. In June, the group said it had sought $1.5 million in ransom for Tata Group files containing component designs belonging to Apple and Tesla, and said it published the data after Tata did not meet the demand.


The Kudankulam plant, in Tamil Nadu, is the largest of India’s seven nuclear facilities and central to Prime Minister Narendra Modi’s plans to expand the country’s atomic energy capacity. After commissioning two 1,000-megawatt VVER reactors, the plant is constructing four additional units using Russian technology, with a planned total generating capacity of 6,000 megawatts. In 2019, the plant faced a separate incident involving a North Korean malware infection on its administrative network, which the corporation at the time said did not compromise what it described as an unbreachable standalone network.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543