Ransomware Group Leaks 19,000 Kudankulam Files From Reliance Server, NPCIL Denies 'Sensitive' Breach
The Wire Staff
Real journalism holds power accountable
Since 2015, The Wire has done just that.
But we can continue only with your support.
New Delhi: A ransomware group World Leaks has posted thousands of highly sensitive files linked to India's largest nuclear power plant on the dark web, labelling the data as coming from the Reliance Group, prompting the Nuclear Power Corporation of India Limited (NPCIL) on Wednesday (July 15) to publicly deny that any sensitive information had been compromised.
The files, pertaining to the Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu, are tied to an expansion of the plant with four additional reactor units under construction with Russian technical assistance, into what is set to become India's largest nuclear park with a combined capacity of 6,000 MW.
Reliance Infrastructure, part of Anil Ambani's Reliance Group, won a contract in 2018 to build infrastructure for units three and four, both still under construction and expected to add 2,000 MW of capacity by 2027.
The data breach
Independent cybersecurity researcher Rakesh Krishnan, who first alerted Reuters of the leak, said close to 19,000 files totalling 14.3 gigabytes, which appear when the term "KKNP" is searched, have been online since June 11.
Reuters reviewed the documents, dated between 2016 and mid-2025, however, it could not verify their authenticity. Nevertheless, according to the news agency's report, the files appeared to be "most sensitive" of a much larger set of 858,000 Reliance-related files posted on World Leaks' website.
The leaked documents purportedly contain blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies.
Reliance confirms a 'partial breach'
Reliance Group, in a statement to Reuters, confirmed that there was a "partial breach" of data on a server hosted by a third-party data centre service provider Yotta and said the incident had been reported to the government. It did not disclose what data had been accessed.
Reliance Infrastructure was awarded the engineering, procurement and construction contract for the plant's common service facilities through a public tender process. NPCIL stated that it had provided bidders with indicative drawings and technical specifications, based on which Reliance Infrastructure prepared detailed blueprints in consultation with the original equipment manufacturers. The final designs were accepted by NPCIL after review.
As per the Reuters report, Yotta said it detected suspicious activity on the server on May 29 and had immediately terminated it, preventing what it described as an attempted "ransomware execution."
Yotta noted that Reliance Infrastructure had informed it only at the end of June that external actors were claiming a data breach, adding that it could not verify claims of the "external threat actor." The service provider also shared technical findings with Reliance and is supporting the ongoing investigation.
NPCIL says data is not nuclear-related
In its statement released on Wednesday (July 15), NPCIL said the information reported to be publicly available pertains only to "conventional balance of plant common service facilities." Independent analysis by Reuters also revealed that the documents posted on World Leaks did not seem to concern the nuclear reactors' core systems, which are supplied by Russia's state-owned Rosatom.
The data reportedly includes blueprints for the ventilation and cooling systems used in Units three and four, the complete floor layout of a "common control room," vendor proposals, a list of approved suppliers and records of a 2024 joint inspection meeting between NPCIL and Reliance engineers, along with photographs of equipment.
Also read: India's Nuclear Liability Fund Has Hit Its Cap, But It Is Not Enough
One document shows that Reliance Infrastructure and NPCIL had taken out an insurance policy that would pay out $122 million if either of the two units – three or four – suffered an "act of terrorism."
Nevertheless, Nicholas Roth, a senior director at the Nuclear Threat Initiative, told Reuters that the breach could potentially pose a "serious" threat to the safety of the plant. The files can be used to outline the plant's support systems, identify suppliers and pinpoint weaknesses in the security chain.
"[The data could] show an adversary not just who has access to the project but which systems that access reaches," said Roth.
He added that the breach exemplifies how cyberattacks in India have grown more common, while several companies remain ill-equipped to handle such threats.
'Absolute commotion' inside the plant
According to The Hindu, sources within KKNPP said the leak had triggered "absolute commotion" among the project's leading team, who were said to be initially "completely clueless" about this development which could pose serious security risks by allowing adversaries to map the plant's support systems and identify vulnerabilities.
On the other hand, a senior NPCIL official maintained that the leaked files were "ordinary" in nature, common to any thermal power plant and unrelated to plant safety. KKNPP site director, station director and the plant's senior human resources and public relations official could not be reached for comment when contacted by The Hindu.
Not the first cyber scare at KKNPP
The incident marks the second time the KKNPP has been linked to a cyber incident. In 2019, malware traced to a North Korean hacker group was found on the plant's administrative network. At the time, NPCIL said the matter was investigated immediately and the plant systems were unaffected.
This article went live on July sixteenth, two thousand twenty six, at thirty minutes past twelve at noon.The Wire is now on WhatsApp. Follow our channel for sharp analysis and opinions on the latest developments.
