World Leaks Exposes Kudankulam Nuclear Plant Files in a Breach of India’s Reliance Group

Kudankulam nuclear plant data breach: leaked engineering blueprints and supplier records from India's largest nuclear power station

A major leak has struck documents tied to the construction of India’s largest nuclear power plant. Alleged engineering-system blueprints, supplier details, inspection reports, and insurance papers have all surfaced in the public domain.

The Source: A Reliance Group Server

The ransomware group World Leaks published a trove of data on the dark web that, by its own account, belongs to India’s Reliance Group. One of the group’s companies is helping build the third and fourth power units of the Kudankulam nuclear plant in the state of Tamil Nadu.

Reliance Group confirmed that some data leaked from a server hosted with the third-party data-center operator Yotta. The company notified the authorities, yet it did not disclose the exact composition of the stolen information.

Nearly 19,000 Files Spanning Nine Years

Cybersecurity specialist Rakesh Krishnan found almost 19,000 files, totaling 14.3 GB, related to the Kudankulam plant among the published materials. The documents span the period from 2016 to mid-2025. Reuters examined the materials but could not independently verify their authenticity.

The archive allegedly contains ventilation and cooling blueprints for the third and fourth units, a diagram of the shared control point, contractor proposals, lists of approved suppliers, meeting minutes, and equipment photographs. One document describes a $112 million insurance contract covering a possible terrorist act against the units under construction.

What Was and Was Not Affected

The materials are not connected to the core nuclear reactor systems supplied by the Russian state corporation Rosatom. India’s Nuclear Power Corporation stated that the published information concerns only general auxiliary facilities and does not touch nuclear-safety systems.

Nicholas Roth of the Nuclear Threat Initiative nonetheless warned that such documents could help attackers study the station’s auxiliary infrastructure, identify key suppliers, and locate weak points in the security chain. In his words, the data can reveal not only the circle of people with access to the project, but also the systems associated with them.

How the Intrusion Unfolded

Yotta reported that on May 29 it detected suspicious activity on a Reliance Infrastructure server. The operator halted the activity and, it claims, prevented the ransomware from launching. In late June, Reliance Infrastructure notified Yotta of the attackers’ assertions that they had stolen data. So far, the operator has been unable to confirm those claims and has handed the results of its technical review to the client.

A Prolific Extortion Group

In all, World Leaks posted roughly 858,000 Reliance files. The group typically publishes stolen corporate data after victims refuse to pay a ransom. Previously, World Leaks claimed to have attacked Nike and India’s Tata Group.

The third and fourth units of the Kudankulam plant are still under construction. They are scheduled to enter service by 2027, with a combined capacity of 2,000 MW.

Not the Station’s First Cyber Incident

The plant has faced a computer incident before. In 2019, investigators discovered malware linked to a North Korean group on the internal administrative network. At the time, the operator declared that the plant’s control systems had not been affected.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply