India’s state-owned nuclear operator says documents posted online by a cybercrime group do not contain information tied to nuclear safety or security at Kudankulam, the country’s largest nuclear power plant.
The Nuclear Power Corporation of India Limited, or NPCIL, said the files appear to concern engineering, procurement and construction work for conventional balance-of-plant facilities at Kudankulam. In nuclear-plant terms, that means support infrastructure outside the reactor and its safety systems. NPCIL said the material does not relate to nuclear safety systems, nuclear security systems or related information.
The statement followed Reuters reporting that World Leaks, a cyber-extortion group, had published thousands of files that appeared to be connected to Kudankulam Nuclear Power Plant Units 3 and 4, which are under construction near India’s southern tip. The reported documents included engineering drawings, supplier data, inspection records and insurance paperwork.
Science and Technology Minister Jitendra Singh also rejected suggestions that sensitive nuclear information had been exposed, according to local media. He said there was no immediate need for a wider security review.
Contractor systems, not reactor systems
The trail described publicly points to a contractor breach rather than a compromise of nuclear operations. The files published by World Leaks were labeled as coming from Reliance Group. Reliance Infrastructure, a Reliance Group subsidiary, is building non-nuclear infrastructure for the new Kudankulam units.
Reliance Group told Reuters it had experienced a partial breach involving data kept on infrastructure hosted by Indian data center provider Yotta. The company said it notified the Indian government, but it did not publicly detail what was accessed.
Yotta said it found suspicious activity in late May on a Reliance Infrastructure server it hosts and stopped the activity immediately. Yotta described the incident as a suspected ransomware execution that it prevented. The company said Reliance later told it that outside threat actors claimed to have stolen data.
Yotta said it has not independently confirmed those theft claims. It said it shared forensic findings with Reliance Infrastructure and is still assisting the investigation.
Independent cybersecurity researcher Rakesh Krishnan, who documented the alleged leak, said World Leaks published the Kudankulam-related data on June 11 after its usual countdown timer expired. Krishnan said the attackers may have used exposed remote desktop services, phishing or a Fortinet vulnerability, but he also said there is no public proof confirming how the intrusion happened.
Krishnan said the posted set contained nearly 19,000 files, totaling about 14.3 GB, with dates ranging from 2016 to mid-2025. He said the material appeared to include engineering drawings, supplier records, meeting documents, inspection reports and insurance files.
The authenticity of the files has not been independently verified. Neither Reliance nor Indian authorities have publicly named the attackers behind the intrusion or said how they got in.
A familiar target, a newer extortion brand
Kudankulam has dealt with cybersecurity scrutiny before. In 2019, malware that researchers later associated with North Korea’s Lazarus Group was found on an internet-connected administrative network at the plant. NPCIL said at the time that the infected system was separated from reactor control and operational networks. India’s CERT-In concluded that plant operations were not affected.
World Leaks has recently claimed other Indian targets. Last month, the group claimed responsibility for a breach at Tata Electronics, an Indian manufacturer that supplies Apple, Tesla and Qualcomm. It demanded $1.5 million and later published what it claimed were confidential engineering documents after saying Tata refused to pay.
The group appeared in early 2025 after Hunters International, a ransomware operation, rebranded. Its recent activity has leaned toward stealing and publishing data for extortion rather than relying mainly on file encryption, according to public reporting on the group.
This story draws on original reporting from The Record.