Lead

A ransomware group has published a large cache of files online that it claims are connected to India's largest nuclear power plant, including purported blueprints and supplier details. The files, which were posted on the dark web by a group called World Leaks, are said to have originated from Reliance Group, a contractor for the Kudankulam Nuclear Power Plant in Tamil Nadu.

The Nuclear Power Corporation of India, which operates the plant, said the breach did not reveal any sensitive information related to nuclear security. However, experts have cautioned that the exposure of such documents could pose a "serious" risk to the safety of the facility.

Coverage Comparison

Reports from Al Jazeera, Dawn, and The Jerusalem Post, all citing Reuters, describe similar facts: the leak includes purported blueprints of parts of the plant and supplier details. Reliance Group, owned by Indian businessman Anil Ambani, confirmed a "partial breach" of its data on a server hosted by Yotta, a third-party Indian data center service provider, and said the government had been informed. The company did not disclose which data had been breached.

While Al Jazeera focused on the Nuclear Power Corporation's downplaying of the incident, both Dawn and The Jerusalem Post emphasized the potential risks highlighted by experts. All three outlets noted that the breach underscores the increasing frequency of cyberattacks in India, where many companies are ill-equipped to handle such threats.

Key Claims

  • World Leaks, a known ransomware group that has previously targeted Nike and India's Tata Group, posted the files on the dark web. The documents, dated from 2016 to mid-2025, were reviewed by Reuters, which could not verify their authenticity. They reportedly include meeting and inspection records, equipment reviews, and insurance policies, in addition to blueprints and supplier details.
  • Nearly 19,000 files, totaling 14.3 gigabytes, appear to be related to the Kudankulam plant, searchable under the acronym "KKNP." These files were online since June 11, according to independent cybersecurity researcher Rakesh Krishnan, who first alerted Reuters to the leak. The 19,000 files were described as the most sensitive among 858,000 Reliance files on the World Leaks website.
  • The Kudankulam plant is the largest of India's seven nuclear plants and is central to Prime Minister Narendra Modi's plans to expand the country's atomic energy capacity. A subsidiary of Reliance, Reliance Infrastructure, won a contract in 2018 to design and build infrastructure for the plant's Units 3 and 4, which are under construction and expected to be operational by 2027, providing a combined 2,000 megawatts.
  • India ranks third among countries suffering the most data breaches, with 28.9 million accounts compromised last year, as reported by multiple outlets.
  • Nickolas Roth, a senior director at the Nuclear Threat Initiative, which advises governments on nuclear security, said the breach could pose a "serious" risk to the plant's safety.

Perspectives

The Nuclear Power Corporation of India has stated that the data breach did not reveal any sensitive information related to nuclear security, suggesting that the impact on the plant's safety is limited.

Security experts, including Nickolas Roth of the Nuclear Threat Initiative, have expressed concern that the exposure of such documents could pose a "serious" risk to the plant's safety, highlighting a potential divergence from the official assessment.