Key Takeaways
- The ransomware group World Leaks posted a large cache of files allegedly linked to India’s Kudankulam Nuclear Power Plant, including purported blueprints and supplier information.
- Reliance Group confirmed a “partial breach” of data stored on a third‑party server operated by Yotta, but did not specify the exact content taken.
- The Nuclear Power Corporation of India (NPCIL) stated that the exposed material pertains only to common service facilities and does not affect nuclear safety or security systems.
- Independent researcher Rakesh Krishnan reported nearly 19,000 files (≈14.3 GB) marked with the plant’s acronym “KKNP” have been online since June 11, 2026.
- Cybersecurity experts warn the leak could pose serious risks and highlight India’s growing vulnerability to ransomware attacks on critical infrastructure.
Overview of the breach
On July 16, 2026, Reuters reported that the ransomware collective World Leaks had dumped a substantial volume of data on the dark web that it claimed originated from Reliance Group and related to Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu. The leak surfaced after the group’s typical modus operandi: stealing corporate data, demanding a ransom, and publishing the information when the target refuses to pay. The disclosed files spanned from 2016 to mid‑2025 and were indexed under the search term “KKNP,” the plant’s internal acronym. This incident adds to a growing list of high‑profile ransomware attacks in India, raising concerns about the security posture of firms handling critical infrastructure.
Details of leaked data
According to independent cybersecurity researcher Rakesh Krishnan, the leaked trove consists of nearly 19,000 files totaling approximately 14.3 gigabytes. The documents reportedly include purported blueprints of plant components, supplier details, meeting and inspection records, equipment reviews, and insurance policies. While Reuters could not independently verify the authenticity of every file, the sheer volume and the presence of technical drawings suggest a significant exposure of operational information. Notably, these 19,000 files represent the most sensitive subset of a larger 858,000‑file Reliance dataset that World Leaks had previously posted on its site.
Reliance Group’s statement
Reliance Group, through its subsidiary Reliance Infrastructure, acknowledged a “partial breach” of data residing on a server managed by third‑party Indian data‑centre provider Yotta. The conglomerate confirmed that the breach had been reported to the Indian government but declined to disclose precisely which data had been exfiltrated. Reliance Infrastructure had been awarded a contract in 2018 to design and build infrastructure for KKNPP’s Units 3 and 4, which are still under construction and slated to add 2,000 megawatts of capacity upon completion. The company’s limited commentary leaves open questions about the depth and sensitivity of the compromised information.
NPCIL’s response and safety assurances
The Nuclear Power Corporation of India (NPCIL), which commissions and operates the nation’s nuclear plants, issued a statement asserting that the information appearing in the public domain pertains only to common service facilities and does not involve nuclear safety or nuclear‑security‑related systems. NPCIL emphasized that it has been in direct communication with Reliance regarding the incident and that no critical safety parameters have been compromised. The corporation’s position aims to reassure stakeholders that, despite the leak, the plant’s core protective barriers remain intact.
Cybersecurity context and rising threats
Nickolas Roth, a senior director at the Nuclear Threat Initiative, warned that the breach could pose a “serious” risk to plant safety, noting that even seemingly non‑critical data can be leveraged by adversaries to map facility layouts, identify supply‑chain weaknesses, or plan future intrusions. The incident underscores a broader trend: Indian companies, especially those involved in critical infrastructure, often lack mature cyber‑defense capabilities, making them attractive targets for ransomware groups. World Leaks has previously targeted multinational corporations such as Nike and India’s Tata Group, demonstrating a pattern of extortion followed by public data dumps when ransoms are unmet.
Potential safety implications
While NPCIL downplays the safety relevance of the leaked files, security analysts caution that blueprints of auxiliary systems, inspection logs, and supplier details could be used to refine cyber‑or physical‑attack strategies. Knowledge of service‑facility layouts might enable adversaries to pinpoint choke points, plan sabotage, or exploit maintenance windows. Moreover, the exposure of supplier information could facilitate supply‑chain attacks, where malicious code is introduced via trusted vendors. The combination of technical data and operational records thus warrants a thorough risk assessment, even if immediate nuclear‑safety systems appear unaffected.
Government and investigative actions
In response to the leak, India’s primary cyber‑security agency, the Indian Computer Emergency Response Team (CERT‑In), has launched an investigation into the incident, according to a source familiar with the matter who requested anonymity due to the sensitivity. The agency is coordinating with NPCIL, Reliance, and law‑enforcement entities to trace the breach’s origin, assess the extent of data exfiltration, and mitigate further dissemination. The government’s involvement signals a recognition of the strategic importance of protecting nuclear‑related information from cyber threats.
Conclusion and outlook
The World Leaks disclosure concerning Kudankulam Nuclear Power Plant highlights the intersecting risks of ransomware, supply‑chain vulnerabilities, and the protection of critical national assets. Although NPCIL maintains that no direct safety systems were compromised, the breadth of exposed technical and operational data necessitates vigilant monitoring, enhanced cyber‑hygiene for contractors, and possibly tighter regulatory oversight of data handling practices. As India expands its atomic energy capacity under Prime Minister Narendra Modi’s agenda, fortifying the cyber defenses of associated contractors and facilities will be essential to safeguard both operational continuity and public trust.

