The Nuclear Power Corporation of India Limited (NPCIL) has strongly rejected suggestions that sensitive nuclear information was compromised in the latest NPCIL cyber attack. However, in one of the most alarming pieces of cyber attack news to hit the energy sector, the cybersecurity community remains on high alert after thousands of files allegedly linked to the Kudankulam Nuclear Power Plant (KKNPP) surfaced on the dark web following what’s now being called the Kudankulam data breach. The ransomware group known as “World Leaks” claimed responsibility for stealing the data from a hosting provider used by one of the project’s key contractors.
Importantly, the Kudankulam-tagged files are part of a much larger breach. Researchers say the World Leaks ransomware group actually posted roughly 858,000 files tied to the broader Reliance Group, and only around 19,000 of those were specifically tagged with “KKNP” — making the nuclear-linked documents a smaller, especially sensitive subset of a far bigger corporate data theft.
The documents reportedly include engineering drawings, vendor details, inspection records, and other project-related files spanning nearly a decade. While NPCIL maintains that none of the leaked information relates to nuclear safety or reactor systems, some independent security experts warn that the fallout from this cyber attack could still reveal critical details about a strategic facility’s supply chain and support network.
What Happened During the Kudankulam Nuclear Plant Hack?
Cybersecurity researchers reported that the World Leaks ransomware group uploaded approximately 19,000 files, totaling nearly 14.3 GB, to its dark web leak site. The files were specifically tagged with “KKNP,” an acronym referring to the Kudankulam Nuclear Power Plant in Tamil Nadu.
According to initial reports, the documents appear to date from 2016 to mid-2025. They include detailed engineering drawings, supplier information, inspection records, meeting minutes, and insurance documents related to the construction of Units 3 and 4 at the plant. The alleged leak came to light after independent researchers flagged the compromised data on dark web forums.
The sheer volume of stolen information echoes other large-scale leaks we have seen this year. For more context on how threat actors are executing a modern cyber attack to exfiltrate massive quantities of corporate data, you can read our detailed breakdown of the recent Massive Stealer Logs Data Breach June 2026.
How Did the NPCIL Cyber Attack Occur?
Investigators believe the attackers did not directly compromise NPCIL’s highly secured internal nuclear systems. Instead, the breach appears to have originated from a third-party supply chain cyber attack tied to Reliance Infrastructure, which was involved in engineering, procurement, and construction (EPC) work for common infrastructure associated with Kudankulam Units 3 and 4.
Reliance Group described the incident as a “partial breach” involving data hosted on a server operated by third-party data center provider Yotta Data Services. According to Yotta, suspicious ransomware activity was detected on May 29 and was immediately contained, with no confirmed ransomware execution or lateral movement within its systems. However, by the end of June, external threat actors began claiming they possessed stolen data from the server.
The incident has been officially reported to the Indian Computer Emergency Response Team (CERT-In), and enhanced monitoring and additional security controls have since been implemented.
What Information Was Reportedly Leaked in the Kudankulam Data Breach?
- Engineering Schematics: Drawings of cooling and ventilation systems.
- Layout Plans: Architectural blueprints of a common control room.
- Supply Chain Data: Vendor proposals, supplier lists, equipment reviews, and inspection records.
- Internal Communications: Minutes of meetings involving Indian and Russian engineers.
- Financial Documents: Internal insurance documents, including a reported $112 million terrorism insurance policy covering the under-construction units.
Experts remain divided on how serious the exposure is. While there is no evidence that the files contain reactor control software or classified reactor design information, at least one nuclear security expert has cautioned that this type of data could still help attackers map a facility’s support infrastructure — potentially revealing not just who has access to the project, but which internal systems that access could reach.
NPCIL’s Official Response on the Cyber Attack
In a statement issued in mid-July, NPCIL clarified that the compromised documents relate only to the Balance of Plant (BoP) common service facilities. The Balance of Plant refers to all supporting infrastructure required for the plant to function—such as electrical distribution and water treatment—excluding the nuclear reactor itself.
NPCIL emphasized that these systems are entirely separate from nuclear safety and security components. The reactor control networks operate on a highly secure, air-gapped system that is not connected to the internet.
This isn’t the first time Kudankulam has been linked to a cyber incident. In 2019, malware associated with a North Korean state-linked hacking group was discovered on the plant’s administrative network. At the time, NPCIL similarly confirmed that operational and safety systems remained unaffected — a pattern that has now repeated itself with this latest breach.
This incident highlights a growing trend: a modern cyber attack increasingly targets contractors and vendors rather than the primary organization itself. CERT-In is actively investigating the incident alongside NPCIL to determine how attackers bypassed the contractor’s defenses and to strengthen cybersecurity standards across the national supply chain.
Frequently Asked Questions
Was Kudankulam nuclear plant hacked?
The reactor control systems were not hacked — they’re air-gapped and not connected to the internet. What was compromised is a third-party server holding Balance of Plant support documents, unrelated to nuclear safety systems.
How many files were leaked in the NPCIL data breach?
Around 858,000 files were posted from the broader Reliance Group breach, of which roughly 19,000 files (about 14.3 GB) were specifically tagged as Kudankulam-related.
Who is responsible for the Kudankulam data breach?
The ransomware group World Leaks claimed responsibility, saying the data came from a server hosted by third-party provider Yotta Data Services on behalf of Reliance Infrastructure.
Is Kudankulam nuclear plant safe after this cyber attack?
Yes, according to NPCIL. The reactor control networks remain on a separate, air-gapped system that was not part of this breach. CERT-In is investigating to strengthen supply chain security further.
Has Kudankulam faced a cyber attack before?
Yes. In 2019, malware linked to a North Korean hacking group was found on the plant’s administrative network, though NPCIL confirmed operational systems were unaffected at that time as well.
Track Every Breach: See our complete Data Breach 2026 Timeline to stay informed on every major incident this year.
Reported by CyberUpdates365 Desk
Delivering the latest insights on enterprise security, federal AI directives, and the future of IT infrastructure. Follow us for daily updates on how technology is reshaping the corporate landscape.




