Critical Incident (July 2026): The ransomware group World Leaks has published 19,000 files (14.3 GB) allegedly stolen from systems related to the Kudankulam Nuclear Power Plant — India’s largest nuclear facility. The leaked data includes blueprints for reactor ventilation and cooling systems, floor layouts for Units 3 and 4, supplier records, and inspection reports dating 2016–2025. The breach was accessed via a Reliance Group server hosted by Yotta Data Services. NPCIL has disputed the sensitivity of the leaked information, while cybersecurity experts call the exposure “serious.”
India’s largest operational nuclear power plant, Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu, has become the subject of the country’s most alarming critical infrastructure data breach of 2026. The ransomware group World Leaks published approximately 19,000 files totalling 14.3 gigabytes on its dark web leak site — a cache it claims was stolen from servers managed by Reliance Group through cloud infrastructure operated by Yotta Data Services.
The files, which were accessible from June 11, 2026 — over a month before public disclosure — include detailed blueprints for the plant’s ventilation systems, cooling infrastructure, floor layouts for Units 3 and 4, supplier lists, equipment reviews, and inspection records. Cybersecurity researcher Rakesh Krishnan first identified the leak and alerted media and government authorities.
What Was Leaked: Inside the 19,000 Files
The World Leaks dump contains a range of documentation that, in aggregate, provides a detailed map of the Kudankulam plant’s physical and mechanical systems:
| Category | Contents | Sensitivity |
|---|---|---|
| Structural Blueprints | Ventilation, cooling systems, floor layouts — Units 3 & 4 | High |
| Supplier Records | Names, contracts, component specifications of equipment vendors | Medium-High |
| Inspection Records | Safety inspection reports, equipment review logs (2016–2025) | Medium |
| Technical Drawings | Engineering drawings of support systems | High |
| Internal Communications | Emails and project coordination documents | Medium |
Security experts who reviewed the cache note that while the data does not appear to include nuclear fuel handling procedures or weapons-grade material specifications, the physical plant blueprints are themselves a significant intelligence asset for adversaries planning physical or cyber-physical attacks against the facility.
The Attack Chain: Third-Party Breach via Contractor
Critically, the breach did not directly compromise NPCIL’s (Nuclear Power Corporation of India Limited) own networks — which would be classified as extremely sensitive government infrastructure. Instead, attackers targeted Reliance Group, which is a contractor involved in the construction of Kudankulam Units 3 and 4, and specifically the Reliance data stored on servers operated by Yotta Data Services, a major Indian data centre and cloud services provider.
Reliance Group confirmed the incident and described it as a “partial breach” of data stored on a third-party server. The attack represents a classic supply chain / third-party breach — where the primary target (the nuclear plant itself) is never directly attacked, but sensitive data is accessed through a less-secured contractor or service provider.
The attack chain likely followed this path:
- Target selection: World Leaks identified Reliance Group as holding construction and technical data for Kudankulam Units 3 & 4 — a contractor with access to sensitive plant documentation
- Initial access: Exploitation of Reliance Group’s systems or the Yotta-hosted infrastructure — likely through a combination of credential theft, vulnerable public-facing services, or phishing of Reliance employees
- Data discovery: Threat actors found and catalogued the nuclear plant documentation stored on Reliance’s contractor servers
- Exfiltration: 14.3 GB exfiltrated — files accessible since June 11, 2026
- Publication: Files posted to World Leaks dark web portal to maximise pressure for ransom payment
Who is World Leaks?
World Leaks is a ransomware-as-a-service operation that emerged in 2025, positioning itself as a data extortion group targeting large enterprises and critical infrastructure. The group operates a dark web leak site where it publishes data from victims who fail to pay ransom demands.
World Leaks is notable for:
- Targeting high-profile, media-attractive victims to maximise negotiation pressure
- Publishing partial datasets publicly while retaining more sensitive data as leverage
- Operating across multiple geographies — their victim list includes organisations in Asia, Europe, and North America
- Using legitimate cloud and storage infrastructure for initial staging of stolen data before transfer to their own infrastructure
NPCIL’s Response: Denials Amid Evidence
The Nuclear Power Corporation of India Limited issued a statement asserting that the leaked data does not reveal any sensitive information related to nuclear security. NPCIL emphasised that the breach occurred on a contractor’s third-party server, not on NPCIL’s own systems.
However, independent cybersecurity experts challenge this framing. A facility blueprint for ventilation and cooling systems — even if it does not contain nuclear weapon specifications — provides adversaries with:
- Knowledge of critical dependencies in the cooling infrastructure that, if disrupted, could lead to a Fukushima-type scenario
- Identification of suppliers and their components — enabling supply chain attacks that introduce compromised hardware
- Understanding of physical access points, floor layouts, and security checkpoints
- Awareness of past safety issues identified in inspection reports
This mirrors the 2019 Kudankulam cyber incident, when North Korean threat group Lazarus (DTrack malware) was found to have compromised the plant’s administrative network. That time, NPCIL also initially denied the breach before acknowledging it weeks later. The pattern of initial denial followed by partial acknowledgment has become a concern for nuclear security observers.
Kudankulam’s Strategic Importance
Kudankulam Nuclear Power Plant, built in collaboration with Russia (Rosatom), is India’s largest nuclear power facility:
- Located in Tirunelveli district, Tamil Nadu
- Currently operational: Units 1 and 2 (2 × 1,000 MWe VVER reactors)
- Under construction: Units 3 and 4 — the subject of this breach’s blueprints
- Planned: Units 5 and 6
- Total planned capacity: 6,000 MWe — a significant fraction of India’s nuclear power target
- Supplies electricity to Tamil Nadu, Kerala, Karnataka, and Puducherry
The construction data for Units 3 and 4 is particularly sensitive because these units are not yet operational — meaning a physical attack informed by the leaked blueprints could target the facility while its safety systems are still being commissioned and tested, when safeguards are at their most vulnerable.
The Yotta Data Services Connection
Yotta Data Services, one of India’s largest data centre operators, hosts infrastructure for numerous government and enterprise clients. The involvement of Yotta in this breach raises questions about:
- The classification of data that private data centres are permitted to host on behalf of defence contractors working on nuclear projects
- Yotta’s security posture and access controls for sensitive government-adjacent workloads
- Whether NPCIL and the Department of Atomic Energy have established clear guidelines for what data contractors may store on commercial cloud or data centre infrastructure
India’s DPDP Act (Digital Personal Data Protection Act) 2023 and the forthcoming regulations around Critical Information Infrastructure Protection under IT Act Section 70 will need to explicitly address how contractors handling nuclear-related data must store and protect that data.
Nuclear Facility Cybersecurity: The Global Picture
Kudankulam is not isolated. Nuclear facilities worldwide have become priority targets for APT groups:
- 2021 — Israel Dimona (attempted): Iranian group attempted water system tampering at a facility near the nuclear research centre
- 2021 — Natanz, Iran: Stuxnet follow-up attacks disrupted centrifuge operations
- 2022 — Zaporizhzhia, Ukraine: Russian military takeover of the plant highlighted the physical-cyber nexus in nuclear security
- 2019 — Kudankulam: Lazarus Group DTrack malware found on administrative network
- 2020 — India power grid: Chinese RedEcho APT pre-positioned in Maharashtra power grid infrastructure
The International Atomic Energy Agency (IAEA) has called for nuclear facilities worldwide to implement cybersecurity frameworks aligned with its NSS-17-T technical guidance. India’s implementation of these standards across its nuclear complex remains uneven.
Immediate Actions Required
For NPCIL, AERB (Atomic Energy Regulatory Board), and India’s nuclear security apparatus:
- Comprehensive contractor security audit: All contractors with access to nuclear plant documentation must undergo immediate cybersecurity audit, with particular attention to data stored on commercial cloud and data centre platforms
- Data classification enforcement: Nuclear-adjacent blueprints and technical specifications must be explicitly classified and stored only on certified, air-gapped government networks — not on commercial infrastructure regardless of the contractor’s designation
- Dark web monitoring: India’s CERT-In and NCIIPC should maintain active dark web intelligence coverage of all nuclear-related data
- Yotta security review: An independent security audit of Yotta’s infrastructure and access controls for all government-adjacent workloads
- Physical security review of Units 3 & 4 construction site: Given that blueprints are now public, physically assess whether the construction site’s security posture needs reinforcement
Conclusion
The Kudankulam data breach illustrates a fundamental truth about modern cybersecurity: the strongest perimeter is only as secure as its weakest contractor. NPCIL’s direct networks may be hardened, but the technical blueprints of India’s largest nuclear plant are now in the hands of a ransomware group because a contractor’s commercial server wasn’t adequately protected.
Nuclear security is national security. The contractor supply chain around India’s nuclear programme must be held to the same cybersecurity standard as the plants themselves. For critical infrastructure organisations assessing their third-party risk and supply chain security posture, contact Vivek Verma for a security assessment.
Sources: The Wire — World Leaks / NPCIL Report | Eastern Herald — Nuclear Breach Analysis | Al Jazeera — India Nuclear Plant Breach