Hackers claim data leak at India's largest nuclear plant
Hacker group World Leaks claims thousands of documents from Kudankulam Nuclear Power Plant have been leaked.
The hacker group 'World Leaks' has claimed that thousands of documents related to India's largest nuclear power plant, Kudankulam, have been leaked. According to a report by news agency Reuters, 'World Leaks' has claimed that it has uploaded these documents on the dark web.
As per Reuters, the leaked documents include blueprints of some parts of the power plant, a list of suppliers, records related to the control room, and other technical documents. The server was hacked in May, and the data leak was claimed in June, but the information has come to light now.
Anil Ambani's Reliance Group, working on the Kudankulam project in Tamil Nadu, has confirmed that the server of the third-party data center company Yotta was the victim of a cyber attack. The company has informed the government about this incident.
The ransomware group 'World Leaks' claims to have made public more than 19,000 documents related to the Kudankulam project. These documents are part of a large data set of 8.58 lakh files stolen from the Reliance Group.
According to the report, most of the documents are related to Unit-3 and Unit-4 of the Kudankulam nuclear plant, which are under construction and expected to be operational by 2027. The leaked files include engineering blueprints of the ventilation and cooling systems, floor layout of the common control room, inspection reports of equipment, supplier lists, vendor proposals, meeting records, and insurance-related documents. Nicholas Roth, Senior Director of the Nuclear Threat Initiative, said that
if this data breach proves to be true, it could pose a "serious" threat to the plant's security.
According to independent cybersecurity researcher Rakesh Krishnan,
around 19,000 files related to the KKNP search term, with a total size of 14.3 gigabytes, have been available online since June 11.
However, Reuters reviewed these files dated from 2016 to mid-2025 but could not independently verify their authenticity. On the World Leaks website, these 19,000 documents are described as the most sensitive among the total 8.58 lakh files related to Reliance.
Nuclear Power Corporation of India Limited (NPCIL) is reviewing the entire matter in collaboration with Reliance. Meanwhile, the Indian Computer Emergency Response Team (CERT-In) is also investigating the data leak. Nuclear security experts say that if these documents on the dark web are genuine, they could allow an attacker to better understand the plant's support systems, supply chain, and security framework. This could increase the risk of cyber attacks or other security threats in the future.
It is noteworthy that the Kudankulam Nuclear Power Plant has previously been a victim of a cyber attack. In 2019, malware linked to a North Korean hacker group was confirmed to be found in the plant's administrative network. However, at that time, NPCIL clarified that the plant's operational system remained completely secure and was not affected by the attack.