Dark Web Breach Hits Kudankulam Nuclear Plant: 19,000 Sensitive Files Exposed via Contractor Server
A ransomware group known as “World Leaks” has published thousands of engineering blueprints, vendor records, and layout plans for India’s flagship nuclear facility on the dark web. While top officials downplay the intrusion, internal sources warn of severe security vulnerabilities.
At a Glance
Ransomware group World Leaks accessed over 19,000 sensitive files (dating between 2016 and mid-2025) linked to the Kudankulam Nuclear Power Plant (KKNPP). The leak originated from third-party server provider Yotta, hosting data for project contractor Reliance Group.
Exposed documents include blueprints for control room layouts, cooling and ventilation systems, equipment inspection reports, and supplier lists for under-construction Units 3 and 4.
Nuclear Power Corporation of India Limited (NPCIL) claims the compromised files relate strictly to non-nuclear “common service facilities” and pose no risk to nuclear safety.
System Blueprints Exposed Online
India’s largest nuclear project, the Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu, is facing a major cyber incident following the unauthorized release of nearly 19,000 sensitive operational and engineering files on the dark web.
The security breach did not originate from KKNPP’s internal networks directly, but rather through a third-party server operated by data center provider Yotta. The server housed data belonging to Anil Ambani’s Reliance Group, whose subsidiary, Reliance Infrastructure, was awarded an engineering and construction contract in 2018 for common service infrastructure across Units 3 and 4.
Reliance confirmed a “partial breach” on the external server, noting that the Indian government and relevant cybersecurity agencies had been informed.
“Absolute Commotion” Inside KKNPP vs. Official Dismissals
Inside the nuclear park’s administration, sources describe the atmosphere as one of “absolute commotion,” with senior officials struggling to gauge the full damage. Experts warn that exposed facility layouts and vendor details could allow hostile adversaries to map support infrastructure and exploit secondary supply-chain vulnerabilities.
However, project proponent NPCIL moved quickly to counter panic:
“The files leaked are not related to KKNPP plant safety or nuclear safety. They are ordinary files pertaining to conventional balance-of-plant common service facilities, which are typical to any thermal power plant.”
— Official Statement, NPCIL
Incident Timeline & History
| Date | Incident Milestone |
| May 29 | Suspicious activity detected on Yotta’s third-party server. |
| Late June | Incident formally reported following external data breach claims. |
| July 15 | News breaks of 19,000+ files uploaded to the dark web; CERT-In launches probe. |
This breach revives uncomfortable memories of KKNPP’s 2019 cyber incident, where a North Korean malware infection was detected on the plant’s administrative network. At the time, NPCIL similarly brushed aside concerns, stating its operational reactor systems remained air-gapped and unbreachable.
As investigations by the Computer Emergency Response Team (CERT-In) and NPCIL continue, key plant leadership—including Site Director Ashok Bhatiya and Station Director V.P. Sunil—have remained unreachable for public comment.
