Breaking News
Loading latest updates...
Loading latest updates...
Markets
Loading market data...
Loading market data...
Loading market data...
Loading market data...
Loading market data...
India's Nuclear Power Security Breach: Over 19,000 Blueprints and Files of Kudankulam Nuclear Plant Leaked on Dark Web!
Cybersecurity

India's Nuclear Power Security Breach: Over 19,000 Blueprints and Files of Kudankulam Nuclear Plant Leaked on Dark Web!

India's largest nuclear power station, the Kudankulam Nuclear Power Plant, faces a severe cyber security assessment after the ransomware group "World Leaks" published over 19,000 sensitive project files, blueprints, and engineering plans on the dark web through a contractor's server.

user avatar

Muhammad Mubashir

2 min read
53
0

⚠️ Dark Web Data Leak Hits Contractor of India's Kudankulam Nuclear Power Plant

A major cybersecurity incident has shaken India's critical infrastructure sector. The data-extortion group known as World Leaks published a massive cache of over 19,000 highly detailed files and blueprints related to the Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu—India’s largest nuclear power facility.

Supply-Chain Cyber Vulnerability

The security breach did not target the plant's operational technology (OT) directly. Instead, it occurred via a third-party supply chain compromise.

The files were exfiltrated from a server hosted by Indian data center provider Yotta, which was utilized by Reliance Infrastructure Limited—the primary engineering contractor tasked with building common service facilities for the upcoming Units 3 and 4 of the plant.

Detail Specifications & Incident Status
Target Plant Kudankulam Nuclear Power Plant (KKNPP), India
Exposed Contractor Reliance Infrastructure Limited (Anil Ambani Group)
Threat Actor World Leaks (Ransomware/Data-Extortion Group)
Total Compromised Files Over 19,000 specific KKNPP files (out of 858,000 leaked corporate files)
Document Dates Covering project blueprints, logs, and designs from 2016 to mid-2025
Investigation Agencies CERT-In (Computer Emergency Response Team) and NPCIL

What Was Leaked?

The leaked cache uploaded to the dark web includes:

  • Detailed engineering blueprints and floor layouts of common control rooms.

  • Ventilation, cooling, and water piping designs for under-construction units.

  • Supplier directories, meeting logs, equipment evaluations, and joint Indo-Russian inspection records.

Official Response: Is the Nuclear Core Safe?

The Nuclear Power Corporation of India Limited (NPCIL) quickly issued a public clarification to ease national security concerns.

Official NPCIL Statement:

"The leaked material pertains only to 'conventional balance of plant common service facilities'. These are standard industrial infrastructure systems similar to those in thermal power plants and do not involve any nuclear safety or core reactor control systems, which remain completely isolated and air-gapped."

Nonetheless, cyber warfare experts warn that having high-fidelity engineering layouts of secondary systems in public space still gives bad actors crucial intelligence regarding physical entry points and system interdependencies. CERT-In is currently executing a deep-dive analysis to locate the exact security failure that allowed this massive data extraction.


Discussion

Comments (0)

Sort By:

No comments yet.

Related Topics

More For You