A massive cache of 1.2 TB, including a 14.3 GB set of 18,997 files tied to the Kudankulam Nuclear Power Plant, surfaced on the dark web. The breach, linked to Reliance Group, revives concerns over cyber‑security and transparency in India's critical energy infrastructure.

मुख्य बिंदु (Key Takeaways)

  • Dark‑web cache reveals 14.3 GB, 18,997 files related to Kudankulam Nuclear Power Plant.
  • Documents pertain to the non‑nuclear Balance‑of‑Plant (BoP) EPC contract awarded to Reliance Infrastructure, not to nuclear safety systems.
  • Previous 2019 North‑Korea‑linked malware incident resurfaces, heightening security concerns.

New Delhi (July 17 2026) – A ransomware gang calling itself World Leaks has put a sizeable data set on the dark web that sheds fresh light on India’s flagship nuclear project, the Kudankulam Nuclear Power Plant (KKNPP). The leak consists of a 14.3 GB collection of 18,997 files, primarily covering the plant’s non‑nuclear “Balance of Plant” (BoP) facilities.

Origin of the Leak and Ongoing Dispute

The files are claimed to be part of a larger 1.2 TB cache containing over 858,000 documents allegedly tied to the Anil Ambani‑led Reliance Group. In 2018, Reliance Infrastructure Ltd secured the Engineering, Procurement and Construction (EPC) contract for KKNPP’s BoP services. The exposed material includes tender documents, financial invoices, engineering drawings, minutes of meetings, and email exchanges between Reliance Infrastructure and the Nuclear Power Corporation of India Ltd (NPCIL).

Reliance Group and Yotta’s Response

Reliance officials acknowledged a “partial breach” of data hosted on a server operated by third‑party data‑centre provider Yotta. Yotta reported detecting suspicious activity on May 29, immediately terminating the session and averting a ransomware execution. Government agencies have been notified of the incident.

Historical Cyber Attacks and Security Implications

This is not the first cyber‑related episode at Kudankulam. In 2019, a malware strain known as “DTrack,” linked to a North‑Korean hacker group, infiltrated the plant’s administrative network. The National Cyber Coordination Centre (NCCC) received intelligence from a U.S. cybersecurity firm, prompting CERT‑In to isolate the compromised system while keeping the critical control network intact. Analysts concluded the attack aimed at data theft, technology espionage, and reconnaissance.

Looking Ahead: Risks and Recommendations

Located in Tamil Nadu’s Tirunelveli district, KKNPP hosts six VVER‑type pressurised water reactors built in technical collaboration with Russia. Units 1 and 2 are operational, Units 3 and 4 are slated for commissioning by 2027, while the remaining units are at various stages of construction. The current leak, focused on Units 3 and 4, underscores that even non‑nuclear documentation can become a strategic vulnerability when linked to large contractors. It calls for stricter data‑security protocols, greater transparency, and coordinated monitoring across public‑private partnerships to safeguard India’s critical energy infrastructure.