The ransomware group World Leaks posted documents it claimed were linked to the Kudankulam nuclear plant, but NPCIL clarified that the files contain no safety‑related information. The statement aims to reassure the public that the breach does not affect nuclear security.
Key Takeaways
- The leaked files contain only conventional Balance‑of‑Plant engineering drawings.
- None of the documents relate to the reactor core or nuclear safety systems.
- The incident appears to be a data‑theft breach, not a ransomware‑driven sabotage.
The ransomware collective known as World Leaks recently uploaded a set of files to the dark web, claiming they were tied to India’s largest nuclear installation – the Kudankulam Nuclear Power Plant in Tamil Nadu, slated for a total capacity of 6,000 MW. While the leak sparked alarm, the Nuclear Power Corporation of India Limited (NPCIL) has stressed that none of the disclosed material compromises nuclear safety or security.
Background and Initial Reports
Reuters first reported that the group released blueprints of certain plant components, along with supplier details, inspection records and equipment reviews. However, the authenticity of the documents could not be independently verified, and they showed no connection to the reactor core or to the Russian‑supplied Rosatom systems.
NPCIL’s Official Statement
In a statement dated 15 July 2026, NPCIL explained that the material pertains solely to engineering drawings for the Common Services, Balance of Plant (BoP) package of Units 3 and 4. This contract was awarded to Reliance Infrastructure Ltd in 2018 after a public tender and covers conventional plant infrastructure – the type found in ordinary thermal power stations – rather than any specialized nuclear‑operational equipment. “They are not related to nuclear safety or nuclear security systems,” the corporation emphasized.
Technical Explanation of the Breach
Reliance Group acknowledged that some of its data was compromised on a server managed by Yotta, a third‑party data‑centre provider. India’s Computer Emergency Response Team (CERT‑In) detected the leak, contacted Reliance Infrastructure, and confirmed the ransomware incident. The exposed information primarily concerns the company’s Engineering, Procurement and Construction (EPC) business, and there is no evidence of file encryption, indicating a data‑theft event rather than a disruptive ransomware attack.
Previous Cyber‑Security Concerns
This is not the first cyber incident at Kudankulam. In 2019, NPCIL reported malware on one of its computers, but assured that the plant’s operational systems remained untouched. Units 3 and 4 are still under construction, forming part of India’s broader nuclear power expansion.
Overall, NPCIL reassures that India’s nuclear safety standards remain robust and that the leaked documents do not endanger the nation’s nuclear infrastructure.