The ransomware group World Leaks has published a cache of approximately 19,000 files allegedly related to the Kudankulam Nuclear Power Plant (KKNPP) on the dark web. The leak includes purported blueprints of facility components, supplier lists, and inspection records. The data is linked to Reliance Group, a contractor for the plant, which confirmed a "partial breach" occurred on a server managed by third-party provider Yotta. Reliance stated it has informed the Indian government of the incident.
Researcher Rakesh Krishnan identified 14.3 gigabytes of data specifically related to the plant, with documents dated between 2016 and mid-2025. While the documents do not appear to involve the plant's core reactor systems, they reportedly contain layouts for ventilation and cooling systems for Units 3 and 4, which are currently under construction. World Leaks typically publishes such data after companies refuse ransom demands; the group previously targeted other major corporations including Nike and Tata Group.
The Nuclear Power Corporation of India (NPCIL) stated that the exposed information pertains only to common service facilities and does not involve nuclear safety or security-related systems. However, security experts from the Nuclear Threat Initiative noted that such data could potentially be used to identify vulnerabilities in the facility's support systems. The Indian Computer Emergency Response Team (CERT-In) is reportedly investigating the breach. Yotta reported detecting suspicious activity on the Reliance server in late May and has shared its technical findings with investigators.
