Wednesday, July 29, 2026

The Plain Record

Neutral daily news — clear headlines, complete facts.

World

Data Breach Exposes Files Related to India's Kudankulam Nuclear Plant

Ransomware group World Leaks posted documents including facility blueprints and supplier details following a breach at contractor Reliance Group.

Sourced from Reuters
Published July 15, 2026 at 5:01 AM EDT
Data Breach Exposes Files Related to India's Kudankulam Nuclear Plant

The Facts

Who
World Leaks (ransomware group), Reliance Group (contractor), and Kudankulam Nuclear Power Plant.
What
A data breach involving 19,000 files related to a nuclear power plant.
When
July 15, 2026 (Reported); Breach detected in May.
Where
India (Tamil Nadu and Bengaluru).
Why
To demand a ransom or expose corporate data following a server breach at a third-party provider.

The ransomware group World Leaks has published a cache of approximately 19,000 files allegedly related to the Kudankulam Nuclear Power Plant (KKNPP) on the dark web. The leak includes purported blueprints of facility components, supplier lists, and inspection records. The data is linked to Reliance Group, a contractor for the plant, which confirmed a "partial breach" occurred on a server managed by third-party provider Yotta. Reliance stated it has informed the Indian government of the incident.

Researcher Rakesh Krishnan identified 14.3 gigabytes of data specifically related to the plant, with documents dated between 2016 and mid-2025. While the documents do not appear to involve the plant's core reactor systems, they reportedly contain layouts for ventilation and cooling systems for Units 3 and 4, which are currently under construction. World Leaks typically publishes such data after companies refuse ransom demands; the group previously targeted other major corporations including Nike and Tata Group.

The Nuclear Power Corporation of India (NPCIL) stated that the exposed information pertains only to common service facilities and does not involve nuclear safety or security-related systems. However, security experts from the Nuclear Threat Initiative noted that such data could potentially be used to identify vulnerabilities in the facility's support systems. The Indian Computer Emergency Response Team (CERT-In) is reportedly investigating the breach. Yotta reported detecting suspicious activity on the Reliance server in late May and has shared its technical findings with investigators.

This story was rewritten from reporting at Reuters. Read the original for full detail.

Summaries are written by The Plain Record to state the facts of a story plainly and without political slant. See our editorial standards, or report a correction.

← Back to the front page