BENGALURU: Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear power plant, including purported blueprints of parts of its facilities and supplier details — information it labelled as coming from the Reliance Group, Reuters reported.
The Kudankulam Nuclear Power Plant, located in the southern state of Tamil Nadu, is the largest of India’s seven nuclear power plants and is central to Prime Minister Narendra Modi’s ambitious plans to expand the country’s atomic energy capacity.
The leaked documents, posted by ransomware group World Leaks, include blueprints of parts of the Kudankulam Nuclear Power Plant, supplier information, inspection records and insurance documents. Reuters reviewed the files but said it could not independently verify their authenticity.
The Kudankulam Nuclear Power Plant, located in the southern state of Tamil Nadu, is India’s largest nuclear facility and a key part of Prime Minister Narendra Modi’s plan to significantly expand the country’s nuclear power generation.
Reliance Group, one of the contractors involved in the project, acknowledged a “partial breach” of data stored on a server hosted by Indian data centre provider Yotta. The company said the Indian government had been informed, but did not disclose what information had been compromised.
Investigation Underway
According to a source familiar with the matter, the Nuclear Power Corporation of India (NPCIL) has been coordinating with Reliance over the incident, while the Indian Computer Emergency Response Team (CERT-In) is investigating the breach.
Yotta said it detected suspicious activity on a server belonging to Reliance Infrastructure on May 29 and immediately terminated the activity, preventing what it described as suspected ransomware execution.
The company said Reliance later informed it that external threat actors had claimed responsibility for a data breach. Yotta added it had been unable to independently verify those claims but had shared the findings of its technical investigation with Reliance and was assisting ongoing inquiries.
Indian authorities, including the Department of Atomic Energy and NPCIL, have not publicly commented on the reported breach.
Sensitive Infrastructure Documents
The leaked cache reportedly contains about 19,000 sensitive files selected from a total of more than 858,000 files allegedly stolen from Reliance.
Among the documents are purported blueprints of ventilation and cooling systems for Kudankulam’s Units 3 and 4, floor layouts of a common control room, supplier lists, equipment inspection records and insurance policies.
One document reportedly details a $112 million insurance policy covering terrorist attacks affecting the two reactor units, which remain under construction and are expected to become operational by 2027.
Security experts warned that while the leaked files do not appear to include information on the nuclear reactors’ core systems, which are supplied by Russia’s state-owned Rosatom, they could still expose critical support infrastructure and supply chains.
Nickolas Roth, Senior Director at the Nuclear Threat Initiative, said such information could allow hostile actors to identify suppliers, map facility support systems and assess potential security vulnerabilities.
Rising Cybersecurity Concerns
The incident highlights growing cybersecurity challenges in India, where data breaches have become increasingly common.
According to cybersecurity company Surfshark, India recorded nearly 28.9 million compromised accounts last year, ranking third globally behind the United States and France.
The Kudankulam plant was previously linked to a cybersecurity incident in 2019 when malware associated with a North Korean hacking group was detected on its administrative network. Indian authorities said at the time that the plant’s operational systems were not affected.



