Indian Nuclear Security Breach Can Lead to Regional Instability: Nuclear Experts Warn

The leak of thousands of files linked to India's largest nuclear power plant has renewed concerns over cybersecurity, oversight and the protection of critical infrastructure.

July 16, 2026 at 2:06 PM
icon-facebook icon-twitter icon-whatsapp

ISLAMABAD: The reported leak of thousands of sensitive documents linked to India’s Kudankulam Nuclear Power Plant has raised fresh concerns over the cybersecurity of the country’s critical nuclear infrastructure, with experts warning that the exposure of facility layouts, supplier networks and support systems could create new security risks even if reactor core designs remain uncompromised.

According to Reuters, World Leaks published nearly 19,000 files, amounting to about 14.3 GB of data, allegedly obtained through Reliance Infrastructure, a contractor involved in constructing Units 3 and 4 of the Kudankulam Nuclear Power Plant.

The files reportedly include facility layouts, ventilation and cooling system drawings, supplier information, inspection records and floor plans of a common control room. Reuters reviewed portions of the leaked material but said it could not independently verify the authenticity of every document.

Reliance Infrastructure acknowledged what it described as a “partial breach” involving data stored on a server hosted by Indian data centre provider Yotta. According to Reuters, suspicious activity was detected on 29 May, while the leaked files had reportedly been accessible online since 11 June, raising questions over the speed of detection, information sharing and public disclosure.

Sensitive Infrastructure Information

Security experts told Reuters the leaked cache does not appear to include reactor core designs supplied by Russia’s state-owned Rosatom, but they warned that documents relating to support infrastructure, contractor networks, equipment suppliers and facility layouts could still provide valuable intelligence for hostile actors.

INDIA PLANT, Sensitive Files From India's Largest Nuclear Power Plant Published on Dark Web

Nickolas Roth, Senior Director at the Nuclear Threat Initiative, said such information could help adversaries identify supply chains, map support systems and better understand potential security vulnerabilities associated with the facility.

The Nuclear Power Corporation of India (NPCIL) is coordinating with Reliance Infrastructure, while India’s Computer Emergency Response Team (CERT-In) is investigating the reported breach.

A Repeat of Earlier Cybersecurity Concerns

The latest incident is not the first time Kudankulam has faced cybersecurity concerns.

In 2019, malware linked to a North Korean hacking group was detected on the plant’s administrative network. At the time, Indian authorities said the operational systems of the nuclear facility had not been affected.

The recurrence of cyber-related incidents involving one of India’s most strategically important nuclear facilities is likely to intensify scrutiny of cybersecurity measures protecting critical infrastructure.

Growing Questions Over Nuclear Security

The incident indicates serious vulnerabilities in India’s critical nuclear infrastructure and program.
Critical information regarding reactor system details, compromised layouts, contractor networks, suppliers and support-system information indicate poor security culture and systems deserve serious concern and timely action by the international nuclear watchdog International Atomic Energy Agency (IAEA).

This is not the first time that international media have reported poor Indian security. Earlier, another cyber incident was reported associated with Kudankulam after malware was detected in its administrative network in 2019.

The recurrence of such incidents raises questions regarding the absence of an independent nuclear regulator, weak oversight and poor security culture across India’s large and ambitious nuclear programme.

This incident has surfaced at a time when a leading European think tank stated that India has deployed a dozen nuclear warheads at sea on its ballistic missile nuclear submarines.

Any accident of such mated warheads due to poor safety and weak oversight can lead to a major catastrophe and inadvertent escalation with any of New Delhi’s two nuclear-armed neighbours, China and Pakistan.

Against that backdrop, the reported breach has prompted renewed discussion among security analysts over the importance of protecting not only reactor systems but also the wider ecosystem of contractors, suppliers and digital infrastructure supporting nuclear facilities.

Experts note that while reactor core systems are often heavily protected, contractor networks and third-party service providers can present attractive targets for cybercriminals seeking indirect access to sensitive information.

Oversight and International Attention

The reported leak has also revived debate over regulatory oversight and cybersecurity preparedness within India’s nuclear sector.

Some analysts argue that repeated cybersecurity incidents highlight the need for stronger protection of critical infrastructure, enhanced monitoring of contractor networks and greater transparency in responding to cyber incidents involving strategic facilities.

The incident comes at a time when India’s strategic nuclear capabilities continue to expand, increasing the importance of maintaining robust physical and cyber security standards across the country’s civilian and strategic nuclear infrastructure.

Cybersecurity specialists say the exposure of infrastructure-related information should serve as a reminder that critical facilities remain attractive targets for increasingly sophisticated cyber threats.

The investigation by Indian authorities remains ongoing, and the full scope of the reported breach has yet to be established.

icon-facebook icon-twitter icon-whatsapp