
The Nuclear Power Corporation of India Limited (NPCIL) has categorically denied reports of a sensitive data breach at the Kudankulam Nuclear Power Project, following media reports that a ransomware group had accessed files related to the project through a contractor's server. In a statement issued on Wednesday, NPCIL said the information claimed to be available in the public domain pertains only to conventional Balance of Plant (BoP) common service facilities and does not relate to any nuclear safety or nuclear security-related systems or information. The corporation emphasized that the leaked files do not contain any information that could compromise nuclear operations or security systems.
According to NPCIL, the Engineering, Procurement and Construction (EPC) contract for the Common Services–Balance of Plant package was awarded to Reliance Infrastructure Ltd in 2018 through a public tender process. The contract covers the engineering, procurement/supply, construction and commissioning of common service facilities. As part of the public tendering process, NPCIL had provided indicative drawings and technical specifications to bidders. Based on these inputs and the project's requirements, Reliance Infrastructure prepared detailed engineering drawings in consultation with the respective Original Equipment Manufacturers (OEMs). The designs were reviewed and accepted by NPCIL after ensuring they met the required technical specifications. These facilities are conventional in nature and are typically found in thermal power plants and other process industries, not related to nuclear safety or nuclear security systems.
Indian businessman Anil Ambani's Reliance Group, one of the plant's contractors, confirmed that it had experienced a partial data breach involving a server hosted by third-party Indian data centre service provider Yotta. In a statement to Reuters, the company said the matter had been reported to the government and that appropriate authorities had been informed. However, Reliance Infrastructure did not disclose what specific information may have been compromised or whether any data related to the Kudankulam project had been exposed. Yotta detected suspicious activity on May 29 on a server it hosts for Reliance Infrastructure and immediately terminated the activity, preventing the suspected ransomware execution. However, Reliance Infrastructure informed Yotta at the end of June that 'external threat actors' had claimed there had been a data breach.
The Kudankulam Nuclear Power Plant, located in Tamil Nadu, is India's largest operational nuclear power station and plays a key role in the country's plans to significantly expand nuclear energy generation over the coming years. According to Reuters, one of Reliance Infrastructure's subsidiaries won a 2018 contract to design and build infrastructure for Unit 3 and Unit 4 of the plant, both still under construction and due to become operational by 2027 with a combined capacity of 2,000 megawatts. The files posted by World Leaks are claimed to include engineering blueprints of certain facilities, supplier and contractor details, meeting and inspection records, and other project records spanning nearly a decade. However, the documents primarily relate to Units 3 and 4 of the Kudankulam plant, which are currently under construction, and do not appear to include designs for the nuclear reactors' core systems, which are supplied by Russia's state-owned Rosatom.
As reported by Reuters, the leaked documents contained purported blueprints for ventilation and cooling systems used in Unit 3 and Unit 4, as well as what appeared to be the complete floor layout of a 'common control room'. The files included vendor proposals, a list of approved suppliers, and a record of a 2024 meeting on a joint inspection by the Nuclear Power Corporation and Reliance, with photographs of equipment. Another document purportedly showed that Reliance Infrastructure and the Nuclear Power Corporation had taken out an insurance policy that would entitle them to ₹9,100 crore if either Unit 3 or Unit 4 were to suffer an act of terrorism. Reuters reviewed a sample of the files but could not independently verify their authenticity. According to the latest reports, ransomware group World Leaks has uploaded nearly 19,000 files, allegedly related to Kudankulam Units 3 and 4, including the purported blueprints, supplier details, inspection records and insurance documents.
This marks the second time the Kudankulam plant has been linked to a cyber incident, following malware tied to a North Korean hacker group found on the plant's administrative network in 2019. According to Reuters, India ranked third among countries reporting the highest number of data breaches, with 28.9 million accounts compromised last year, behind only the United States and France. A report by the Data Security Council of India and cybersecurity firm Seqrite found that of 204 organisations surveyed across India, about 73% were 'unaware if they have ever been attacked', while 57% lacked cyber hygiene practices. World Leaks, a well-known ransomware group that has previously targeted Nike and India's Tata Group, typically posts stolen corporate data after companies decline to pay ransom demands. Neither the Department of Atomic Energy nor the Prime Minister's Office publicly commented on the investigation conducted by Reuters.