
India’s state-owned nuclear operator said that documents recently posted online and purportedly linked to the country’s largest nuclear power plant contain no information affecting safety or security.
The statement came after the media reported last week that the cybercrime group World Leaks had published thousands of files apparently connected to the Kudankulam Nuclear Power Plant (KKNPP).
The files appeared to include engineering drawings, supplier information, inspection records and insurance documents related to Units 3 and 4, which are under construction near the southern tip of India.
However, the Nuclear Power Corporation of India Limited (NPCIL) said the documents appear to relate only to the engineering, procurement and construction contract for the plant’s conventional Balance of Plant (BoP) package, which covers support infrastructure separate from the reactors and their safety systems.
“NPCIL reiterates that the information claimed to be available in the public domain pertains only to conventional Balance of Plant (BoP) common service facilities and does not relate to any nuclear safety- or nuclear security-related systems or information,” the operator said.
Science and Technology Minister Jitendra Singh also dismissed reports suggesting sensitive nuclear information had been compromised, telling local media there was no immediate need for a broader security review.
Third-party contractor breach
The files posted by World Leaks were labeled as originating from Reliance Group, whose subsidiary Reliance Infrastructure is building non-nuclear infrastructure for the new Kudankulam reactors.
In a statement to Reuters, which first reported the incident, Reliance Group said it had suffered a “partial breach” involving data stored on infrastructure hosted by Indian data center provider Yotta. The company said the Indian government had been informed but did not specify what information had been accessed.
Yotta said it detected suspicious activity on a Reliance Infrastructure server it hosts in late May and immediately terminated the activity, preventing what it described as a suspected ransomware execution. Yotta said Reliance later informed it that external threat actors were claiming to possess stolen data.
Yotta said it has not independently verified those claims but has shared the results of its forensic investigation with Reliance Infrastructure and continues to support the investigation.
Independent cybersecurity researcher Rakesh Krishnan, who first documented the purported leak, said World Leaks published the data on June 11 after the expiration of the group’s typical countdown timer.Â
He said the attackers may have gained access through exposed remote desktop services, phishing or exploitation of a Fortinet vulnerability, although there is no public evidence confirming the intrusion vector.
According to Krishnan, nearly 19,000 files totaling about 14.3 GB related to Kudankulam were published by World Leaks. The documents, dated between 2016 and mid-2025, included what appeared to be engineering drawings, supplier information, meeting records, inspection reports and insurance documents.
The authenticity of the documents could not be independently verified. Neither Reliance nor Indian authorities have publicly attributed the intrusion or disclosed how the attackers gained access.
This is not the first cyber incident involving Kudankulam. In 2019, malware later linked by researchers to North Korea’s Lazarus Group was discovered on an internet-connected administrative network at the plant. NPCIL said the infected system was isolated from reactor control and operational networks, and India’s CERT-In concluded that plant operations were unaffected.
World Leaks’ targets
Kudankulam became the second high-profile Indian victim publicly claimed by World Leaks in recent weeks. Last month, the group claimed responsibility for breaching Tata Electronics, an Indian manufacturer that supplies Apple, Tesla and Qualcomm. It demanded $1.5 million and later published what it said were confidential engineering documents after alleging the company had refused to pay.
World Leaks emerged in early 2025 following the rebranding of the Hunters International ransomware operation. Unlike traditional ransomware groups that prioritize file encryption, it has increasingly focused on stealing and publishing data to pressure victims into paying extortion demands.
Recorded Future
Intelligence Cloud.