3 min read

A breach at the edge, reassurance at the center: what actually leaked from India's largest nuclear plant- 289

A breach at the edge, reassurance at the center: what actually leaked from India's largest nuclear plant- 289

July 23, 2026

A cybercriminal extortion group has published nearly 19,000 files it claims relate to India's largest nuclear power plant, and while Indian officials insist nothing safety-critical was exposed, the incident is a clean illustration of how a nuclear facility's real vulnerability increasingly runs through its contractors and data-center providers, not its reactors.

The files, posted by a group called World Leaks, are labeled as originating from Reliance Infrastructure, a subsidiary of Reliance Group building non-nuclear support infrastructure for two new reactor units under construction at the Kudankulam Nuclear Power Plant in southern India. India's state nuclear operator, the Nuclear Power Corporation of India Limited, said the documents relate only to the plant's conventional Balance of Plant package — the support infrastructure that sits separate from the reactors and their safety systems — and do not touch any nuclear safety or security-related systems or information. The country's Science and Technology Minister publicly dismissed suggestions that sensitive nuclear information had been compromised and said no broader security review was needed.

The actual point of failure sits one step removed from Reliance itself: the company said it suffered a partial breach involving data stored on infrastructure hosted by Yotta, an Indian data-center provider. Yotta said it detected suspicious activity on the Reliance Infrastructure server it hosts in late May and cut it off immediately, preventing what it described as a suspected ransomware execution — though Reliance later told Yotta that outside attackers were separately claiming to already possess stolen data. Yotta says it hasn't independently verified those claims itself, but has shared its forensic findings with Reliance and continues supporting the investigation. Independent researcher Rakesh Krishnan, who first documented the leak, said the intrusion may have come through exposed remote desktop access, phishing, or a Fortinet vulnerability, though none of these has been publicly confirmed as the actual entry point.

Distance rings — showing the breach originated at the contractor/data-center layer, the leak pertains to the outer Balance of Plant systems, and the reactor safety/security systems at the core remain untouched

According to Krishnan's accounting, roughly 19,000 files totaling about 14.3 gigabytes were published, dated between 2016 and mid-2025, and covering engineering drawings, supplier information, meeting records, inspection reports, and insurance documents — published on June 11 once World Leaks' standard countdown timer for the victim to pay expired. Neither the authenticity of the documents nor the actual intrusion method has been independently confirmed by Reliance or Indian authorities.

Leak scale — file count, size, date range, and publication trigger

This isn't Kudankulam's first brush with a cyber incident. In 2019, malware later linked by researchers to North Korea's Lazarus Group was found on an internet-connected administrative network at the plant — a system NPCIL said was isolated from reactor control and operational networks, with India's national cyber-emergency response team concluding plant operations were unaffected. The pattern across both incidents is consistent: repeated attention paid to a strategically significant Indian nuclear site, consistently landing on administrative or contractor-side systems rather than anything touching reactor operations.

Kudankulam is also not World Leaks' only recent high-profile Indian target. Last month the group claimed responsibility for breaching Tata Electronics, an Indian manufacturer supplying Apple, Tesla, and Qualcomm, demanding $1.5 million and publishing what it said were confidential engineering documents after alleging the company refused to pay. World Leaks itself emerged in early 2025 as a rebrand of the Hunters International ransomware operation, shifting away from traditional file encryption toward stealing and publishing data specifically to pressure victims into paying.