Skip to content
Anil Ambani's Reliance confirms data breach after files linked to Kudankulam nuclear plant ...

Anil Ambani's Reliance confirms data breach after files linked to Kudankulam nuclear plant ...

Cnbctv18 July 15, 2026

Reliance Group has confirmed a data breach after a ransomware group posted more than 19,000 files purportedly linked to the Kudankulam Nuclear Power Plant, India's largest nuclear power facility, on the dark web.

The files, reviewed by Reuters but not independently verified, include purported blueprints, supplier information, meeting records, inspection reports, equipment reviews and insurance documents dated between 2016 and mid-2025.

The Anil Ambani-led Reliance Group, one of the contractors for the Tamil Nadu-based nuclear plant, said there had been a "partial breach" of data on a server hosted by third-party data centre provider Yotta. The company said the Indian government had been informed but did not disclose what information had been compromised.

The Nuclear Power Corporation of India, which operates the country's nuclear power plants, has been in with Reliance over the incident, while the Indian Computer Emergency Response Team (CERT-In) is investigating, according to a source familiar with the matter.

Nuclear Power Corporation Chairman Rajesh Veeraraghavan, CERT-In and the government's Press Information Bureau did not respond to Reuters' requests for . The Department of Atomic Energy declined to , while the Prime Minister's Office did not respond.

Yotta said it detected suspicious activity on May 29 on a server belonging to Reliance Infrastructure and hosted at its facility. The company said it immediately terminated the activity and prevented suspected ransomware execution.

According to Yotta, Reliance Infrastructure informed it at the end of June that external threat actors had claimed responsibility for a data breach. Yotta said it had not been able to verify those claims but had shared its technical investigation with Reliance Infrastructure and is supporting the ongoing probe.

Reuters reported that the group typically publishes data after companies refuse to pay ransom demands. In June, it told Reuters it had sought $1.5 million from Tata Group before publishing files it claimed to have stolen.

The documents do not appear to relate to the nuclear reactors' core systems, which are supplied by Russia's state-owned Rosatom.

However, they include purported blueprints of ventilation and cooling systems for Units 3 and 4, what appeared to be the floor layout of a common control room, supplier lists, vendor proposals and records of joint inspections involving the Nuclear Power Corporation of India and Reliance.

One document also appeared to show that Reliance Infrastructure and the Nuclear Power Corporation had taken out an insurance policy worth $112 million covering acts of terrorism affecting Units 3 or 4.

Nickolas Roth, senior director at the Nuclear Threat Initiative, said the breach could pose a "serious" risk to the plant's safety.

The files could "show an adversary not just who has access to the project but which systems that access reaches," Roth said.

Reliance Infrastructure secured the contract in 2018 to design and build infrastructure for Units 3 and 4 at Kudankulam. The two units, expected to become operational by 2027, will add a combined 2,000 megawatts of generation capacity.

According to cybersecurity company Surfshark, India recorded 28.9 million compromised accounts last year, the third-highest total globally after the United States and France.