Skip to content
Hackers publish Reliance linked Kudankulam files, India launches cyber probe

Hackers publish Reliance linked Kudankulam files, India launches cyber probe

Mezha July 15, 2026

A dark web dump alleges drawings and supplier records tied to India’s largest nuclear station. Officials are racing to determine the breach’s security implications.

As reported by Reuters

In Bengaluru, on July 15, the hacker group World Leaks published on the dark web a large archive of files related to the Kudankulam Nuclear Power PlantIndia’s largest nuclear facility and a key element of the government’s ambitions to increase nuclear capacity. The archive allegedly contains drawings of infrastructure components and supplier data, information that World Leaks labeled as Reliance Group data.

The Kudankulam Nuclear Power Plant, located in the southern state of Tamil Nadu, is the largest among India’s seven nuclear power plants and underpins the government’s plans under Narendra Modi to ramp up the country’s nuclear capacity.

One of the station’s contractors is the Reliance Group; the company said that there was a partial data breach on a server hosted by a third-party data center, Yotta, and that the government has been informed of the incident. The company did not disclose which data were breached.

According to group representatives, the breach has been confirmed, but specific details are not disclosed. Such data, according to experts, could pose a serious security risk to the plant.

World Leaks overall hosts more than 858,000 files, of which 19,000, according to analysis, are the most sensitive with regard to the Reliance Group.

One of the group’s divisions, Reliance Infrastructure (RLIN.NS), in 2018 secured a contract to design and construct infrastructure for the plant’s Blocks 3 and 4. Both blocks are still under construction and are expected to be commissioned by 2027 with a combined capacity of 2,000 MW.

World Leaks, previously known for its attacks on Nike and Tata Group data, has not yet responded to requests regarding the Reliance data breach. In light of such actions, hackers usually post stolen materials on their site after companies refuse to pay a ransom. Sources add that access to the site is possible only through a special browser.

In June, World Leaks said it had demanded $1.5 million for Tata Group files containing confidential design components for Apple and Tesla clients – the data were disclosed after Tata allegedly rejected their demands.

India’s youngest public-sector company, the Nuclear Power Corporation of India (NPCIL), which operates and maintains the country’s nuclear power plants, coordinates the liaison with Reliance regarding the incident and awaits responses from the relevant cyber-security regulatory authorities. CERT-In, the government’s central cyber incident response center, is also investigating, but no official have been issued by the Nuclear Power Corporation or the Prime Minister’s Office regarding this leak.

Yotta said that on May 29 it detected suspicious activity on a server belonging to Reliance Infrastructure. According to the service, the incident was immediately contained, but by the end of June Reliance Infrastructure reported statements from external threats that could constitute a data breach.

Regulatory and government officials continue to investigate, but there have been no official from the Nuclear Power Corporation or the Office of the Prime Minister regarding this leak.

The documents published by World Leaks are likely not related to the core of the reactors, which are supplied by the Russian manufacturer Rosatom. At the same time, they contain potential drawings for the ventilation and cooling systems of Units 3 and 4, as well as allegedly complete plans for the overall control hall.

The file set also included supplier proposals, a list of approved suppliers, and a record of a 2024 joint inspection between the Nuclear Power Corporation and Reliance; there are also photographs of equipment. Another document states that Reliance Infrastructure and the Nuclear Power Corporation arranged an insurance policy for approximately $112 million in case of a terrorist attack on Blocks 3 or 4.

Experts estimate that these materials could enable attackers not only to understand who has access to the project but also to determine which systems fall under that access, creating a security risk.

According to Surfshark, India ranks among the top three countries for data breaches – with over 28.9 million compromised accounts last year, behind only the United States and France. Last year’s studies by the DSCI and Seqrite showed that 73% of surveyed organizations did not know whether they had been attacked, and 57% lacked basic cyber hygiene practices.

For Kudankulam, this is not the first time cyber intrusions have drawn attention: in 2019, malware from supporters of North Korean hacker groups was found on the station’s administrative network; NPCIL said the matter was promptly investigated and the plant’s systems were not affected.

This incident underscores the importance of strengthening protection of critical infrastructure and the need for a coordinated response to cyber threats in the country’s energy sector. At the same time, the issue of data leaks remains in the focus of government and industrial bodies, which must ensure greater transparency and readiness to act swiftly in case of future incidents.

You may be interested in these materials: