Skip to content
NPCIL Denies Sensitive Data Breach at Kudankulam Nuclear Power Plant

NPCIL Denies Sensitive Data Breach at Kudankulam Nuclear Power Plant

Sanskritiias July 16, 2026

Kudankulam Nuclear Power Plant data breach, NPCIL cyber attack, Kudankulam nuclear leak, World Leaks ransomware, NPCIL statement, Reliance Infrastructure Kudankulam, Yotta server breach, India's nuclear security, CERT-In, Kudankulam Nuclear Power Plant, UPSC 2026

Mains (GS-III) : Critical Infrastructure Security, Cyber Security, Internal Security, Energy Security, and Nuclear Energy in India

The Nuclear Power Corporation of India Limited (NPCIL) has denied reports of a "sensitive data breach" at the Kudankulam Nuclear Power Plant (KKNPP) after media reports claimed that over 19,000 engineering and project-related files had been accessed by the ransomware group World Leaks .

NPCIL has categorically stated that :

NPCIL further clarified that the contractor had prepared detailed engineering drawings based on publicly shared tender specifications, which are unrelated to reactor control or nuclear security.

Balance of Plant refers to all supporting systems required to operate a power plant apart from the reactor itself.

These systems support plant operations but do not control nuclear reactions.

Even if reactor systems remain secure, leaked engineering documents can provide valuable intelligence.

Potential concerns include :

Such information could assist hostile actors in planning cyber or physical attacks against critical infrastructure.

One of the major lessons from this incident is the cyber security risk arising from vendors and contractors.

Modern infrastructure depends heavily on :

A weak contractor network can become an entry point for attackers even when the core operational network remains secure.

The Indian Computer Emergency Response Team (CERT-In) is India's national cyber incident response agency.

Its responsibilities include :

CERT-In is currently investigating the reported breach.

This is not the first cyber security controversy involving Kudankulam.

In 2019 , malware linked to a North Korean hacking group reportedly infected an administrative network.

NPCIL had clarified that :

The present incident has revived concerns regarding vendor cybersecurity and supply-chain risks.

Nuclear facilities are among the most sensitive components of a country's Critical Information Infrastructure (CII) . A successful cyber-attack on a nuclear installation can have far-reaching consequences for national security, public safety, and economic stability. Even if reactor systems remain physically protected, cyber threats targeting supporting networks, vendors, or administrative systems can expose vulnerabilities and disrupt operations.

Q. With reference to the Kudankulam Nuclear Power Plant (KKNPP), consider the following statements:

Which of the statements given above is/are correct?

A. 1 and 2 only B. 2 and 3 only C. 1 and 3 only D. 1, 2 and 3

"Cybersecurity of critical infrastructure has become as important as physical security." this statement in the context of the reported cyber incident involving the Kudankulam Nuclear Power Plant. Suggest measures to strengthen India's cyber resilience in strategic sectors.

It is India's largest nuclear power project located in Tamil Nadu and operated by NPCIL using Russian VVER reactor technology.

Media reports claimed that engineering drawings, Balance of Plant documents, vendor information, meeting records, inspection reports and related project files were accessed from a contractor's server. NPCIL states these are not related to nuclear safety systems.

No. NPCIL denied any breach of sensitive nuclear or reactor control systems and stated that only conventional Balance of Plant documentation was involved.

BoP refers to supporting infrastructure—such as cooling, ventilation, electrical distribution and water treatment systems—required to operate a power plant, excluding the reactor and its core nuclear safety systems.

The incident highlights the cybersecurity risks posed by third-party vendors and supply chains. Even if reactor systems remain secure, exposure of engineering and infrastructure data can have implications for national security and the protection of critical infrastructure.

Extracted Entities

Attack Types (1)

Countries (1)

Industries (1)

Ransomware Groups (1)