Kudankulam Nuclear Plant Files Exposed in Data Breach: NPCIL Clarifies

Kudankulam Nuclear Plant Files Exposed in Data Breach, NPCIL Says Core Systems Unaffected

New Delhi, September 4, 2026 — A reported cybersecurity breach involving files linked to India’s Kudankulam Nuclear Power Plant has raised concerns about the protection of sensitive information connected to the country’s critical infrastructure.

The ransomware group World Leaks reportedly published a large collection of files on the dark web that it claimed were connected to the Kudankulam Nuclear Power Project in Tamil Nadu. Reuters reported that the material included purported engineering drawings, supplier information and other project-related documents. The authenticity of all the leaked material has not been independently verified.

Reliance Infrastructure Data Was Involved

The reported breach was linked to data belonging to Reliance Infrastructure, which was awarded a contract for infrastructure work associated with Units 3 and 4 of the Kudankulam project.

Reliance Group acknowledged that a partial breach had occurred involving data hosted on servers operated by third-party data-centre provider Yotta. The company said the incident had been reported to the relevant authorities.

Reports indicated that nearly 19,000 files, totalling around 14.3 GB, had appeared online. The reported documents included engineering drawings, inspection records, supplier information, meeting documents and insurance-related material.

NPCIL Says Nuclear Safety Systems Were Not Compromised

The Nuclear Power Corporation of India Limited (NPCIL) rejected suggestions that the incident had compromised the plant’s nuclear safety or security systems.

According to NPCIL, the information reportedly exposed online related to conventional “Balance of Plant” facilities and did not involve nuclear safety or nuclear security systems.

This distinction is important because Kudankulam’s core nuclear systems are separated from ordinary information and infrastructure networks. Therefore, the reported exposure of contractor documents does not by itself mean that the reactor control systems were hacked.

Why the Incident Is Still a Concern

Cybersecurity experts have warned that even when core reactor systems remain protected, the exposure of engineering information, equipment details and supplier data can create risks for critical infrastructure.

Such information could potentially help attackers understand parts of an industrial facility and identify weaknesses in its wider supply chain. This is why cybersecurity protection is increasingly important not only for government agencies but also for private contractors and third-party technology providers.

Kudankulam’s Importance to India

Kudankulam is India’s largest nuclear power plant and is a major part of the country’s long-term nuclear energy programme.

Units 1 and 2 are already operational, while additional units are under construction or development. Units 3 and 4 are being developed with Reliance Infrastructure involved in common infrastructure work.

The incident therefore highlights a broader cybersecurity challenge: protecting critical infrastructure requires security across the entire supply chain, including contractors, cloud platforms and data-centre providers.

Conclusion

The reported Kudankulam data breach has raised important questions about cybersecurity around India’s critical infrastructure. However, available official statements indicate that the leaked material did not involve the plant’s nuclear safety or security systems.

Authorities and companies involved will need to determine the authenticity and full scope of the exposed files and strengthen security measures to prevent similar incidents in the future.

Source: Reuters and official statements reported by Indian media.

Disclaimer: This article is based on publicly available reports. Claims concerning the leaked files have not all been independently verified.

Leave a Comment