A ransomware group has dumped nearly 19,000 files tied to India’s largest nuclear power plant onto the dark web, and the fallout is raising urgent questions about how secure the country’s most sensitive infrastructure really is. Here is the full breakdown of what happened, what was exposed, and why it matters.
Kudankulam Data Leak Explained: What Actually Happened?
This Kudankulam data leak explained in simple terms comes down to one core fact: a cybercriminal group called World Leaks published roughly 14.3 GB of data, spread across about 18,997 files, on its dark web leak site starting June 11. The files are tagged “KKNP,” a clear reference to the Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu, India’s largest nuclear facility.
The leaked cache is part of a far larger 1.2 terabyte trove containing more than 858,000 files, all linked to the broader Reliance Group. The nuclear-plant-related portion is just one slice of that massive breach, but it is the slice drawing the most attention given the strategic sensitivity of the facility involved.
Where the Breach Actually Originated?
Contrary to early fears, investigators say the plant’s core reactor systems were never touched. Instead, the breach traces back to Reliance Infrastructure Ltd, a subsidiary of the Anil Ambani-led Reliance Group. The company was awarded the Engineering, Procurement, and Construction (EPC) contract back in 2018 for the plant’s non-nuclear common service facilities, technically known as the Balance of Plant (BoP).
These systems cover essential but non-reactor infrastructure such as:
- Ventilation and cooling system blueprints
- Common control room layouts
- Vendor proposals and approved supplier lists
- Equipment inspection and quality review reports
- Internal meeting records and correspondence with the Nuclear Power Corporation of India Ltd (NPCIL)
- Insurance documentation covering Units 3 and 4
The compromised data was reportedly hosted on a server managed by Yotta, a third-party Indian data center provider. Yotta has said it detected suspicious activity and claimed to have blocked the ransomware execution, yet the subsequent publication of the files on June 11 proved that data exfiltration had already occurred before containment.
The Numbers Behind the Breach
Understanding the scale of the incident is central to any Kudankulam data leak explained accurately, since the size and age range of the files show just how deep the exposure runs.
| Detail | Information |
| Files leaked | Approximately 18,997 |
| Data volume | Around 14.3 GB |
| Date range of documents | 2016 to mid-2025 |
| Units affected | Units 3 and 4 (under construction) |
| Plant capacity involved | 2,400 MW combined |
| Expected completion | 2027 |
| Hosting provider breached | Yotta (third-party data center) |
| Contractor involved | Reliance Infrastructure Ltd |
| Ransomware group | World Leaks (formerly Hunters International) |
| Wider Reliance Group leak | 1.2 TB, over 858,000 files |
Who Is Behind the Attack?
World Leaks is not a new name in the ransomware world. The group has a track record of targeting large corporations and has previously been linked to breaches involving Nike and India’s Tata Group. In a prior incident, the group reportedly demanded a ransom of roughly 1.5 million dollars for stolen Tata Group files before publishing the data after the demand was allegedly ignored.
The group’s typical playbook involves stealing corporate data, demanding payment to prevent publication, and releasing the files on dark web leak sites when companies decline to pay. This pattern appears to have repeated itself with the Reliance Infrastructure data connected to Kudankulam.
What the Government and NPCIL Are Saying?
Officials have been quick to stress that the plant’s operational and reactor-critical systems remain untouched. NPCIL has maintained that none of the leaked material relates to nuclear safety systems or reactor operations, noting that the reactor technology itself is supplied separately by Russia’s state-owned Rosatom. Authorities continue to describe the plant’s most sensitive systems as “air-gapped,” meaning physically isolated from external networks.
However, cybersecurity researchers caution that this framing may understate the real risk. Even non-classified infrastructure documents, including cooling system schematics and supplier lists, can reveal exploitable details about a strategic facility’s support systems and its wider supply chain.
Why This Kudankulam Data Leak Matters Beyond One Plant?
This is not the first cybersecurity scare at Kudankulam. Back in 2019, the plant faced an intrusion linked to North Korean hackers using malware known as DTrack, though that attack only reached the administrative network and did not affect critical internal systems.
What makes this Kudankulam data leak explained differently from that 2019 episode is the entry point. This time, attackers did not need to breach NPCIL directly at all. They simply needed to compromise a third-party contractor’s data center, exposing a much broader truth: the security of India’s nuclear ecosystem is only as strong as its weakest external vendor.
Key takeaways from the incident include:
- Supply-chain and third-party vendor security is now a frontline risk for critical infrastructure, not a secondary concern.
- Ransomware groups are increasingly targeting contractors rather than attacking hardened primary targets directly.
- “Air-gapped” reassurances apply narrowly to reactor control systems, not to the wider digital ecosystem surrounding a plant.
- Authenticity of leaked files remains unverified by independent reviewers, even though the volume and detail suggest a genuine breach.
The Road Ahead for Critical Infrastructure Security
The broader Kudankulam data leak explained through this lens becomes less about one contractor’s failure and more about a systemic vulnerability facing every sensitive industrial installation that relies on outsourced digital infrastructure. As India expands its nuclear energy ambitions, with Kudankulam’s additional units expected to become operational by 2027, the incident is likely to accelerate calls for stricter cybersecurity audits of third-party vendors handling even “non-critical” infrastructure data.
For now, officials insist the reactor core remains secure, but the exposure of nearly a decade’s worth of engineering and supplier documentation is a clear signal that digital perimeter security around India’s most strategic assets needs urgent reinforcement.