
India’s nuclear energy sector has come under the spotlight after reports emerged that a ransomware group had published thousands of files allegedly linked to the Kudankulam Nuclear Power Project (KKNPP) in Tamil Nadu. While the incident sparked concerns over the cybersecurity of critical infrastructure, the Nuclear Power Corporation of India Limited (NPCIL) has firmly denied that any nuclear safety or security-related information was compromised.
According to NPCIL, the documents circulating online relate only to conventional project infrastructure and do not involve reactor operations, nuclear safety systems, or nuclear security systems. The clarification came after widespread reports claimed that sensitive engineering documents connected with the country’s largest nuclear power project had been leaked on the dark web.
What Happened?
The controversy began when the ransomware group World Leaks claimed to have uploaded a large cache of files allegedly connected to the Kudankulam Nuclear Power Project.
Cybersecurity researchers reported that nearly 19,000 files—part of a much larger dataset allegedly stolen from Reliance Infrastructure—were posted on the dark web. The documents reportedly included:
- Engineering drawings.
- Supplier information.
- Equipment inspection reports.
- Meeting records.
- Insurance documents.
- Blueprints of certain conventional facilities.
Reuters reviewed portions of the leaked material but noted that it could not independently verify the authenticity of all the files. (Reuters)
NPCIL’s Clarification
In an official statement, NPCIL rejected suggestions that India’s nuclear infrastructure had suffered a security breach.

The corporation explained that:
- The Engineering, Procurement and Construction (EPC) contract for the Common Services – Balance of Plant (BoP) package had been awarded to Reliance Infrastructure Ltd. in 2018 through a public tender.
- The leaked information, if genuine, relates only to conventional facilities, similar to those used in thermal power plants and other industrial projects.
- No drawings, data or information concerning nuclear safety or nuclear security systems have been compromised. (DT Next)
NPCIL emphasized that India’s nuclear reactor systems remain isolated from public networks and continue to operate under stringent security protocols.
Reliance Infrastructure Confirms Partial Breach
Reliance Infrastructure acknowledged a partial data breach involving a server hosted by the third-party data centre company Yotta.
The company stated that:
- Suspicious activity was detected.
- Government authorities were informed.
- Investigations are underway.
- The breach affected a third-party hosted server rather than operational nuclear systems.
However, Reliance did not disclose the precise nature or volume of the compromised files. (Reuters)
What Kind of Files Were Reportedly Leaked?
According to media reports and cybersecurity researchers, the leaked material allegedly includes:
- Layouts of ventilation systems.
- Cooling system drawings.
- Common control room floor plans.
- Vendor proposals.
- Lists of approved suppliers.
- Inspection reports.
- Equipment review documents.
- Insurance policy records.
Importantly, reports indicate that the leaked documents do not relate to the reactor core, nuclear fuel systems, reactor control mechanisms, or safety instrumentation, much of which is supplied separately by Russia’s Rosatom.
Why the Incident Still Matters
Although NPCIL maintains that nuclear safety systems remain unaffected, cybersecurity experts caution that even conventional engineering documents can have security implications.
According to experts, such information could potentially help malicious actors:
- Understand facility layouts.
- Identify contractors and suppliers.
- Map infrastructure dependencies.
- Study support systems.
- Target future cyber or physical attacks.
For this reason, cybersecurity specialists argue that protecting contractor networks is also an essential component of critical infrastructure security. (Reuters)
CERT-In Investigation
India’s national cyber emergency response agency, CERT-In, along with other government agencies, is examining the incident.
Investigators are expected to determine:
- Whether the leaked files are authentic.
- How the breach occurred.
- Whether additional systems were affected.
- If any further security measures are required.
NPCIL has stated that it is cooperating fully with the investigation. (Reuters)
Kudankulam’s Importance to India
The Kudankulam Nuclear Power Plant, located in Tamil Nadu’s Tirunelveli district, is India’s largest nuclear power station.

The facility plays a central role in India’s strategy to expand clean electricity generation and reduce dependence on fossil fuels.
Current and planned units are expected to contribute significantly to the country’s long-term energy security.
Because of its strategic importance, the project is protected through multiple layers of:
- Physical security.
- Digital security.
- Regulatory oversight.
- International nuclear safety standards.
Cybersecurity Challenges for Critical Infrastructure
The Kudankulam incident highlights the growing cyber risks faced by critical infrastructure worldwide.
Power plants, transportation systems, financial institutions, and government agencies increasingly rely on digital systems, making cybersecurity an essential national security concern.
Experts recommend:
- Stronger contractor cybersecurity requirements.
- Regular penetration testing.
- Zero-trust network architecture.
- Multi-factor authentication.
- Continuous monitoring.
- Employee cybersecurity training.
Not the First Cybersecurity Concern
This is not the first time Kudankulam has attracted cybersecurity attention.
In 2019, malware linked to a North Korean hacking group was detected on an administrative network associated with the plant.
NPCIL clarified at the time that:
- Operational systems were unaffected.
- Reactor control networks remained isolated.
- Nuclear safety was never compromised.
The current incident similarly appears to involve contractor-related systems rather than operational reactor infrastructure. (Reuters)
Public Confidence and Nuclear Safety
Nuclear facilities operate under some of the strictest safety regulations in the world.
Even when cybersecurity incidents involve contractors or administrative systems, public concern tends to be high because of the strategic importance of nuclear energy.
NPCIL’s clarification aims to reassure the public that:
- Reactor operations continue normally.
- Nuclear safety systems remain isolated.
- No radioactive material or reactor controls were affected.
- There is no impact on public safety.
Lessons for India’s Cybersecurity Landscape
The incident also reflects broader cybersecurity challenges across India.

Industry reports have shown that many organizations still face gaps in cyber hygiene, third-party risk management, and incident response capabilities.
As India rapidly digitizes its infrastructure, strengthening cybersecurity across both public and private sectors will remain a national priority.
Looking Ahead
Authorities are expected to continue investigating the reported breach while reviewing cybersecurity practices across contractors involved in strategic infrastructure projects.
Experts believe future improvements may include:
- Enhanced third-party security audits.
- Better supply-chain cybersecurity.
- Stronger encryption.
- More frequent vulnerability assessments.
- Improved coordination between government agencies and private contractors.
These measures could help reduce future cyber risks to critical national infrastructure.
Conclusion
The reports surrounding the alleged Kudankulam data breach have raised important questions about cybersecurity and the protection of critical infrastructure. However, according to NPCIL, no nuclear safety or nuclear security systems have been compromised, and the reported documents relate only to conventional project infrastructure.
While the investigation by CERT-In and other agencies continues, officials maintain that reactor operations remain secure and unaffected. At the same time, the incident serves as a reminder that cybersecurity must extend beyond core operational systems to include contractors, vendors, and third-party service providers involved in major national projects.