INDIA: Hackers Claim Leak of Sensitive Documents From Kudankulam Nuclear Power Plant
· 101 views
NEW DELHI (Terror Monitor) — The ransomware group World Leaks has allegedly published sensitive documents linked to India’s Kudankulam Nuclear Power Plant (KKNPP) on the dark web following a reported data breach, raising fresh concerns over the cybersecurity of critical infrastructure.
According to Reuters, the Kudankulam Nuclear Power Plant, located in the southern state of Tamil Nadu, is India’s largest nuclear power facility and plays a central role in Prime Minister Narendra Modi’s nuclear energy expansion program.
Reliance Group, a contractor involved with the project, confirmed that one of its servers suffered a “partial data breach.” The company said the affected server was hosted by Indian data center provider Yotta and that the incident had been reported to the government, but it did not disclose what information may have been compromised.
Independent cybersecurity researcher Rakesh Krishnan said approximately 19,000 files, totaling 14.3 gigabytes, have been available on the dark web under the label “KKNPP” since June 11. The files allegedly contain documents dating from 2016 to mid-2025.
Reuters reviewed portions of the leaked material but said it could not independently verify its authenticity. The documents reportedly include ventilation and cooling system diagrams, supplier information, inspection reports, meeting records, and insurance documents.
Cybersecurity experts warned that if authentic, the leaked information could expose details about the plant’s support systems, supply chain, and potential security vulnerabilities, increasing the risk to the facility.
Nicholas Roth, Senior Director at the Nuclear Threat Initiative, said such information in the wrong hands could pose a serious security threat to the nuclear plant.
India’s Nuclear Power Corporation and the national cybersecurity agency CERT-In are investigating the incident. However, authorities have not yet confirmed the authenticity or scope of the alleged leaked data.
Yotta said it detected suspicious activity on Reliance Infrastructure’s server on May 29 and took immediate action to stop what appeared to be a ransomware attack. The company later became aware of claims by external actors that data from the server had been leaked.
World Leaks has previously targeted major organizations in cyberattacks and is known for allegedly publishing stolen data on the dark web when ransom demands are not met.
Related Articles
Israel and Greece Sign $3.5 Billion Defense Deal for Multilayered Air Defense System
Israel and Greece have signed a $3.5 billion defense agreement, their largest arms deal to date, under which Athens will acquire a multilayered Israeli air defense system designed to counter ballistic missiles, drones and other aerial threats.
Turkey, Saudi Arabia and Pakistan to Hold First Meeting Under New Joint Defense Pact
Turkey, Saudi Arabia and Pakistan are set to hold their first committee meeting in Istanbul under the Makkah Joint Defense Agreement, which treats an armed attack on any one of the three countries as an attack on all. The pact aims to strengthen collective defense, military coordination and cooperation in the defense industry amid rising tensions across the Middle East.
India Signs Deal With US to Acquire Javelin Anti-Tank Missile Systems
India has signed a deal with the United States to acquire Javelin anti-tank missile systems, strengthening defense cooperation between the two countries amid recent diplomatic and trade tensions.
CIA Chief John Ratcliffe Makes Unannounced Moscow Visit as Trump Says Talks Could Produce Results
CIA Director John Ratcliffe made an unannounced visit to Moscow for talks with Russian intelligence officials, in a rare high-level U.S.-Russia contact. President Donald Trump said the discussions could produce results and reiterated Washington’s desire to end the war in Ukraine, while the Kremlin confirmed the intelligence contacts but said Ratcliffe did not meet President Vladimir Putin.