Control panel of nuclear power plant showing data breach

Data Breach at Largest Indian Nuclear Power Plant Leaks Sensitive Files

A data breach at an Indian nuclear power plant has exposed sensitive details after hackers breached a contractor via a third-party server infrastructure provider.

Tamil Nadu-based Kudankulam Nuclear Power Plant (KKNPP) is the largest of India’s seven nuclear power generators.

The nuclear power plant came under attack after hackers breached its contractor, Reliance Group, via a third-party cloud data center provider, Yotta.

Hackers publish sensitive files stolen from an Indian nuclear power plant

The World Leaks ransomware gang has published 858,000 files stolen from Reliance on their dark web leak site, totaling 14.3 GB, including 19,000 sensitive files, after unsuccessful extortion attempts.

The data breach exposed cooling and ventilation blueprints, a complete floor plan of the common control room, supplier lists, inspection records, meeting notes, insurance policies, and equipment reviews, including photos.

News outlet Reuters, which reviewed the files, says they date back to 2016 and 2025. The Nuclear Power Corporation of India Limited (NPCIL) says they primarily relate to the nuclear power plant’s Units 3 and 4, currently under construction and expected to become operational by 2027. Consequently, the data breach did not affect the core facility maintained by Russia’s Rosatom. Once completed, the additional units will provide 2,000 Megawatts of power, as part of the country’s nuclear expansion plans.

Nevertheless, the data breach leaked information that could enable attackers to study the nuclear power plant’s blueprints and identify security vulnerabilities that could be exploited during terrorist attacks. However, the nuclear power plant had reportedly taken an insurance policy worth about $112 million for terrorism-related damage.

The data breach could also enable attackers to identify and target suppliers to disrupt supply chains, or to launch cyber attacks to gain initial access to the nuclear power plant’s IT infrastructure.

“The real story here isn’t that the reactor was breached, because it wasn’t,” said Brian Proctor, Founder and CEO of Frenos. “It’s that attackers didn’t need to touch the reactor at all to get something just as useful: a map. Ventilation and cooling blueprints, the control room floor layout, and a full list of approved vendors are exactly the reconnaissance package you’d want if your plan is to compromise a facility’s support systems rather than attack it head-on.”

“And it reflects a shift we’re watching across OT: adversaries are spending less time hunting for vulnerabilities to exploit and more time studying the physical process itself, how the plant actually runs, what depends on what, and what happens downstream when a specific system fails,” added Proctor.

Indian nuclear data breach confirmed as authorities downplay the incident

Yotta has confirmed it detected suspicious activity at Reliance Infrastructure on May 29, 2026. The server infrastructure provider says it immediately responded and terminated the threat actor’s attempt to execute ransomware.

The server infrastructure provider also said it shared technical details regarding the data breach with Reliance, which has since confirmed “partial breach.” However, Yotta has not confirmed the identity of the threat actor or disclosed the nature of the leaked information.

Nevertheless, NPCIL says the data breach affected only Balance of Plant systems, not nuclear safety or security systems.

“NPCIL reiterates that the information claimed to be available in the public domain pertains only to conventional Balance of Plant (BoP) common service facilities and does not relate to any nuclear safety- or nuclear security-related systems or information,” the agency stated.

NPCIL also claims it had supplied drawings and detailed specifications to the bidders for the proposed facilities during the tendering process. It also claims the drawings are common in other industries, including thermal power plants.

“These facilities are of a conventional nature and are typically found in thermal power plants as well as other process industries. They are not related to nuclear safety or nuclear security systems,” the agency added.

Nevertheless, NPCIL and the Indian Computer Emergency Response Team (CERT-In) are assisting Reliance and Kudankulam Nuclear Power Plant in responding to the incident.

Meanwhile, this is hardly the first time cyber attacks have hit the nuclear power plant. In 2019, the Lazarus Group, a North Korean hacking group, deployed Dtrack malware on the nuclear power plant’s administrative network.

India is also among the top three most targeted countries, alongside the United States and France, with over 28.9 million accounts compromised.