How were 19,000 Files Related to the Kudankulam Nuclear Power Plant Exposed?
One of the striking incidents illustrating the potential extent of supplier-related security risks occurred in July 2026 at the Kudankulam Nuclear Power Plant in India.
A ransomware group known as "World Leaks" published thousands of files online that it claimed were linked to the plant.
According to a Reuters report dated July 15, 2026, the archive comprising approximately 19,000 files totaled 14.3 GB in size. The files reportedly included facility blueprints, supplier information, records of meetings and inspections, equipment assessments, and insurance documents.
Reuters examined the documents but specifically noted that it could not independently verify their authenticity.
Source of the Attack
The attack did not originate directly from the plant's main system.
This is precisely the most significant aspect of the incident.
Reliance Group was one of the contractors carrying out infrastructure work on the plant's Units 3 and 4. The company acknowledged that some of its data had been compromised on a server hosted by Yotta, a third-party data center provider. In other words, the source of the attack was not the nuclear power plant's core operational systems, but rather an external system belonging to a contractor working on the project.
We can liken this to a large building. The building’s main entrance might be protected by robust doors, cameras, and security personnel.
However, if the key to a side office containing technical blueprints is held by an external contractor, an attacker does not need to force their way through the main entrance.
In the Kudankulam case, there was no need for the main system to be compromised. Merely gaining access to files linked to the project was enough to spark a serious controversy.
Were Nuclear Safety Systems Affected?
India’s Nuclear Power Corporation (NPCIL) stated that the documents reported to have been leaked were unrelated to nuclear safety or the reactor's critical systems. According to the corporation, the files pertained to the plant's conventional support facilities and shared service areas; the primary nuclear safety systems remained unaffected.
This statement is significant. However, the fact that "core systems were unaffected" does not mean the incident is trivial.
Technical drawings, supplier lists, and inspection records are not sufficient on their own to control a power plant. Nevertheless, such information can aid attackers seeking to understand how an organization operates, who it does business with, and who has access to which systems.
The real issue is not the number of files.
While the 19,000 files involved in this incident are notable, the primary question should be:
Why were these files on a third-party system, and who had access to them?
In critical infrastructure projects, it is not enough for the plant operator alone to be secure. Contractors, data center providers, engineering firms, and equipment suppliers are all links in the same security chain.
Therefore, it is essential to restrict third-party access, regularly review shared files, and remove sensitive documents from systems once they are no longer needed.
The Kudankulam incident demonstrates that serious data security breaches can occur even while core systems continue to operate.
Attackers do not always force the strongest door; finding a less protected side entrance is often enough.
Disclaimer
This article has been prepared solely for informational purposes based on publicly available news and statements. The assessments contained herein do not constitute legal, technical, commercial, or security advice. Details regarding the incident are subject to change in light of the investigation process and new statements. This content does not imply any official relationship with, or endorsement by, the Kudankulam Nuclear Power Plant, NPCIL, Reliance Group, or any other mentioned entities.