The dark-web data dump has shaken up the critical infrastructure industry in India, revealing highly sensitive information about the country’s largest nuclear power plant, the Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu. Recently, the notorious ransomware syndicate, “World Leaks”, published more than 19,000 files that were directly tied to the construction of the facility and financial risk management. Qualysec Technology has confirmed the 14.3-gigabyte cache. The analysts have found that the incident is a major supply chain failure and an example of the critical shortcomings of third party security. The leaked files reveal secondary structural blueprints and a list of suppliers as well as a confidential $112 million terrorism insurance policy, all of which are separated from the primary reactor controls by physical barriers at the operators’ works.
The Attack Path: How the Breach Occurred
The breach did not originate from KKNPP’s internal networks. Instead, attackers compromised a third-party partner. Reliance Infrastructure Limited, a major contractor building Units 3 and 4 of the Kudankulam plant, stored project data on a server that third-party data center provider Yotta managed. Yotta initially spotted suspicious activity on the server May 29, 2026 and stopped the immediate ransomware threat.
However, the attackers had already stolen a huge collection of files. Reliance Group only found out by late June that external “threat actors” had gained access to their systems. World Leaks then leaked the gigantic collection of 858,000 corporate stolen documents on their dark-web site. From this huge dump, almost 19 thousands of highly sensitive files are directly linked to Kudankulam nuclear.
What the Leaked Data Contains: A Technical Breakdown
The leaked Kudankulam files cover a period of 10 years from 2016 to mid-2025. The leak doesn’t risk the main reactor core systems that Russian state-owned company Rosatom provides, but it reveals the important support infrastructure. The files include:
- Secondary System Blueprints: Architectural Plan of the building of the ventilation system and cooling grids.
- Operational Documentation: Equipment evaluation documents, supplier lists, vendor proposals and inspection records.
- Control Room Layouts: Floor plans for common control rooms to be used by operators to operate Units 3 and 4.
- A $112 Million Terrorism Underwriting Policy: An extremely confidential insurance policy between Reliance Infrastructure and the Nuclear Power Corporation of India Limited (NPCIL).
This document provides for the recovery of financial loss and risk assessment. Nuclear operators need to buy highly specialised private policies; standard commercial property insurance policies exclude acts of terrorism and geopolitical warfare. These policies are based on physical security parameters, regional threat levels, and perimeter defense capabilities. This policy will effectively give an opponent a financial and physical risk profile of the facility.
Why This Matters: The Threat Landscape and Expert Analysis
While simple “air-gapping” remains a security barrier, Critical Infrastructure (CI) operators should not fall for the trap of thinking it is the only option, warn experts from Qualysec Technology. This air-gap is a physical separation of the primary control computers of the reactor from the public internet, but is not necessarily a completely safe separation.
The “Balance of Plant” (BOP) is a vital component of modern nuclear plants. The BOP includes the external cooling reservoirs, steam turbines and electrical transformers which serve the main reactor. In this instance, a cybercriminal or saboteur might be able to cut power to the secondary elements, resulting in a serious loss of off-site power. The main reactor core could overheat, and potentially trigger a nuclear disaster, if there is no electricity to operate the emergency cooling pumps.
Moreover, these blueprints offer a physical and digital blueprint for more advanced threat actors. Highly sophisticated attackers can review the ventilation diagrams, cooling system plans and layouts of the control room and strategically plan for further supply chain disruption or physical attack.
The Response and Historical Context
Currently, NPCIL is working with the Reliance Group to determine the extent of the leak. The formal investigation of Indian primary cyber security agency Indian Computer Emergency Response Team (CERT-In) is also underway. On the other hand, other senior government officials, such as NPCIL Chairman Rajesh Veeraraghavan and Atomic Energy Department officials have remained tight-lipped, refusing to comment on the public.
It was the second big security incident in Kudankulam. Security teams found “Dtrack” malware on the plant’s administrative network in 2019. That malware has been attributed to a North Korean state-sponsored threat group by investigators. That’s an administrative system breach, but this is the leakage of physical infrastructure diagrams, which is a much more serious threat.
Actionable Solutions: Qualysec Technology Recommendations
As an industry leader in cybersecurity, Qualysec Technology recommends that critical infrastructure companies adopt several immediate defense measures to secure their supply chains:
- Enforce Strict Third-Party Risk Management (TPRM): Companies need to assess the security of any vendor, contractor, and subcontractor. Contractors are required to adhere to the same cybersecurity requirements as the main operator.
- Implement Continuous Security Auditing: Don’t trust vendor audits that can only be performed once a year. They are required to perform continuous automated monitoring and vulnerability scanning on contractor environments which contain sensitive data.
- Mandate End-to-End Encryption: Contractors should ensure that sensitive engineering blueprints and operational files are encrypted at rest and in transit. This way, even if the attackers manage to exfiltrate the data, they won’t be able to read or exploit the files.
- Deploy Advanced Endpoint Detection and Response (EDR): Companies will need to implement modern EDR solutions across all admin and corporate servers. These tools can detect and block out-of-the-ordinary activity, like the unauthorized bulk export of files, that a hacker might use to mount a ransomware attack.
This breach proves that the hackers don’t have to attack the nuclear reactor directly. They are able to gain easy access to the ‘crown jewels of national defence’ by targeting weak third party contractors.
Protect Critical Infrastructure from Supply Chain Attacks. Get a Security Assessment






