India’s Largest Nuclear Plant Hit by Major Data Breach as Ransomware Group Exposes 19,000 Files — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


India’s largest nuclear power plant has been embroiled in a massive data breach, sparking widespread concern over the cybersecurity of nuclear facilities. The notorious ransomware group “World Leaks” has published nearly 19,000 internal files allegedly linked to the Kudankulam Nuclear Power Plant (KKNP), containing highly sensitive content including engineering blueprints, supplier information, and employee records.

According to The Indian Express, the data trove totals 14.3 gigabytes and has been circulating on the dark web since June 11. Independent cybersecurity researcher Rakesh Krishnan confirmed that the data can be found on the dark web by searching for the plant’s abbreviation, “KKNP.” After reviewing the files, Reuters noted that the documents span from 2016 to mid-2025. While their authenticity cannot be fully verified at this time, the level of detail—including meeting and inspection records, equipment review documents, and insurance policies—is sufficient to cause unease within the industry.

The focus of the incident points to Reliance Infrastructure Limited, a subsidiary of India’s Reliance Group. The company won a contract in 2018 to design and build supporting infrastructure for Units 3 and 4 of the Kudankulam plant. These two units, with a combined capacity of 2,000 megawatts, are still under construction and expected to be operational by 2027.

In a statement sent to Reuters, Reliance Group confirmed the data breach. The statement indicated that data hosted with a third-party Indian data center service provider had been “partially compromised,” and that the group had informed the Indian government of the situation. Sources further revealed that the Indian Computer Emergency Response Team (CERT-In), under the Ministry of Electronics and Information Technology, has launched an investigation into the matter.

It is worth noting that this is not a simple internal management mishap, but rather the aftermath of a typical ransomware attack. “World Leaks” is an internationally notorious ransomware group that has previously targeted sportswear giant Nike and India’s largest multinational conglomerate, the Tata Group. The group’s standard modus operandi is to first steal a target’s core data and encrypt its systems. If the company refuses to pay the ransom, they publish the stolen data on a dedicated dark web site accessible only through specialized anonymous browsers.

The 19,000 leaked files represent just a portion of the data exfiltrated from Reliance Infrastructure Limited. Indian sources indicate that the ransomware attack resulted in the theft of over 850,000 files from the company, with the 19,000 files related to the Kudankulam plant widely considered the most sensitive core content among them.

The severity of the data breach quickly drew alarm from international security experts. The U.S.-based non-governmental organization Nuclear Threat Initiative issued a stern warning, stating that the data leak could pose a “serious” risk to the physical security of the Kudankulam plant.

Security experts analyzing the situation note that, theoretically, attackers could use the leaked engineering drawings to precisely map out the plant’s related support systems, identify specific suppliers, and use that as a starting point to find weak links in the supply chain. Once the protective vulnerabilities of such critical infrastructure are exposed to malicious actors, the plant could face unpredictable security threats.

Facing a torrent of external questioning, the plant’s operator, the Nuclear Power Corporation of India Limited (NPCIL), quickly issued a statement attempting to quell panic. The company insisted that the information currently available in the public domain only pertains to general service facilities built by the contractor and is unrelated to any core nuclear safety or security systems, and therefore there is no need to worry about risks to the plant.

Despite the operator’s efforts to clarify, the incident has once again ripped open deep wounds in India’s cybersecurity landscape. According to statistics from cybersecurity firm Surfshark, India ranks third globally on the list of countries worst affected by data breaches. Last year alone, as many as 28.9 million accounts in the country were compromised, trailing only the United States and France.

More critically, a joint survey report released by the Data Security Council of India and cybersecurity firm Seqrite reveals that cybersecurity defense awareness among Indian enterprises is extremely weak. Among the 204 Indian organizations surveyed, approximately 73% admitted they “do not know if they have ever suffered a cyberattack,” while a staggering 57% of surveyed companies acknowledged a lack of basic cybersecurity operational norms and practices internally. This widespread security blind spot makes companies like Reliance Infrastructure, which hold the lifelines of national critical infrastructure, particularly vulnerable in the face of increasingly rampant hacker attacks.

The Kudankulam Nuclear Power Plant, located in the southern Indian state of Tamil Nadu, has been operational since 2013 and is a crucial strategic asset for India’s energy self-sufficiency. This massive data breach not only tests the Indian government’s ability to handle critical infrastructure security crises but also serves as a wake-up call for all traditional industrial enterprises accelerating their digital transformation: when ransomware targets major national projects, what is at stake may be far more than just commercial secrets.

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW