In July 2026, files describing parts of India’s largest nuclear power plant appeared on a dark web leak site. Nobody hacked a reactor. Nobody touched a control system. Attackers went after a construction contractor’s paperwork, and that was enough to make it national news.
What happened
The ransomware group World Leaks published roughly 19,000 files, about 14.3 gigabytes, tied to the Kudankulam Nuclear Power Plant in Tamil Nadu. Reuters reviewed the documents and reported they included purported blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies, dated between 2016 and mid-2025. The agency could not verify the files were authentic.
The data was attributed to Reliance Group. Its subsidiary Reliance Infrastructure won a 2018 contract to design and build infrastructure for Kudankulam’s Units 3 and 4, both still under construction and due to deliver a combined 2,000 MW. Reliance told Reuters there had been a partial breach of its data on a server hosted by the Indian data centre provider Yotta, and that the government had been informed.
The Kudankulam material was the sharp edge of a much larger dump. World Leaks had posted around 858,000 Reliance files in total, with the nuclear-related subset online since 11 June. The group follows the usual double-extortion routine: steal, demand, then publish when the victim refuses to pay.
The Nuclear Power Corporation of India said the exposed information relates only to common service facilities and has no bearing on nuclear safety or security systems. CERT-In opened an investigation.
Why this one lands differently than 2019
Kudankulam has been here before. In 2019, malware turned up on an administrative machine at the plant. NPCIL confirmed the infected computer sat on a network used for administrative purposes, isolated from the critical internal network.
The 2026 incident has a different shape. Nothing at the plant itself was compromised. The weak point was a vendor’s document store, hosted with a third party, two steps removed from the facility everyone actually worries about.
That distance is the whole story. Design documents describe layouts, access routes and where building services run. Nickolas Roth of the Nuclear Threat Initiative told Reuters the exposure could pose a serious risk to plant safety. Physical security at a nuclear site does not collapse because drawings leaked — fences, guards and vehicle barriers work regardless. But reconnaissance gets a lot cheaper when the drawings are free.
The pattern behind the headline
This is not an outlier. Check Point’s 2026 report put Indian organisations at an average of 3,195 attacks per week during 2025, a 2% rise on the year before. CERT-In’s own figures show a steeper climb: roughly 29.4 lakh incidents handled in 2025, up around 44% on 2024.
Extortion crews have also worked out that Indian conglomerates are worth their time. World Leaks had previously hit Tata Group, telling Reuters it demanded $1.5 million before publishing files that included confidential component designs belonging to Tata’s clients.
The common thread across most of these cases is that attackers rarely walk in the front door of the organisation named in the headline. They come through a supplier, a hosting provider, or a vendor portal.
Three things worth taking from this
Your data inherits your vendor’s security posture. Reliance’s documents were exposed because of where they were stored, not because of anything at Kudankulam. Vendor risk assessments and contractual security obligations are dull work. They are also cheaper than the alternative.
Old project files are live risk. The leaked material stretched back a decade. Design documents don’t become harmless with age when the thing they describe is still being built.
Isolation solves one problem, not all of them. Air-gapped control systems protected Kudankulam’s operations and did precisely nothing for the blueprints. Segmentation addresses availability and integrity. Confidentiality needs its own answer.
The clock is already running
Indian regulation assumes speed now. CERT-In requires reporting within six hours of detecting an incident. Listed companies must disclose material incidents to the exchanges. The DPDP Act adds its own notification duties where personal data is involved, and critical infrastructure operators have NCIIPC to notify as well.
Working out who you call, in what order, and with what information is a task for a quiet Tuesday afternoon. It is a terrible thing to be figuring out at 3am on the day it happens.