A reported cyberattack involving a contractor connected to India’s Kudankulam Nuclear Power Plant has prompted fresh concerns about cybersecurity at one of the country’s most important energy facilities.
The incident came to light after the ransomware group World Leaks allegedly uploaded thousands of files to the dark web, claiming they were linked to the Kudankulam project. The leaked material reportedly includes engineering drawings, supplier information, inspection records and other project-related documents.
Although the reports have attracted widespread attention, Indian officials insist that the country’s nuclear safety systems have not been compromised.
Thousands of Documents Reportedly Leaked
According to cybersecurity researchers, nearly 19,000 files connected to the project were published online. The documents reportedly cover several years of work and include records dating from 2016 to 2025.
The files are said to contain technical information related to construction, suppliers, inspections and project management. However, the authenticity of the documents has not been independently confirmed.
The leak was first highlighted by cybersecurity researcher Rakesh Krishnan, who alerted media outlets after discovering the files on the dark web.
Reliance Group Confirms Limited Security Incident
Reliance Group, one of the contractors involved in the Kudankulam project, acknowledged that it experienced what it described as a partial data breach.
The company said the incident affected data stored on servers operated by third-party data centre provider Yotta. However, it did not reveal exactly which files had been accessed or whether any confidential project information was involved.
Reliance also confirmed that it had informed the Indian government and is cooperating with authorities investigating the incident.
Government Says Nuclear Security Was Not Affected
The Nuclear Power Corporation of India (NPCIL) moved quickly to reassure the public after reports of the breach emerged.
Officials said the leaked information relates only to common service facilities connected with the project and does not involve nuclear safety systems, reactor operations or security infrastructure.
According to the corporation, the country’s nuclear facilities continue to operate safely, and there is no indication that sensitive operational systems were exposed.
Cybersecurity Experts Urge Caution
Even though officials say critical systems remain secure, cybersecurity specialists believe incidents like this should be taken seriously.
Experts point out that engineering documents, contractor information and infrastructure records can still be valuable to cybercriminals if they fall into the wrong hands. They say attacks targeting energy facilities have become more common as hackers increasingly focus on critical infrastructure around the world.
India’s national cybersecurity agency, CERT-In, has launched an investigation to determine exactly what information may have been exposed and whether additional security measures are needed.
A Reminder of Growing Cybersecurity Risks
The Kudankulam Nuclear Power Plant is India’s largest nuclear energy facility and plays a major role in the country’s long-term energy strategy. New reactors are currently under construction as India continues expanding its nuclear power capacity.
While officials maintain that the reported breach did not affect nuclear safety, the incident highlights the growing cybersecurity challenges facing major infrastructure projects.
As investigations continue, authorities are expected to review existing security systems to ensure similar incidents can be prevented in the future. The case also serves as another reminder that protecting digital infrastructure has become just as important as protecting physical facilities in today’s increasingly connected world.