India Kudankulam Nuclear Plant Leak: Documents From A Contractor’s Hacked Server Include Control Room Floor Plans And Cooling System Drawings, Prompting A CERT-In And NPCIL Investigation
According to Gulf News, ransomware group World Leaks has published more than 19,000 files allegedly stolen from the Reliance Group; a contractor at the Kudankulam Nuclear Power Plant in Tamil Nadu, India’s largest nuclear power station with the full cache potentially containing up to 858,000 documents.
A Reuters investigation reviewed the leaked files, which reportedly include ventilation and cooling system drawings, control room floor plans, equipment inspection reports, vendor proposals, supplier lists, and internal meeting records for Units 3 and 4 of the plant, which are currently under construction and expected to begin operations in 2027.
Reactor core designs and critical nuclear technology supplied by Russia’s state-owned Rosatom do not appear to have been included in the leak.
Reliance Group confirmed a partial data breach occurred on a server hosted by third-party provider Yotta, which detected suspicious activity on May 29. India’s Computer Emergency Response Team and the Nuclear Power Corporation of India have launched investigations.
Nickolas Roth of the Nuclear Threat Initiative told Reuters the breach could pose a “serious” risk, warning that even infrastructure-level documents reveal access patterns and system vulnerabilities that hostile actors can exploit without ever touching the reactor.
A nuclear plant’s supporting infrastructure is not a minor footnote. Who supplies it, who inspects it, and how it is configured are exactly the details that turn a cyberattack into a physical one. India’s Department of Atomic Energy and the Prime Minister’s Office have not publicly commented.
Check out our previous coverage of tech on The Trusted Times.

