INDIA: Hackers Claim Leak of Sensitive Documents From Kudankulam Nuclear Power Plant
· 103 views
NEW DELHI (Terror Monitor) — The ransomware group World Leaks has allegedly published sensitive documents linked to India’s Kudankulam Nuclear Power Plant (KKNPP) on the dark web following a reported data breach, raising fresh concerns over the cybersecurity of critical infrastructure.
According to Reuters, the Kudankulam Nuclear Power Plant, located in the southern state of Tamil Nadu, is India’s largest nuclear power facility and plays a central role in Prime Minister Narendra Modi’s nuclear energy expansion program.
Reliance Group, a contractor involved with the project, confirmed that one of its servers suffered a “partial data breach.” The company said the affected server was hosted by Indian data center provider Yotta and that the incident had been reported to the government, but it did not disclose what information may have been compromised.
Independent cybersecurity researcher Rakesh Krishnan said approximately 19,000 files, totaling 14.3 gigabytes, have been available on the dark web under the label “KKNPP” since June 11. The files allegedly contain documents dating from 2016 to mid-2025.
Reuters reviewed portions of the leaked material but said it could not independently verify its authenticity. The documents reportedly include ventilation and cooling system diagrams, supplier information, inspection reports, meeting records, and insurance documents.
Cybersecurity experts warned that if authentic, the leaked information could expose details about the plant’s support systems, supply chain, and potential security vulnerabilities, increasing the risk to the facility.
Nicholas Roth, Senior Director at the Nuclear Threat Initiative, said such information in the wrong hands could pose a serious security threat to the nuclear plant.
India’s Nuclear Power Corporation and the national cybersecurity agency CERT-In are investigating the incident. However, authorities have not yet confirmed the authenticity or scope of the alleged leaked data.
Yotta said it detected suspicious activity on Reliance Infrastructure’s server on May 29 and took immediate action to stop what appeared to be a ransomware attack. The company later became aware of claims by external actors that data from the server had been leaked.
World Leaks has previously targeted major organizations in cyberattacks and is known for allegedly publishing stolen data on the dark web when ransom demands are not met.
Related Articles
US Approves $5 Billion Arms Sale to Saudi Arabia
The U.S. State Department has approved a $5 billion military equipment sale to Saudi Arabia, including guidance systems for thousands of bombs and long-range missiles. Washington said the deal would strengthen Saudi Arabia’s air-defense capabilities and contribute to stability and economic development in the Gulf.
Pakistan Appoints Major General Faisal Naseer as NACTA National Coordinator
Pakistan’s federal government has appointed Major General Faisal Naseer as National Coordinator of the National Counter Terrorism Authority (NACTA) for a three-year term. Naseer, a former head of the ISI’s Internal Wing, takes charge as Pakistan faces rising militant violence, particularly in Khyber Pakhtunkhwa and Balochistan.
Israel and Greece Sign $3.5 Billion Defense Deal for Multilayered Air Defense System
Israel and Greece have signed a $3.5 billion defense agreement, their largest arms deal to date, under which Athens will acquire a multilayered Israeli air defense system designed to counter ballistic missiles, drones and other aerial threats.
Turkey, Saudi Arabia and Pakistan to Hold First Meeting Under New Joint Defense Pact
Turkey, Saudi Arabia and Pakistan are set to hold their first committee meeting in Istanbul under the Makkah Joint Defense Agreement, which treats an armed attack on any one of the three countries as an attack on all. The pact aims to strengthen collective defense, military coordination and cooperation in the defense industry amid rising tensions across the Middle East.