TAMIL NADU — Ransomware group World Leaks posted files related to the Kudankulam Nuclear Power Plant on the dark web. Nearly 19,000 files totaling 14.3 gigabytes appeared in the data for the search term "KKNP," and the files have been online since June 11.

The leaked files included purported blueprints of parts of the plant's facilities and supplier details. Among the documents were what appeared to be blueprints for the ventilation and cooling systems in Units 3 and 4, as well as the complete floor layout of a "common control room." The files also contained vendor proposals, a list of approved suppliers, and a record of a 2024 meeting about a joint inspection by the Nuclear Power Corporation of India and Reliance Infrastructure. One document purports to show that Reliance Infrastructure and the Nuclear Power Corporation had taken out an insurance policy that would entitle them to $112 million if either Unit 3 or Unit 4 were to suffer an act of terrorism.

World Leaks labeled the information as coming from Reliance Group. Reliance Group issued a statement confirming a partial breach of its data on a server hosted by third-party Indian data center service provider Yotta. The company stated that the government has been informed about the incident but did not disclose what data had been breached. Independent cybersecurity researcher Rakesh Krishnan first alerted Reuters to the leak.

Yotta stated it noted suspicious activity on May 29 on a server it hosts that belongs to Reliance Infrastructure. The company said the suspicious activity was immediately terminated and the suspected ransomware execution was prevented. Reliance Infrastructure informed Yotta at the end of June that there had been claims of a data breach made by external threat actors. Yotta stated it has not been able to verify the claims of the threat actor but has shared its detailed technical investigation with Reliance Infrastructure and supports an ongoing investigation.

The documents were dated from 2016 to mid-2025. The authenticity of the documents could not be verified. The 19,000 files appeared to be the most sensitive of a total 858,000 Reliance files on the World Leaks website.

The files purportedly show meeting and inspection records, equipment reviews, and insurance policies. The documents posted on World Leaks do not appear to relate to the nuclear reactors' core systems, which are supplied by Russia's state-owned Rosatom.

Reliance Infrastructure won a contract in 2018 to design and build infrastructure for the plant's Unit 3 and Unit 4. Units 3 and 4 are still under construction, are due to be operational by 2027, and are slated to provide a combined 2,000 megawatts of capacity. The Kudankulam Nuclear Power Plant is located in the southern state of Tamil Nadu and is the largest of India's seven nuclear plants.

World Leaks has previously targeted Nike and India's Tata Group. The group typically posts stolen corporate data on its website after companies decline to pay the ransom demanded. In June, World Leaks stated it had sought $1.5 million in ransom for Tata Group files, which contained confidential component designs of clients Apple and Tesla. World Leaks stated it posted the Tata Group data after Tata "ignored" its demand.

The Nuclear Power Corporation of India has been communicating with Reliance about the breach. The Indian Computer Emergency Response Team (CERT-In) is looking into the incident. Malware tied to a North Korean hacker group was found on the Kudankulam plant's administrative network in 2019. The Nuclear Power Corporation stated at the time that the matter was investigated immediately and plant systems were not affected.

The Kudankulam Nuclear Power Plant represents a critical piece of India’s energy infrastructure, with Units 3 and 4 expected to expand its generating capacity by 2027. The breach involves files tied to infrastructure under active construction, raising concerns about potential vulnerabilities in systems that support nuclear operations—even if core reactor systems are not directly implicated. India ranks third globally in data breaches, with 28.9 million accounts compromised last year, and a recent report by the Data Security Council of India and cybersecurity firm Seqrite found that 73% of surveyed organizations were unaware if they had ever been attacked, while 57% lacked basic cyber hygiene practices.

Nickolas Roth, senior director at the Nuclear Threat Initiative, which advises governments and benchmarks countries on nuclear safety, said the data breach could pose a "serious" risk to the safety of the plant. He added that the documents "could show an adversary not just who has access to the project but which systems that access reaches." The leak follows a prior incident in 2019 involving North Korean malware on the plant's administrative network, underscoring recurring cybersecurity challenges at sensitive nuclear sites in India.