According to the Indian Express reported on July 17, a group called World Leaks released a large cache of documents related to India’s largest nuclear power plant, Kudankulam. These documents included blueprints for some facilities at the plant and details about suppliers. The group marked these information as coming from the Reliance Group.
Sincerity Group is one of the contractors for the power plant, and it informed Reuters that data from its managed by a third-party Indian data center service provider was partially leaked. The Indian government has been notified of this incident.
Symphony Group has not disclosed which data was leaked.
The American non-governmental organization ‘Nuclear Threat Initiative’ stated that this data breach could pose a ‘serious’ risk to the safety of power plants.
Independent cybersecurity researcher Rakesh Krishnan said that since June 11, nearly 19,000 files have appeared on the dark web, totaling 14.3 gigabytes. These files appeared when searching for the abbreviation of that nuclear power plant, “KKNP”.
Reuters found that these documents date from 2016 to mid-2025, but their authenticity could not be verified. In addition to some blueprints and supplier details, the documents reportedly contained records of meetings and inspections, equipment reviews, and insurance policies.
Sinist Infrastructure Co., Ltd. won the contract in 2018 to design and build infrastructure for Units 3 and 4 of the power plant. Both units are still under construction and are expected to be operational in 2027, with a total installed capacity of 2000 megawatts.
World Leaks is a well-known ransomware organization that has previously attacked Nike and other companies. The organization typically publishes the stolen corporate data on its website after businesses refuse to pay the demanded ransom. Its website can only be accessed through specialized browsers.
The Indian nuclear power company issued a statement indicating that the information available in the public domain only relates to general service facilities and has nothing to do with any nuclear safety or nuclear security-related systems.
According to cybersecurity company Surfshark, India ranks third among countries with the most data breaches. Last year, 28.9 million accounts were hacked, second only to the United States and France.
According to a report released last year by the Indian Data Security Council and cybersecurity company Seqrite, in surveys of 204 organizations in India, approximately 73% were unaware of whether they had been attacked, and 57% lacked cybersecurity practices.