Skip to content
Yellow Desk
July 28, 2026
India

Kudankulam nuclear plant cyber attack: Were sensitive files leaked? NPCIL says safety systems unaffected

Thomas Smith - indiadailyupdate.com 4 mins read

Kudankulam Nuclear Plant Cyber Attack: Data Leak Concerns and Safety Assurances Kudankulam nuclear plant cyber attack - The Kudankulam Nuclear Power Plant

Kudankulam nuclear plant cyber attack: Were sensitive files leaked? NPCIL says safety systems unaffected

Kudankulam Nuclear Plant Cyber Attack: Data Leak Concerns and Safety Assurances

Indiadailyupdate.com – The Kudankulam Nuclear Power Plant (KKNP) has become the center of attention after a cyber attack raised alarms about potential data exposure. Reports indicate that thousands of sensitive documents, including technical designs and supplier details, were reportedly shared on the dark web by a ransomware group. The breach, attributed to Reliance Infrastructure—a key contractor for the project—has sparked questions about the security of India’s nuclear facilities. While officials from NPCIL, the agency overseeing the plant, have reassured the public that critical safety systems remain intact, the incident underscores growing vulnerabilities in the nation’s energy infrastructure.

Details of the Cyber Attack and Its Scope

According to independent cybersecurity experts, the attack exposed nearly 19,000 files totaling approximately 14.3 GB. These documents were accessible under the term “KKNP” since June 11, as reported by Reuters. The breach occurred through servers managed by Yotta, a third-party data center provider. While the exact timeline and method of infiltration remain under investigation, the ransomware group claims it gained access via Reliance Infrastructure, which handles engineering, procurement, and construction of the plant’s conventional systems. This revelation has intensified scrutiny over the integration of private sector involvement in nuclear projects.

NPCIL has emphasized that the compromised data pertains solely to the Balance of Plant (BoP) facilities, which support the nuclear reactors but are distinct from the core safety systems. The organization stated in a formal statement that the cyber attack does not threaten the operational integrity of the plant’s nuclear reactors or its security protocols. “All safety-critical systems remain unaffected,” NPCIL clarified, assuring that the incident has no bearing on the plant’s ability to generate power or meet safety standards.

Reliance Infrastructure’s Role and Response

Reliance Infrastructure, a subsidiary of the Reliance Group, was contracted in 2018 to develop Units 3 and 4 of the Kudankulam Nuclear Plant. The two reactors, with a combined capacity of 2,000 MW, are slated for commissioning next year. The company acknowledged a “partial breach” involving data stored on Yotta’s servers, which were quickly secured to prevent ransomware execution, data loss, or further spread within the network. This incident marks the first significant cyber threat reported at the Kudankulam nuclear plant, prompting a review of security protocols across the project’s supply chain.

Industry insiders suggest that the breach highlights the challenges of balancing efficiency with cybersecurity in large-scale infrastructure projects. While Reliance Infrastructure’s role is limited to conventional systems, the integration of third-party data centers introduces new risks. NPCIL has since stated that all design reviews and technical assessments were conducted with rigorous checks, ensuring compliance with international safety standards. However, the incident has fueled debates about the adequacy of current cybersecurity measures in protecting nuclear facilities from evolving threats.

The cyber attack on Kudankulam nuclear plant also coincides with India’s broader push to expand nuclear energy capacity. The Modi government’s nuclear mission, launched last year, prioritizes two approaches: scaling conventional reactors through mass construction and introducing small modular reactors (SMRs) with private sector participation. The recently enacted Sustainable Harnessing and Advancement of Nuclear Energy for Transforming India (SHANTI) Act further enables private companies to operate nuclear plants, accelerating this growth. While the breach at Kudankulam may not directly impact the nuclear mission’s goals, it serves as a cautionary tale for the sector’s digital security.

“The exposure of design schematics and supplier information through the Kudankulam nuclear plant cyber attack could potentially reveal insights into the project’s operational logistics and vendor relationships,” noted cybersecurity analyst Rakesh Krishnan. “Though the safety systems are unaffected, this incident highlights the need for enhanced digital safeguards in both public and private sectors managing nuclear infrastructure.”

In the wake of the breach, NPCIL has committed to a thorough security audit to identify vulnerabilities and implement additional layers of protection. Reliance Infrastructure has also pledged to strengthen its cybersecurity measures, including encryption protocols and real-time monitoring. The incident has prompted discussions about the role of private contractors in safeguarding India’s energy security, particularly as the nation increases its reliance on nuclear power to meet growing energy demands. As the Kudankulam nuclear plant cyber attack evolves, its implications for the nuclear sector and digital resilience will likely remain a topic of debate among policymakers and industry experts.

Leave a Reply

Your email address will not be published. Required fields are marked *