Kudankulam Files Posted On Dark Web, NPCIL Says No Safety Risk

About 19,000 files relating to the Kudankulam Nuclear Power Project in south Tamil Nadu, the largest nuclear facility in the country, were posted on the dark web by a ransomware group called World Leaks, prompting concern in national security and nuclear establishments. Reuters reported that the group asserted the material formed part of more than 0.85 mn documents that it said were obtained by hacking members of the Reliance Anil Ambani group. The disclosure has led to heightened scrutiny by cybersecurity and government agencies.

The Nuclear Power Corporation of India Ltd (NPCIL) stated that no drawings, data or information connected to nuclear safety or nuclear security systems were compromised, and clarified that engineering, procurement and construction work carried out by Reliance Infrastructure pertains only to commissioning of common service facilities. NPCIL emphasised that these facilities are conventional in nature and similar to those used in thermal power plants and other process industries, and that they are not linked to nuclear safety or nuclear security systems. The corporation indicated that it was coordinating with relevant agencies on the matter.

Media reports and agency accounts indicated that the leaked material included blueprints and details of ventilation and cooling systems for Units three and four, which are under construction by a firm of the Anil Ambani Group. Reliance Infrastructure informed agencies that a partial data breach had occurred at a third party service provider engaged by the firm and that the government had been notified. The incident prompted the Computer Emergency Response Team India (CERT-In) to begin an investigation and has drawn attention to supply chain vulnerabilities.

While officials continue to assess the extent of the breach and the identities of those responsible, authorities have underlined that current assessments do not show compromise of nuclear safety or security systems. Investigations are ongoing and agencies are coordinating technical reviews and mitigation measures. The episode has nevertheless reinforced calls for tighter oversight of third party data handling in critical infrastructure projects.

Related Stories