A ransomware group has published nearly 19,000 files linked to India's Kudankulam Nuclear Power Plant on the dark web, exposing purported blueprints of ventilation and cooling systems for reactors scheduled to come online in 2027.
The hacker collective World Leaks posted the cache of 14.3 gigabytes, which has been accessible online since June 11 and contains documents dated from 2016 through mid-2025. Reliance Group, a contractor for the plant, acknowledged a partial data breach on a server hosted by Yotta. The leaked files mostly concern units 3 and 4, whose infrastructure Reliance was contracted to design and build, but do not include information on reactor core systems supplied by Russia's Rosatom.
The Nuclear Power Corporation of India said the breach involved only public-service facilities and did not compromise nuclear security systems. India's Computer Emergency Response Team is investigating the incident.