Key Facts
- Perpetrator: World Leaks (also referred to as World Lix) ransomware group
- Scale: Over 858,000 Reliance corporate files posted; 19,000 files (14.3 GB) linked to KKNPP
- Timeline: Yotta detected suspicious activity on May 29, 2026; files surfaced online around June 11, 2026
- Exposed Data: Blueprints for ventilation/cooling systems (Units 3 & 4), common control room floor layout, supplier lists, vendor proposals, inspection records, $112 million anti-terrorism insurance policy
- Official Response: Reliance Group confirmed “partial breach”; NPCIL stated core nuclear safety systems unaffected
- Investigation: CERT-In and Department of Atomic Energy investigating
Direct Answer
A ransomware group known as World Leaks (or World Lix) has published thousands of files linked to India’s Kudankulam Nuclear Power Plant on the dark web, claiming the data was obtained from Anil Ambani’s Reliance Group .
The breach occurred on a server belonging to Reliance Infrastructure — a key contractor for the plant’s expansion — hosted by third-party data centre provider Yotta Data Services . Out of over 858,000 corporate Reliance files posted, approximately 19,000 files (totaling 14.3 GB) are directly tied to the KKNPP project and include blueprints for ventilation and cooling systems, supplier lists, and a $112 million anti-terrorism insurance policy .
While the Nuclear Power Corporation of India Limited (NPCIL) confirmed that core nuclear safety systems — supplied by Russia’s Rosatom as “standalone” networks — were unaffected, nuclear security experts warn the leaked documents could be exploited by bad actors to map vulnerabilities and coordinate supply chain attacks . CERT-In and the Department of Atomic Energy have launched a high-level investigation .
In this article:
- The Perpetrator: World Leaks Ransomware Group
- Timeline of the Breach
- What Was Exposed: The Leaked Data
- Official Responses: Reliance Group and NPCIL
- Security Implications: Supply Chain Risks
- Government Investigation
- India’s Cybersecurity Readiness
- FAQ
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
The Perpetrator: World Leaks Ransomware Group
World Leaks (also referred to as World Lix) is a well-known ransomware group that has previously targeted major corporations, including Nike and India’s Tata Group .
The group typically steals corporate data and demands payment in exchange for not releasing it publicly. If organisations refuse to pay, the group publishes the stolen material on its dark web portal . In June 2026, World Leaks told Reuters it had sought $1.5 million in ransom for Tata Group files containing confidential component designs of clients Apple and Tesla, releasing the data after Tata “ignored” its demand .
The group’s website can only be accessed using a specialised browser . World Leaks did not respond to Reuters’ queries about the Reliance data breach .
Timeline of the Breach
Chronology of Events
Yotta, the third-party data centre provider, first detected suspicious activity on a server hosted by its facility and belonging to Reliance Infrastructure on May 29, 2026 . The activity was immediately terminated and the suspected ransomware execution was prevented .
However, by late June, Reliance Infrastructure informed Yotta that external threat actors were claiming responsibility for a data breach . Files began appearing online around June 11, 2026, according to independent cybersecurity researcher Rakesh Krishnan, who first alerted Reuters to the leak .
Yotta stated that it has been unable to independently verify the claims of the “threat actor” but has shared detailed technical investigation findings with Reliance Infrastructure and is supporting the ongoing investigation .
What Was Exposed: The Leaked Data
Out of over 858,000 corporate Reliance files posted on the dark web by World Leaks, approximately 19,000 files (totaling 14.3 GB) are directly linked to the Kudankulam Nuclear Power Plant project .
The documents, dated between 2016 and mid-2025, include :
Engineering and Infrastructure Documents
- Blueprints for ventilation and cooling systems used in Units 3 and 4
- Complete floor layout of a “common control room”
Procurement and Supply Chain Data
Operational Records
- Records of a 2024 joint inspection meeting between NPCIL and Reliance engineers, including photographs of equipment
- Meeting and inspection records
Financial Documents
- A $112 million (approximately ₹934 crore) anti-terrorism insurance policy taken out by Reliance Infrastructure and NPCIL, covering Units 3 and 4
Reuters reviewed the documents but could not independently verify their authenticity .
The documents do not appear to relate to the nuclear reactors’ core systems, which are supplied by Russia’s state-owned Rosatom .
Official Responses: Reliance Group and NPCIL
Reliance Group
Reliance Group confirmed a “partial breach” of its data on a server hosted by third-party data centre service provider Yotta . The company stated that the incident had been reported to the government but did not disclose what specific data had been accessed .
The company maintained that there was “no ransomware execution, data loss or lateral movement within its systems” .
Nuclear Power Corporation of India Limited (NPCIL)
NPCIL issued a statement asserting that the leaked documents relate only to “conventional balance of plant (BoP) common service facilities” and “do not relate to any nuclear safety or nuclear security-related systems or information” .
NPCIL clarified that:
- Reliance Infrastructure’s contract is limited to conventional, non-nuclear infrastructure .
- The scope covers common service facilities of a conventional nature — similar to those used in thermal power plants and other industrial facilities — and does not involve nuclear safety or security systems .
- The core reactor systems, supplied by Russia’s Rosatom, are built as “standalone” networks and were not compromised .
The company emphasised that the information reportedly available in the public domain pertains only to conventional BoP facilities, which are “of conventional nature” and typically found in thermal power plants and other process industries .
Security Implications: Supply Chain Risks
Despite official assurances that core nuclear systems remain unaffected, security experts have expressed serious concerns about the breach.
Nickolas Roth, Senior Director at the Nuclear Threat Initiative (NTI), told Reuters that the breach could pose a “serious” risk to the safety of the plant .
Key risk factors identified by experts:
- Mapping Vulnerabilities: The files — including blueprints of support systems — could be used by adversaries to map the plant’s auxiliary networks and identify weaknesses in the security chain .
- Supply Chain Attacks: Supplier lists and vendor information could be exploited to target contractors and service providers, compromising the integrity of the supply chain .
- Access Mapping: The data could “show an adversary not just who has access to the project but which systems that access reaches,” Roth explained .
- Comprehensive Reconnaissance: Engineering documents, combined with supplier information and insurance records, provide a comprehensive picture of the facility’s operations that could be used for future attacks .
Sources within the project
According to The Hindu, sources within KKNPP said the leak had triggered “absolute commotion” among the project’s leading team, who were said to be initially “completely clueless” about this development . A senior NPCIL official maintained that the leaked files were “ordinary” in nature, common to any thermal power plant and unrelated to plant safety .
Government Investigation
The Indian Computer Emergency Response Team (CERT-In), the government’s premier cybersecurity agency, alongside internal specialists from the Department of Atomic Energy, has launched a high-level investigation into the breach .
NPCIL has been communicating with Reliance about the breach, according to a source familiar with the matter .
The Department of Atomic Energy declined to comment, and the Prime Minister’s Office did not respond to Reuters’ queries .
India’s Cybersecurity Readiness: Broader Context
The breach highlights broader concerns about India’s cybersecurity preparedness, particularly regarding critical infrastructure.
Data Breach Statistics
According to cybersecurity company Surfshark, India ranked third globally for data breaches in 2025, with 28.9 million accounts compromised, behind only the United States and France .
Organisational Readiness
A 2025 report by the Data Security Council of India and cybersecurity firm Seqrite found that:
- 73% of 204 organisations surveyed across India were “unaware if they have ever been attacked” .
- 57% lacked basic cyber hygiene practices .
Previous Incident at KKNPP
This is the second time the Kudankulam plant has been linked to a cyber incident. In 2019, malware linked to a North Korean hacker group was found on the plant’s administrative network. At the time, NPCIL said the matter was investigated immediately and plant systems were unaffected .
FAQ
What happened in the Kudankulam data breach?
Ransomware group World Leaks posted thousands of files linked to India’s Kudankulam Nuclear Power Plant on the dark web, including blueprints, supplier lists, and insurance documents, after breaching a server belonging to contractor Reliance Infrastructure .
Who is responsible for the Kudankulam data leak?
The ransomware group World Leaks (also referred to as World Lix) claimed responsibility for the cyberattack .
When did the Kudankulam data breach occur?
Yotta detected suspicious activity on a server on May 29, 2026. Files began surfacing online around June 11, 2026 .
How many files were leaked in the Kudankulam breach?
Approximately 19,000 files totalling 14.3 GB, out of a total of 858,000 Reliance corporate files posted on the dark web .
What information was exposed in the Kudankulam data breach?
Exposed files include blueprints for ventilation and cooling systems, the floor layout of a common control room, approved supplier lists, vendor proposals, joint inspection records, and a $112 million anti-terrorism insurance policy .
Were the nuclear reactors affected by the breach?
No. NPCIL confirmed that core nuclear safety and reactor operating systems — supplied by Russia’s Rosatom as “standalone” networks — were unaffected .
What is the security risk from the leaked documents?
Nuclear security experts warn that adversaries could use the blueprints and supplier lists to map vulnerabilities, identify weaknesses in the security chain, and coordinate supply chain attacks .
Which government agencies are investigating the breach?
The Indian Computer Emergency Response Team (CERT-In) and the Department of Atomic Energy have launched a high-level investigation .
Has this happened before at Kudankulam?
Yes. In 2019, malware linked to a North Korean hacker group was found on the plant’s administrative network .
What does the breach reveal about India’s cybersecurity readiness?
A recent survey found that 73% of Indian organisations were “unaware if they have ever been attacked,” while 57% lacked basic cyber hygiene practices .
Q: Did the hackers gain control of the nuclear reactor core systems?
Ans: No. NPCIL confirmed that the core reactor systems, supplied by Russia’s Rosatom, are built as “standalone” networks and were completely unaffected.
Q: What specific engineering details were leaked about the plant?
Ans: The leaked files included blueprints for the ventilation and cooling systems of Units 3 and 4, and the common control room floor layout.
Q: What is a “Supply Chain Attack” in this context?
Ans: It is when threat actors target a secondary contractor (like Reliance Infrastructure) to gain access to the data or assets of the primary client (the nuclear power plant).
Q: What role did the Yotta Data Center play in the breach?
Ans: Yotta provided the server hosting for Reliance Infrastructure, where the suspicious activity was first detected on May 29, 2026.
FREQUENTLY ASKED QUESTIONS (FAQ)
Q: Is there an immediate safety risk to the Kudankulam plant?
Ans: Nuclear security experts, including those from NTI, warn that while core systems are safe, the blueprints and supplier lists provide adversaries with reconnaissance data to map support system vulnerabilities.
Q: Why do attackers steal insurance policies?
Ans: Insurance policies reveal the client’s assessment of potential risks (terrorism, equipment failure). This intelligence helps attackers understand what the company views as its most vulnerable and valuable assets.
Q: What should companies do if they are a “third-party contractor” for a critical infrastructure project?
Ans: They must treat their client’s data as if it were classified national security material, implementing high-grade encryption and network segmentation that exceeds standard commercial requirements.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Adv. Shoeb Hakim Cybercrime & Digital Forensics Advisor | shoebhakim.com
🔖 #AdvShoebHakim #Kudankulam #CyberAttack #Ransomware #SupplyChainSecurity #CriticalInfrastructure #CyberEspionage #WorldLeaks #DataBreach #IndiaCybersecurity #Reliance #NPCIL #DigitalForensics #Vakilverse #LegalComplianceIN
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
Author:
Adv. Shoeb Hakim
Author Bio (for schema markup):
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police and judiciary since 1996. Provides expert commentary on cybercrime, data protection, critical infrastructure security, and financial crime.
Article Publisher:
Adv. Shoeb Hakim
Article Section:
Cybersecurity | Critical Infrastructure | Data Breach | Nuclear Security
Article Tags:
Kudankulam, nuclear plant, data breach, ransomware, World Leaks, Reliance Group, Reliance Infrastructure, Yotta, NPCIL, CERT-In, cybercrime, supply chain attack, critical infrastructure, Adv Shoeb Hakim



Leave a Reply