← Blog

Kudankulam Leak: 19K Nuclear Files on Dark Web

Share on X

July 15, 2026: Ransomware group World Leaks published a cache of files on the dark web that Reuters says includes roughly 19,000 documents tied to India's Kudankulam Nuclear Power Plant—the country's largest atomic facility—from a broader 858,000-file dump labelled as Reliance Group data.

What was exposed

Reuters reviewed materials dated 2016 through mid-2025 but could not fully verify authenticity. The Kudankulam subset reportedly includes:

  • Purported ventilation and cooling system blueprints for Units 3 and 4
  • A common control room floor layout
  • Vendor proposals and approved supplier lists
  • 2024 joint inspection records between NPCIL and Reliance, with equipment photos
  • Terrorism insurance documentation citing up to $112 million coverage per unit

Reuters noted the files do not appear to cover reactor core systems supplied by Russia's Rosatom—they focus on support infrastructure Reliance Infrastructure was contracted to build after winning a 2018 deal for Kudankulam Units 3 and 4 (2,000 MW combined, targeted for 2027).

What Reliance and Yotta confirmed

Anil Ambani's Reliance Group told Reuters there was a "partial breach" of data on a server hosted by Indian data-centre provider Yotta Data Services, and that the government was informed. Reliance did not specify every data category lost.

Yotta said it saw suspicious activity on the Reliance Infrastructure server on May 29, 2026, terminated it, and believed ransomware execution was prevented—then learned of external leak claims from Reliance in late June.

Why experts are alarmed

Nickolas Roth of the Nuclear Threat Initiative told Reuters the exposure is serious: leaked files could show an adversary "not just who has access to the project but which systems that access reaches." NPCIL has been communicating with Reliance; India's CERT-In is investigating, per sources familiar with the matter.

World Leaks context

The same group sought $1.5 million in ransom from Tata Group in June 2026 for files containing confidential Apple and Tesla component designs, posting the archive after Tata ignored the demand—part of a rising wave of Indian corporate extortion.

Action items

  1. Critical-infrastructure contractors should audit third-party hosting segmentation and project-data access immediately.
  2. Do not download alleged leak archives from forums or Telegram.
  3. Watch for spear-phishing targeting nuclear-sector suppliers using real vendor names from the dump.

Canonical records: Reliance Infrastructure 2026 · Kudankulam/NPCIL exposure.