← Blog

Nuclear Power Corporation of India Data Breaches: Full Timeline Through 2026

Share on X

People search Nuclear Power Corporation of India data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 2 Nuclear Power Corporation of India-linked incidents, with headline counts up to 19K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Nuclear Power Corporation of India breach history matters

Nuclear Power Corporation of India operates in Energy (India). Across indexed rows, recurring themes include ransomware and extortion, zero-day exploitation and malware, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — World Leaks exposure via Reliance contractor breach; ~19K files (Jul)

Cataloged incident. Critical-infrastructure document exposure — July 15, 2026. Reuters reported World Leaks published ~19,000 files from an 858,000-file Reliance Group cache that appear tied to India's largest nuclear plant, Kudankulam (Tamil Nadu), operated by NPCIL. Materials surfaced through a partial breach Reliance Infrastructure confirmed on a Yotta Data Services-hosted server; Reliance holds the 2018 contract for Units 3–4 support infrastructure. NPCIL was communicating with Reliance about the incident at reporting time but had Exposed categories include ~19,000 files in World Leaks Reliance cache purportedly relate to Kudankulam Units 3–4 support infrastructure: ventilation/cooling blueprints, control room layout, vendor proposals. BreachHistory cites approximately 19K+ affected records in this row. See the kudankulam-nuclear-npcil-reliance-worldl and canonical BreachHistory entry.

2019 — Dtrack malware, IT network

Cataloged incident. Kudankulam nuclear plant IT network compromised by Dtrack malware (Lazarus Group). Admin credentials stolen. Malware collected browser history, registry info. OT network not affected. Exposed categories include IT network data, admin credentials. No attested victim count is published for this row yet. See the npcil2019 and canonical BreachHistory entry.

Patterns and analysis

  • Ransomware and extortion — appears across multiple Nuclear Power Corporation of India catalog entries; prioritize controls that address this class of failure.
  • Zero-day exploitation and malware — appears across multiple Nuclear Power Corporation of India catalog entries; prioritize controls that address this class of failure.
  • Unverified actor or scraping claims — appears across multiple Nuclear Power Corporation of India catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the Nuclear Power Corporation of India company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/npcil · Latest: kudankulam-nuclear-npcil-reliance-worldleaks2026.

Sources: BreachHistory catalog (2 rows for Nuclear Power Corporation of India), company and regulator disclosures cited in individual breach records.