2026 Reliance Infrastructure — World Leaks extortion; 858K files posted; ~19K Kudankulam nuclear plant docs (Jul)
Data compromised
Reuters-reviewed World Leaks dump of 858,000 Reliance Group files includes ~19,000 Kudankulam Nuclear Power Plant-related documents: purported ventilation/cooling blueprints for Units 3–4, common control room floor layout, vendor proposals, approved supplier lists, 2024 NPCIL–Reliance joint inspection records with equipment photos, meeting notes, insurance policies—documents dated 2016–mid-2025; not reactor core systems (Rosatom-supplied)
Technical writeup
Verified partial breach — disclosed July 15, 2026. Anil Ambani's Reliance Group told Reuters a "partial breach" occurred on data hosted on a server operated by Indian data-centre provider Yotta Data Services. The World Leaks extortion group posted a cache of 858,000 files labelled as Reliance data; Reuters identified roughly 19,000 as the most sensitive subset tied to India's Kudankulam Nuclear Power Plant in Tamil Nadu. Reliance Infrastructure won a 2018 contract to design and build support infrastructure for Kudankulam Units 3 and 4 (2,000 MW combined, due online ~2027). Leaked materials purportedly include ventilation and cooling system blueprints, a common control room layout, vendor and supplier details, joint NPCIL–Reliance inspection records, and terrorism insurance documentation—Reuters could not fully verify authenticity. Yotta said it detected suspicious activity May 29, 2026, terminated it, and that Reliance flagged external leak claims in late June; Yotta shared forensic findings with Reliance. NPCIL has been communicating with Reliance; CERT-In is investigating per sources. Nuclear Threat Initiative's Nickolas Roth warned exposure could map adversary access paths to plant support systems. Distinct from Kudankulam's 2019 administrative-network malware incident. BreachHistory indexes Reuters-cited 858,000 total files with ~19,000 nuclear-plant-related subset.
Root cause
Partial data breach on Reliance Infrastructure server hosted by Yotta Data Services; World Leaks ransomware group published cache after extortion—suspicious activity on Yotta-hosted server May 29, 2026