'Serious risk' to India's largest nuclear plant after sensitive files leaked on dark web: Report
Nearly 19,000 files (14.3 GB) linked to the Kudankulam Nuclear Power Plant (KKNPP) — India's largest nuclear power station — surfaced on a dark web leak site operated by a ransomware group, having reportedly been posted online since mid-June
The leaked files formed part of a larger cache of roughly 858,000 documents traced to a private conglomerate's servers, and reportedly included meeting and inspection records, equipment reviews, insurance policies, purported blueprints of the ventilation and cooling systems of under-construction reactor units, and the floor layout of a common control room
The affected company acknowledged a "partial breach" originating from a server hosted by a third-party data centre provider, and stated that the government had been informed
The Nuclear Power Corporation of India Limited (NPCIL) and India's national cybersecurity incident response agency are examining the incident; security researchers assessed the leak as a "serious" risk because such data could theoretically help map a facility's support systems, suppliers, and security weak points
Kudankulam Nuclear Power Plant (KKNPP) — India's Largest Nuclear Facility
KKNPP, located in Tirunelveli district, Tamil Nadu, is being built in six stages using Russian VVER-1000 pressurised water reactor technology, under an Indo-Russian intergovernmental framework involving the Nuclear Power Corporation of India Limited (NPCIL) and Russia's state nuclear agency. It is India's single largest nuclear power complex by planned capacity.
Key Details
- Units 1 and 2 (1,000 MW each) are operational, giving a current capacity of 2,000 MW; Unit 1 was synchronised with the southern grid in October 2013, Unit 2 in 2016
- Units 3–6 (4,000 MW additional) are under various stages of construction, taking total planned capacity to 6,000 MW
- Each VVER-1000 unit has a thermal capacity of ~3,000 MW and net electrical output of ~917 MW
- NPCIL is the public sector undertaking under the Department of Atomic Energy (DAE) responsible for design, construction, and operation of India's nuclear power plants
The plant whose sensitive engineering and security-layout data was exposed is this same six-unit KKNPP complex — the leaked material reportedly concerned systems in the under-construction Units 3 and 4.
Critical Information Infrastructure (CII) Protection Framework
Under the Information Technology Act, 2000, "Critical Information Infrastructure" is defined (Section 70A) as computer resources whose incapacitation would have a debilitating impact on national security, economy, public health, or safety. The National Critical Information Infrastructure Protection Centre (NCIIPC) is the National Nodal Agency for CII protection, notified under Section 70A on 16 January 2014, functioning as a unit of the National Technical Research Organisation (NTRO) under the Prime Minister's Office.
Key Details
- NCIIPC-designated critical sectors include energy (power, nuclear, oil and gas), transport, banking and finance, telecom, defence, and government e-services
- This is distinct from the Indian Computer Emergency Response Team (CERT-In), designated under Section 70B as the national nodal agency for cybersecurity incident response — collection, analysis, and dissemination of information on cyber incidents, and issuing advisories — operating under the Ministry of Electronics and Information Technology (MeitY) since 2004
- CERT-In's 2022 directions mandate reporting of cybersecurity incidents within six hours of detection and impose log-retention obligations on data centres and service providers
- NCIIPC protects designated CII assets proactively; CERT-In responds to and coordinates incidents across the wider digital ecosystem, including non-CII systems
A nuclear facility falls squarely within the "energy — nuclear" critical sector that NCIIPC is mandated to protect, while the incident response and breach investigation function (examining the leak's origin and scope) falls to CERT-In — illustrating the division of labour between the two agencies invoked whenever CII is compromised.
Nuclear Safety and Physical Protection Governance
The Atomic Energy Regulatory Board (AERB) was constituted on 15 November 1983 under Section 27 of the Atomic Energy Act, 1962, to enforce nuclear and radiological safety, including safety review, licensing, and physical protection oversight of operating nuclear power plants. Physical protection of nuclear material and facilities is also governed internationally by the Convention on the Physical Protection of Nuclear Material (CPPNM, 1980), which India has ratified, and its 2005 Amendment extending protection to nuclear facilities and domestic use/storage, not just international transport.
Key Details
- AERB reports functionally to the Atomic Energy Commission/DAE and reviews security and safety aspects of all operating nuclear plants, including KKNPP
- The CPPNM (in force since 1987) is the only binding international treaty on physical protection of nuclear material; its 2005 Amendment (in force 2016) added obligations on protecting nuclear facilities against sabotage
- IAEA Nuclear Security Recommendations (INFCIRC/225) provide the non-binding technical baseline that AERB's physical protection framework draws upon
Even though the leaked files are IT/engineering documents rather than a breach of the plant's operational control systems, they intersect with physical protection concerns — the exact domain AERB's nuclear-security review function and the CPPNM's sabotage-prevention obligations are designed to address, since facility layouts and security-chain details are exactly what physical protection frameworks aim to keep confidential.
- Files leaked: ~19,000 (14.3 GB) specific to KKNPP, out of ~858,000 total files in the wider breach
- KKNPP current operational capacity: 2,000 MW (Units 1 and 2); planned full capacity: 6,000 MW (six units)
- AERB constituted: 15 November 1983, under Section 27 of the Atomic Energy Act, 1962
- NCIIPC notified: 16 January 2014, under Section 70A of the IT Act, 2000 (as amended 2008)
- CERT-In designated under Section 70B of the IT Act, 2000; operational since 2004; 6-hour incident reporting rule in force since 28 June 2022
- CPPNM adopted 1980, in force 1987; 2005 Amendment extended coverage to physical protection of nuclear facilities