← Resources · July 16, 2026
Internal Security GS3 4 min read

Kudankulam Nuclear Power Plant data leak: What happened and what we know | Explained

What happened
01

A ransomware group calling itself World Leaks posted a large cache of files related to the Kudankulam Nuclear Power Plant on the dark web, including purported facility blueprints and supplier details

02

Over 19,000 sensitive files were released, reportedly part of a larger cache of nearly 8.58 lakh documents allegedly stolen from a contractor engaged for the plant's expansion work, rather than from the plant operator's own systems directly

03

The leaked documents reportedly relate to ventilation and cooling systems for under-construction reactor units, not the core reactor control systems, which are supplied and secured separately

04

The Nuclear Power Corporation of India Limited (NPCIL) stated that the breach did not reveal sensitive information related to nuclear security

05

Cybersecurity agencies and nuclear regulatory authorities have initiated an investigation into the scope of the breach

Static topic 1 of 3 · Internal Security

Institutional Framework for Nuclear Security in India

India's nuclear establishment operates under a layered structure: the Department of Atomic Energy (DAE) oversees policy, the Nuclear Power Corporation of India Limited (NPCIL) operates commercial nuclear power plants, and the Atomic Energy Regulatory Board (AERB) performs regulatory and safety oversight, all functioning under the Atomic Energy Act, 1962.

Key Details

  • The Atomic Energy Act, 1962 provides the basic legal framework for the development, control, and use of atomic energy in India
  • AERB was constituted on 15 November 1983 under Section 27 of the Atomic Energy Act, 1962, to ensure that the use of nuclear energy and ionising radiation does not cause undue risk to health, safety, or the environment
  • Reactor control systems at Indian nuclear plants are typically air-gapped (physically isolated from external/internet-connected networks) as a core security design principle, distinct from administrative or contractor IT networks
  • Kudankulam's under-construction Units 3 and 4 use VVER-1000 reactor technology supplied under India-Russia cooperation (Rosatom), while ancillary systems like cooling and ventilation may involve other domestic and foreign contractors
Connection to this news

NPCIL's clarification that the breach did not compromise "nuclear security" rests on this air-gap distinction — the leaked files reportedly pertain to a contractor's systems and non-reactor infrastructure (ventilation/cooling), not the isolated reactor control network.

Static topic 2 of 3 · Internal Security

CERT-In and India's Cyber Incident Response Framework

The Indian Computer Emergency Response Team (CERT-In) is India's national nodal agency for cybersecurity incident response, established under Section 70B of the Information Technology Act, 2000.

Key Details

  • CERT-In was established on 19 January 2004 under the Ministry of Electronics and Information Technology (MeitY), and is designated as the national agency for cyber incident response under Section 70B(4) of the IT Act, 2000
  • Functions include collection and analysis of cyber incident data, forecasting and alerts, emergency response coordination, and issuing guidelines/advisories on information security
  • Under Section 70B(6), CERT-In can call for information and issue directions to service providers, intermediaries, data centres, and body corporates for cybersecurity purposes
  • The 2022 CERT-In Directions mandate reporting of cyber incidents (including data breaches at critical infrastructure) within six hours of noticing them
Connection to this news

A breach involving a nuclear facility's associated data falls squarely within CERT-In's incident response and critical infrastructure protection mandate, alongside sector-specific oversight by AERB/NPCIL and, for critical infrastructure specifically, the National Critical Information Infrastructure Protection Centre (NCIIPC).

Static topic 3 of 3 · Internal Security

Precedent — The 2019 Kudankulam Malware Incident

This is not the first cybersecurity incident linked to Kudankulam. In 2019, malware known as DTrack — later attributed by cybersecurity researchers to North Korea's Lazarus Group — was detected on an administrative network at the plant.

Key Details

  • NPCIL initially denied reports of any cyberattack but subsequently confirmed, in a follow-up statement, that an administrative computer connected to the internet had been infected
  • The affected system was stated to be isolated from the reactor's safety and control systems, which operate on a separate air-gapped network
  • The incident highlighted the distinction between "administrative/IT networks" (connected to the internet, more vulnerable) and "operational technology (OT)/control networks" (air-gapped, hardened) at critical infrastructure facilities
  • Globally, the most cited precedent for a cyberattack on nuclear infrastructure is Stuxnet (discovered 2010), which targeted Iran's uranium enrichment centrifuges at Natanz via a worm that manipulated industrial control systems (SCADA)
Connection to this news

The 2026 breach follows a similar pattern to 2019 — the compromise of adjacent administrative/contractor systems rather than reactor control systems — reinforcing why India's layered air-gap approach to critical infrastructure cybersecurity remains central to the official risk assessment, even as experts caution that any breach touching nuclear facility data carries elevated risk.

Key facts & data
  • Reported leak size: over 19,000 files directly linked to Kudankulam, part of a larger alleged cache of nearly 8.58 lakh documents from a contractor
  • Kudankulam is India's largest nuclear power plant by planned capacity: 6 VVER-1000 reactors, 1,000 MW each (6,000 MW total capacity when fully operational); Units 1 and 2 are operational (grid-synchronised in 2013 and 2016 respectively), Units 3-6 under construction
  • AERB constituted: 15 November 1983, under Section 27 of the Atomic Energy Act, 1962
  • CERT-In: established 19 January 2004; legal basis Section 70B, Information Technology Act, 2000; mandates reporting of cyber incidents within 6 hours (2022 Directions)
  • Precedent: 2019 DTrack malware incident at Kudankulam, attributed to the Lazarus Group, affected an administrative (non-control) network
Read it? Now lock it in. The quiz for this day’s brief covers this story.
Take the quiz