Back to Editorials
The HinduJuly 19, 2026

​Wealth of lacunae: On the Kudankulam nuclear plant data leak

The ransomware attack against a contractor involved in the Kudankulam nuclear power project is concerning, even if nothing threatening the plant’s integrity was stolen. In 2019, malware was found on the same facility’s administrative network, but the NPCIL maintained that the operational reactor network was unaffected. The new incident extends the same theme. India’s breach disclosure regime is inconsistent and often plainly opaque. Affected organisations tend to believe admitting a breach will damage public confidence, share prices, contracts, and invite regulatory scrutiny. So, they tend to ease their language in public statements and avoid disclosure until compelled. Many organisations also lack mature incident response capabilities, not uncommonly because they treat cybersecurity as a matter of compliance rather than necessity. So, assessing what data has been affected in the early stages of an attack becomes technically impossible. According to public information, the facility’s core infrastructure is unaffected; instead, a group called ‘World Leaks’ mounted a ransomware attack compromising systems belonging to Reliance Infrastructure, one of the engineering contractors of Units 3 and 4. The data in the incident were hosted by Yotta Data Services, which said it detected suspicious activity on its servers on May 29. According to open-source intelligence platform RansomLook, the data began appearing on World Leaks on June 11. However, the NPCIL issued a formal clarification only on July 15, following widespread media reports. Some 14.3 GB of files have been released, including the layouts of ventilation systems, floor plans of an alleged “control room”, supplier and vendor lists, and insurance paperwork. While the files have not been independently authenticated, the actors and their incentives merit a closer look. The NPCIL has said that the files only pertain to infrastructure beyond the facility’s nuclear island. However, such information can still serve so-called intelligence preparation activities. India is the third-most breached country and has already brooked similar attacks against AIIMS Delhi, airlines, and State government portals. In this milieu, the government has positioned Kudankulam as the centrepiece of India’s nuclear power ambitions. As CERT-In is conducting an investigation and Reliance and Yotta have shared their findings with the government, CERT-In and NPCIL should also clarify the nature and authenticity of the files, whether data were exfiltrated before detection, and whether any credentials or supplier accounts have been exposed. Radical transparency is impossible here but basic cyber-hygiene and proactive communication are non-negotiable. Published - July 17, 2026 12:20 am IST Read Comments Copy link Email Facebook Twitter Telegram LinkedIn WhatsApp Reddit READ LATER SEE ALL Remove Related Topics cybersecurity / Tamil Nadu / Kudankulam Nuclear Power Project / India / government

Key GK Takeaways for CLAT
  • 1NPCIL, the Nuclear Power Corporation of India Limited, is a Central Public Sector Enterprise under the Department of Atomic Energy, which functions under the Prime Minister's direct charge pursuant to the Atomic Energy Act, 1962. This reflects the constitutional placement of atomic energy on the Union List under Entry 6 of List I, a subject reserved exclusively for Parliament. This centralised authority means critical decisions on breach disclosure rest with Union bodies like CERT-In rather than state agencies, even though the affected contractor and site fall within Tamil Nadu.
  • 2Kudankulam is built under a 1988 inter-governmental agreement with Russia, with Rosatom supplying reactor technology under International Atomic Energy Agency safeguards, making the plant a flagship of India-Russia strategic cooperation. A cyberattack on its contractor ecosystem, even if the reactor's operational network remains unaffected, carries diplomatic sensitivity because it exposes the vulnerability of foreign-collaborated critical infrastructure to ransomware actors. India, described in the editorial as the third-most breached country, has faced comparable attacks on AIIMS Delhi and airline systems, underscoring a pattern that shapes its cybersecurity cooperation with partners like Russia and the Quad.
  • 3Cyber incidents affecting critical infrastructure in India fall under the Information Technology Act, 2000, particularly Section 70, which lets the government declare protected systems, alongside rules governing the National Critical Information Infrastructure Protection Centre, set up in 2014 under the National Technical Research Organisation. Unlike the European Union's NIS2 Directive, India's Digital Personal Data Protection Act, 2023 does not mandate strict breach-disclosure timelines for critical infrastructure operators, leaving disclosure largely shaped by CERT-In's 2022 directions, which require reporting incidents within six hours of detection. NPCIL's eighteen-day gap between the May 29 detection and its July 15 clarification raises questions about adherence to these timelines.
  • 4The breach reportedly involved 14.3 GB of data, including ventilation layouts and control-room floor plans, though NPCIL maintains the leaked material pertains only to areas beyond the plant's 'nuclear island,' the isolated zone housing reactor operations. Kudankulam's six planned units are designed to generate a combined 6,800 MW once fully operational, making it India's largest nuclear power complex and a key contributor toward India's target of 100 GW of nuclear capacity by 2047. The eighteen-day gap between detection on May 29 and public clarification on July 15 illustrates the economic risk delayed disclosure poses to investor and public confidence in India's expanding nuclear sector.