The Squirrels
Monday, 27 July 2026
‹ The Squirrels
Economy

Blueprints of India's Largest Nuclear Plant Are on the Dark Web. They Were Stolen From a Contractor's Server.

By The Squirrels·

ZVZVZThe Files

Nearly 19,000 files tied to India's largest nuclear power plant — Kudankulam Nuclear Power Plant in Tamil Nadu — have surfaced on the dark web. The files include:

  • Purported blueprints of the plant's ventilation systems

  • A control room floor layout

  • Vendor proposals from contractors

  • Records of a joint inspection between the plant's operator (Nuclear Power Corporation of India, NPCIL) and Reliance, with photographs of equipment

The files are part of a larger cache of 858,000 documents that ransomware group World Leaks claims it stole from Anil Ambani's Reliance Group.

The nuclear plant data was not stolen from the plant itself. It was stolen from a contractor that stored sensitive nuclear facility documents on a third-party server. That distinction — between the plant's own cybersecurity and the cybersecurity of everyone who has ever worked on it — is the entire story.


How the Data Got There

The chain of custody:

Step 1: In 2018, Reliance Infrastructure won a contract to build support infrastructure for Kudankulam's Unit 3 and Unit 4 — two of the plant's newer reactor units.

Step 2: As part of that contract, Reliance Infrastructure generated and received documents relating to the plant's physical systems — ventilation designs, control room configurations, equipment specifications, inspection records.

Step 3: These documents were stored on a server hosted by Yotta Data Services Private Limited — a third-party cloud and data centre provider.

Step 4: On May 29, Yotta detected suspicious activity on the server hosting Reliance's data.

Step 5: In late June, Reliance flagged the data leak claims to Yotta after the ransomware group's demands became public.

Step 6: World Leaks published the data — including the 19,000 nuclear-related files — on the dark web.

Reliance has confirmed a "partial breach" of its data on the Yotta-hosted server.

maxresdefault

Why This Matters — In the Words of a Nuclear Security Expert

Nickolas Roth of the Nuclear Threat Initiative — a Washington-based nuclear security organisation — told Reuters:

"The exposure of such data could show an adversary not just who has access to the project but which systems that access reaches."

The statement identifies the specific threat: the leaked files do not give an adversary the ability to operate the reactor. But they reveal the physical layout (ventilation, control room), the supply chain (which vendors, which equipment, which specifications), and the access architecture (who inspected what, when, and with what credentials).

For a state-level adversary or a sophisticated non-state actor, this information is not a weapon. It is a targeting package — the intelligence foundation for planning a physical or cyber attack against specific systems within the facility.


The Supply Chain Vulnerability Nobody Addresses

Kudankulam is operated by NPCIL — a government entity with nuclear-grade security protocols. The plant itself was not breached.

But the contractor that built part of the plant stored sensitive documents on a third-party server — and that server was breached by a ransomware group that had already stolen data from Tata Group (including confidential Apple and Tesla component designs, for which World Leaks demanded $1.5 million in ransom before publishing the data after Tata "ignored" the demand).

The structural problem: India's nuclear security perimeter does not extend to the contractors, subcontractors, and cloud providers who handle nuclear facility data. NPCIL can secure its own systems. It cannot secure Reliance Infrastructure's data management practices. And it apparently cannot control where Reliance stores documents containing nuclear plant blueprints.

This is not hypothetical. Kudankulam has been targeted before. In October 2019, the plant's administrative network was compromised by DTrack malware — linked to North Korea's Lazarus Group. NPCIL initially denied the breach, then confirmed it, stating that the malware had affected the administrative network but not the plant's operational technology (OT) systems.

The 2019 attack came through the plant's own network. The 2026 leak came through a contractor's cloud server. The attack surface is expanding — not because the plant is less secure, but because the ecosystem around it is not secure at all.

Why Do We Still Use Terminals? The Journey of the Black Screen That Shaped  Computing | by Pedro_aoc | Medium

What Is Being Done

NPCIL has been communicating with Reliance about the breach.

CERT-In — India's primary cybersecurity agency — is investigating the incident.

Reliance has acknowledged the "partial breach" but has not disclosed what specific nuclear-related documents were compromised or what remediation steps have been taken.

Yotta says it detected suspicious activity on May 29 and that Reliance flagged the leak claims in late June — a gap of approximately four weeks between detection and escalation.

No public statement has been made by the Atomic Energy Regulatory Board (AERB), the body responsible for nuclear safety and security in India.


The Broader Pattern: World Leaks and Indian Corporate Data

The Kudankulam files are not World Leaks' first Indian target:

Target

Data Compromised

Ransom Demanded

Outcome

Tata Group

Apple and Tesla confidential component designs

$1.5 million

Tata "ignored" — data published

Reliance Group

858,000 files including 19,000 nuclear-related

Unknown

Data published on dark web

Two of India's largest conglomerates — both with critical infrastructure contracts — have been breached by the same ransomware group within months. The pattern suggests either a targeted campaign against Indian corporate infrastructure or a systemic vulnerability in Indian enterprise cybersecurity that a single group can exploit repeatedly.

images1579699134

Three Questions the Investigation Must Answer

1. Why were nuclear plant blueprints stored on a third-party server? NPCIL's nuclear security protocols presumably restrict where such documents can be stored. Did Reliance Infrastructure's contract include data handling requirements? Were those requirements enforced? Did NPCIL know where its facility's blueprints were being stored?

2. Why did it take four weeks from detection to escalation? Yotta detected suspicious activity on May 29. Reliance flagged the leak claims in late June. For nuclear security data, a four-week gap between breach detection and nuclear operator notification is an eternity.

3. What is the actual sensitivity of the leaked files? "Ventilation blueprints" and "control room floor layout" sound alarming. But the operational significance depends on classification level, specificity, and whether the documents relate to current or outdated configurations. NPCIL has not publicly assessed the sensitivity of the leaked material.


The Bottom Line

India's largest nuclear power plant did not get hacked. A contractor that built part of it stored sensitive documents — including ventilation blueprints and control room layouts — on a third-party cloud server. That server was breached. The documents are now on the dark web.

The nuclear plant's own systems were not compromised. But the information that an adversary would need to plan an attack on those systems — the physical layout, the supply chain, the access architecture — is now publicly available to anyone with a dark web browser.

India's nuclear security perimeter protects the plant. It does not protect the ecosystem of contractors, cloud providers, and data management practices that surround it. And until it does, the most secure facility in the country is only as secure as the least secure server that holds its blueprints.