News briefing
Reliance confirms partial breach as Kudankulam project files leak; NPCIL says no safety data

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
Files tied to the Kudankulam nuclear project surfaced on the World Leaks extortion site after a breach of a Reliance Infrastructure server hosted by Yotta. NPCIL says they cover only conventional plant facilities, not nuclear safety or security.
01 / What happened
Around 19,000 files, about 14.3GB, linked to the Kudankulam Nuclear Power Project in Tamil Nadu were available online from 11 June 2026, according to Reuters reporting cited by Al Jazeera, Moneylife and MediaNama. They were posted by the World Leaks extortion group as part of a far larger cache, roughly 858,000 files, that the group claims it took from Reliance group companies.
Reliance Group confirmed a "partial breach" of its data on a server hosted by the Indian data-centre provider Yotta and said the incident had been reported to the government, Reuters reported on 15 July. It did not say what data was accessed. Yotta told Reuters it detected suspicious activity on a Reliance Infrastructure server on 29 May 2026 and stopped it, preventing what it believed was an attempt to run ransomware. Yotta said Reliance Infrastructure told it only at the end of June that outside actors were claiming to hold the data.
On 15 July the Nuclear Power Corporation of India Ltd (NPCIL) said in a press release that the contract for the Common Services – Balance of Plant (BoP) package for Kudankulam Units 3 and 4 was awarded to Reliance Infrastructure in 2018 through a public tender. The Record reported on 20 July that Science and Technology Minister Jitendra Singh had dismissed reports that sensitive data was compromised.
02 / Why it matters
Kudankulam is India's largest nuclear power project. Even if the leaked drawings are conventional, the incident shows how sensitive project data can escape through a contractor and its hosting provider rather than through the plant operator itself.
In critical infrastructure, the weakest link is often a contractor's server, not the plant.
It is not the plant's first cyber incident: The Record recalled that in 2019 malware linked to North Korea's Lazarus Group was found on an administrative network there, and CERT-In concluded plant operations were not affected. The same World Leaks group also posted files it claimed came from Tata Electronics in June.
03 / Who is exposed
Reporting on the Kudankulam material and the wider Reliance cache describes:
- engineering drawings, technical inspection reports and meeting records for the BoP work, dated between 2016 and mid-2025 (The Record)
- supplier information, tender documents and insurance papers
- finance and payroll data, tax returns, bank statements and job applicants' resumes (MediaNama)
That means Reliance Infrastructure staff, job applicants and suppliers may face phishing or invoice fraud, although the company has not said whose personal data was involved.
04 / Confirmed vs. claimed
Confirmed: a partial breach of Reliance data on a Yotta-hosted server, reported to the government (Reliance Group, via Reuters); suspicious activity detected and stopped on 29 May (Yotta, via Reuters); Reliance Infrastructure holds the 2018 BoP contract (NPCIL). NPCIL says the information claimed to be public relates only to conventional BoP common-service facilities and not to any nuclear safety or nuclear security systems or information.
Claimed / unconfirmed: World Leaks' figures for the total volume taken. Reuters reported, citing a source, that CERT-In is investigating; CERT-In has not commented publicly. Moneylife noted that the reactor systems are supplied by Russia's Rosatom and that the leaked documents do not appear to involve them.
05 / What to do now
- Reliance Infrastructure employees, former staff, job applicants and suppliers should expect targeted phishing that quotes real payroll, tender or HR details. Verify any request to change bank details by calling a number you already hold.
- If you lose money, call the national cyber-fraud helpline 1930 immediately and file a complaint at cybercrime.gov.in; the faster a fraud is reported, the better the chance of stopping the money moving on.
- Do not seek out, download or share the leaked files. Leak archives are a common way to spread malware.
- Operators and contractors: CERT-In's 2022 directions require data breaches, data leaks and attacks on critical infrastructure to be reported within six hours, and ICT logs to be kept for a rolling 180 days in India. Write the same speed into contracts, so hosting providers and contractors tell each other, and the asset owner, promptly.
Source log / 2026-0720-KK
- NPCIL — Press release: statement on drawings/data leak through breach at Reliance Infra with respect to KKNPP (15 July 2026) Primary
- The Record — India says allegedly leaked nuclear plant files pose no safety risk (20 July 2026) Secondary
- Al Jazeera — Data breach reportedly targets India's Kudankulam nuclear power plant (16 July 2026) Secondary
- Moneylife — Kudankulam-linked documents surface on dark web after ransomware attack on Reliance Infrastructure (17 July 2026) Secondary
- MediaNama — Reliance and Kudankulam Nuclear Power Plant data breach (16 July 2026) Secondary
- CERT-In — Directions under section 70B(6) of the IT Act, 2000 (28 April 2022) Primary