The operator of India’s Kudankulam Nuclear Power Plant has officially denied that any nuclear safety or security information was compromised following a recent data breach, RT reported. The incident involved the leak of files linked to the plant but did not include critical nuclear safety details, according to the Nuclear Power Corporation of India Limited (NPCIL), which manages the facility.
Reuters initially revealed that the ransomware group World Leaks had posted a substantial number of files related to the plant on the dark web. These files reportedly contained blueprints of certain plant components and supplier information, with nearly 19,000 documents totaling 14.3 gigabytes available online.
Located in Tamil Nadu, the Kudankulam plant is a collaborative project between NPCIL and Russia’s state-owned Rosatom. The site is planned to house six pressurized water reactors, with two operational units each generating 1,000 megawatts of power.
NPCIL clarified the leaked information pertained only to common service facilities, describing them as "conventional" systems similar to those in thermal power plants and other industrial operations, and emphasized that no nuclear safety or security systems were affected.
The compromised data originated from Reliance Group, an Indian company contracted in 2018 to construct all systems excluding the nuclear reactors themselves. Reliance confirmed a "partial breach" on a server hosted by Indian data center provider Yotta and stated the government has been notified. Yotta reported it had prevented an attempted ransomware attack on May 29.
Nickolas Roth, senior director at the Nuclear Threat Initiative, expressed concerns that the breach could pose a "serious" risk to plant safety, though Reuters noted it could not independently verify the authenticity of the exposed documents.
World Leaks is known for publicly releasing stolen corporate data when ransom demands are unmet. Recently, the group leaked Tata Group files containing sensitive designs for Apple and Tesla after a $1.5 million ransom demand was ignored.
Cybersecurity issues at Kudankulam are not new. In 2019, malware linked to a North Korean hacking group was detected on the plant’s administrative network, highlighting ongoing vulnerabilities.
Why this matters
The Kudankulam plant is a critical asset in India’s energy infrastructure, making the security of its operational data vital. Although the breach reportedly did not expose nuclear safety information, the incident underscores the persistent cyber threats facing nuclear facilities worldwide. Ensuring robust cybersecurity measures is essential to prevent any potential risks to public safety and national security.
As nuclear energy becomes increasingly important for clean power generation, maintaining trust in these facilities’ safety protocols is paramount.