An extortion group has posted a cache of files it claims relate to India's largest nuclear power plant — and the important qualifier belongs at the top: the breach was at a contractor, not the reactor. Around 15 to 16 July 2026, the group known as World Leaks published on a dark-web leak site what it says is roughly 19,000 files, totalling about 14.3 gigabytes, labelling the material as data belonging to Reliance Group, a contractor at the Kudankulam Nuclear Power Plant in Tamil Nadu. Both the contractor and the plant operator have responded, and their statements draw the line the coverage needs to hold.
What was actually breached
Reliance Group, in its own statement, described a partial breach limited to its data held on a server hosted by the third-party Indian data-centre provider Yotta, and said the government had been informed. The Nuclear Power Corporation of India Limited (NPCIL), which operates Kudankulam, issued a narrower statement of its own: the incident does not relate to any nuclear safety or nuclear security-related systems, and pertained to common service facilities rather than reactor operations.
Two things follow from that, and both matter for reading this accurately. First, this is a breach of a contractor's records stored with that contractor's hosting provider. From the nuclear operator's perspective, that makes it a fourth-party exposure rather than a direct compromise of plant systems. Second, the specifics remain unconfirmed: neither NPCIL nor India's regulators have verified which documents were taken, or whether the roughly 19,000 files World Leaks is advertising are authentic. The file count, the volume and the contents are, at this stage, the extortion group's claims.
By World Leaks' account, the material spans 2016 to 2025 and includes construction blueprints of parts of the facilities, supplier directories, meeting minutes and equipment-review records. This advisory does not link to, describe how to reach, or detail the contents of that cache. India's Computer Emergency Response Team, CERT-In, is investigating, and the breach was first identified in June 2026 by a cybersecurity researcher.
Why a contractor breach is not as reassuring as it sounds
NPCIL's statement is credible on its face, and consistent with how India's nuclear plants are built: control systems are designed to be standalone and isolated from external networks. That was the same reassurance issued in 2019, when malware linked to a North Korea-aligned group reached Kudankulam's administrative network while the control systems, being air-gapped, were unaffected. On the question that matters most — could this breach affect reactor safety — the operator's answer is the technically sound one.
But design, engineering and supplier data does not stay inside the reactor perimeter, and that is the part that matters most. It flows outward to the firms that design, build and service the plant, and Reliance Infrastructure won a 2018 contract to build infrastructure for two of Kudankulam's units. Blueprints, layout plans, procurement records and vendor lists retain intelligence value for future attackers and other malicious actors regardless of which server they were stored on — they map how a facility is built, who supplies it, and where its dependencies lie. That is why an expert view sits alongside the operator's reassurance: a senior director at the Nuclear Threat Initiative told Reuters the breach could pose a serious risk to the plant's safety. Both statements can be true at once. The control systems can be untouched, and the leaked design data can still be a genuine problem.
The fourth-party lesson
The structural story here is where the data lived. Reliance is a contractor to NPCIL; Yotta is a data-centre provider to Reliance. The exposed information was therefore two steps removed from the asset owner — a fourth party — and yet it concerns one of the country's most sensitive facilities. This reflects the broader direction of modern supply-chain security frameworks, which increasingly expect organisations to manage risks beyond their immediate contractors: an operator cannot treat a contractor's data-centre breach as somebody else's problem when the data describes its own critical infrastructure. Regimes such as the EU's NIS2 and grid-security standards elsewhere are pushing asset owners to take on more responsibility for protecting design and configuration information and for overseeing the vendors and sub-vendors that hold it, rather than leaving that to chance.
Key Takeaways
Extortion group World Leaks posted files (claimed ~19,000, ~14.3 GB) it attributes to Kudankulam contractor Reliance Group, published around 15–16 July 2026.
Reliance confirmed a partial breach limited to a server hosted by data-centre provider Yotta; NPCIL said no nuclear safety or security systems were affected.
The file count, contents and authenticity are World Leaks' unverified claims; CERT-In is investigating and the breach was first identified in June 2026.
Control systems at Indian nuclear plants are designed to be standalone — the same reason the 2019 DTrack incident did not reach reactor operations — but leaked design and supplier data retains intelligence value.
The core issue is fourth-party risk: sensitive infrastructure data held by a contractor's data-centre provider, two steps removed from the asset owner.