Kudankulam Nuclear Power Plant Data Leak Sparks 'Absolute Commotion'
Kudankulam Nuclear Power Plant Data Leak Sparks 'Absolute Commotion'
Relevance: GS Paper III (Cyber Security, Nuclear Security, Critical Infrastructure Protection)
Why in the News?
- A data leak involving over 19,000 sensitive files from the Kudankulam Nuclear Power Plant (KKNPP) has been reported.
- The files, dating from 2016 to mid-2025, were reportedly accessed by the ransomware group World Leaks from a contractor's server.
- Investigations by the Nuclear Power Corporation of India Limited (NPCIL) and the Computer Emergency Response Team (CERT-In) are currently underway.
Source and Nature of the Leak
- The leak originated from a server hosted by third-party provider Yotta, used by Reliance Group, a contractor for KKNPP.
- The leaked data includes engineering blueprints for control, cooling, and ventilation systems, along with vendor and supplier lists.
- NPCIL has stated that the leaked data relates to "conventional balance of plant common service facilities" and not nuclear safety systems.
- Despite this clarification, the incident raises concerns about potential security threats and the mapping of support systems for vulnerabilities.
About Kudankulam Nuclear Power Plant (KKNPP)
- KKNPP is India's largest nuclear power station, located in Tamil Nadu.
- It operates using Russian-designed VVER reactors.
- Reliance Infrastructure secured the contract in 2018 to build infrastructure for KKNPP's Reactors 3 and 4.
- The plant is currently building four more 1,000 MWe VVER units in collaboration with Russia, in addition to its two existing operational units.

Historical Context
- A similar cybersecurity incident occurred in 2019, when North Korean malware infected KKNPP's administrative network — an incident NPCIL had dismissed at the time as not affecting critical systems.
- This latest leak renews concerns about the adequacy of cybersecurity practices around India's critical nuclear infrastructure, particularly regarding third-party contractor and vendor systems.
Significance and Issues for Mains
- Highlights the growing risk to critical infrastructure from vulnerabilities in the contractor/vendor ecosystem, rather than the core facility's own systems.
- Raises the broader question of cybersecurity due diligence requirements for third-party contractors working with sensitive strategic infrastructure.
- Reinforces the need for stronger data segregation between administrative/support systems and core safety-critical nuclear systems.
Underscores the importance of coordinated investigation and response mechanisms, such as those involving NPCIL and CERT-In, for national critical infrastructure protection.