The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified.
NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
India's Computer Emergency Response Team (CERT-In) opened an investigation into the exposure of Kudankulam Nuclear Power Plant-related files that were leaked by World Leaks and tied to Reliance Infrastructure.
The Nuclear Power Corporation of India Limited said the exposed files did not affect nuclear safety or security systems at Kudankulam. According to NPCIL, the material related only to conventional balance-of-plant service facilities covered under a public tender.
Reliance Group acknowledged a partial breach involving data on a server hosted by Yotta. It said the Indian government and law enforcement had been informed.
Analysis of World Leaks' dark web post indicated that roughly 19,000 files labeled "KKNP" and tied to the Kudankulam Nuclear Power Plant had been circulating online since this date. The files were described as part of a much larger set of about 858,000 Reliance-linked files.
Yotta said it detected suspicious activity on a server it hosted for Reliance Infrastructure and prevented suspected ransomware execution. The provider later said it could not verify subsequent breach claims tied to the incident.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcetheravenfile.com
Open sourcecyberveille.ch
Open sourcecysecurity.news
Open sourceteiss.co.uk
Open sourceteiss.co.uk
Open sourcemalware.news
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.