Daily
250 words
6/10
Rating

17 July 2026

Kudankulam nuclear power plant data breach

The incident serves as a significant case study for critical infrastructure protection, cybersecurity policy, and the efficacy of data breach disclosure mechanisms in India.

2 min read 2 questions 2 prelims

Notes

  • A data breach involving Reliance Infrastructure Ltd. resulted in the exposure of approximately 14.3 GB of files related to the Kudankulam Nuclear Power Project (KKNPP) Units 3 and 4.
  • The leaked data originated from a server hosted by Yotta Data Services, a third-party provider for Reliance Infrastructure.
  • NPCIL stated that the compromised files pertain to the Engineering, Procurement and Construction (EPC) contract for the 'Balance of Plant' (BoP) package, which includes conventional infrastructure like ventilation and floor plans, not nuclear safety or core reactor systems.
  • The ransomware group 'World Leaks' claimed responsibility for the breach, alleging they accessed a total of 1.2 TB of data, a portion of which related to KKNPP.
  • The incident highlights challenges in India's breach disclosure regime, with concerns raised regarding the delay between detection (May 29) and public clarification (July 15).
  • Kudankulam is a joint project with Russia (Rosatom), currently operating two 1,000 Mwe VVER reactors with four additional units under construction.
  • Previous cybersecurity incidents at the facility include malware detection on the administrative network in 2019.

Questions

  1. The recent data breach involving a contractor at a critical nuclear facility highlights the vulnerabilities of third-party service providers in the supply chain. Discuss the challenges in ensuring cybersecurity for critical infrastructure in India. 150 words
    Attempt this — 150 words in 8 min
    0 / 150 words 8:00
  2. Effective incident response and transparent disclosure mechanisms are essential for maintaining public trust in critical infrastructure projects. In the context of recent cybersecurity incidents, evaluate the need for a robust national framework for breach disclosure and cyber-hygiene in India's strategic sectors. 250 words
    Attempt this — 250 words in 11 min
    0 / 250 words 11:00

Prelims

  1. Which of the following best describes the 'Balance of Plant' (BoP) in the context of a nuclear power project?

  2. What is the primary role of CERT-In in the context of cybersecurity in India?