Kudankulam nuclear plant data leak sparks ‘absolute commotion’
Reported ransomware-linked access to contractor-hosted files at Kudankulam Nuclear Power Plant raises cyber-security questions for critical infrastructure, while Nuclear Power Corporation of India Limited (NPCIL) says no nuclear safety or security systems were compromised.

- NPCIL said the accessed material from Kudankulam Nuclear Power Plant was public-domain information related to conventional support systems and not nuclear safety or security systems.
- CERT-In is investigating the reported cyber breach at Kudankulam Nuclear Power Plant along with NPCIL.
- The contractor acknowledged a partial breach and said the government had been informed.
A reported cyber breach at Kudankulam Nuclear Power Plant has raised concern because more than 19,000 files were allegedly accessed from a contractor’s server by a ransomware group. The incident matters for UPSC because it links critical infrastructure, cyber security, and vendor risk in one case.
Nuclear Power Corporation of India Limited (NPCIL) said the material involved was public-domain information related to conventional support systems and not nuclear safety or security systems. NPCIL and Computer Emergency Response Team-India (CERT-In) are investigating the breach.
What happened
UPSC may use the Kudankulam Nuclear Power Plant incident to test cyber security of critical infrastructure, third-party/vendor risk, and the distinction between operational support systems and nuclear safety systems. A Mains answer can discuss why critical facilities need layered cyber defences, stronger contractor oversight, incident reporting, and coordination between Nuclear Power Corporation of India Limited and Computer Emergency Response Team-India.
Related dispatches


