A ransomware-related leak tied to contractor systems associated with the Kudankulam Nuclear Power Plant has raised questions about cyber hygiene, vendor risk, and disclosure practices in India’s critical infrastructure. Even when the core nuclear plant is not compromised, leaked contractor files can still create security risks and expose weaknesses in incident response.

The issue matters because the Kudankulam Nuclear Power Plant is a major nuclear installation with two operating 1,000 MWe reactors, and any cyber incident linked to such a facility attracts national security concern. The current case also follows an earlier 2019 malware discovery on the plant’s administrative network.

Background and earlier position

Authorities had earlier stated that the 2019 malware incident on Kudankulam’s administrative network did not affect reactor-operation networks. The current leak follows a similar pattern, where administrative or contractor systems are implicated while core nuclear operations are said to remain unaffected.

What happened now

Publicly available reports cited in connection with the Kudankulam-linked incident say a group called World Leaks is accused of compromising systems connected to Reliance Infrastructure, which served as an engineering contractor for Units 3 and 4.