Approximately 19,000 highly sensitive documents related to the Kudankulam Nuclear Power Plant (KKNPP) have been exposed on the dark web following a significant data security incident. According to reporting from OilPrice, the compromised files predominantly concern Units 3 and 4 of the plant, both currently under construction with an expected operational timeline of 2027. The facility represents India's largest nuclear installation and is a critical component of the nation's energy infrastructure.
The breach occurred on a server operated by third-party data center provider Yotta, which identified suspicious activity affecting infrastructure managed for Reliance Infrastructure, a subsidiary of India's Reliance Group. The incident underscores growing vulnerabilities in critical infrastructure digital systems, particularly as major energy projects rely increasingly on distributed cloud and data center solutions. The exposure of construction documents and operational planning materials for an active nuclear project raises significant security and operational concerns.
The breach highlights the intersection of critical infrastructure protection and cybersecurity risks facing India's energy sector. As the nation continues to expand its nuclear capacity to meet growing electricity demand, the incident presents a cautionary example of how third-party vendors and service providers can become weak points in security architecture. Authorities will likely face increased pressure to strengthen oversight mechanisms and mandatory security protocols for facilities handling sensitive nuclear development data.


