As Prime Minister Narendra Modi accelerates India’s nuclear ambitions, a dream rooted in Homi Bhabha’s post-independence vision of atomic self-reliance, a fresh cyber breach has cast an unflattering light on the risks of rapid expansion. For decades, India has pursued nuclear power as both an emblem of technological sovereignty and a strategic necessity, from the early Tarapur reactors in the 1960s to today’s push for massive capacity addition. Modi has intensified this drive, aiming to expand nuclear capacity while opening the sector to greater private participation and strengthening partnerships with countries including Russia, France, and the United States. Yet the irony surfaced dramatically this week: Reliance Infrastructure, contracted since 2018 to construct Kudankulam Nuclear Power Plant’s Units 3 and 4, saw roughly 858,000 internal files exposed on the dark web by the World Leaks ransomware group. What leaders once hailed as a symbol of technological progress now highlights the vulnerabilities accompanying India’s ambitious nuclear journey.
Ransomware actors exposed sensitive files. The World Leaks group posted nearly 19,000 files from a larger set of about 858,000. Reliance Infrastructure confirmed a partial breach on a server hosted by third-party provider Yotta Data Services. Yotta said it had detected suspicious activity on the server on May 29, though the company has not disclosed the full extent of what attackers accessed. Reliance informed authorities, and India’s Computer Emergency Response Team (CERT-In) and the Nuclear Power Corporation of India Ltd. (NPCIL) began examining the incident.
The leak revealed critical operational details. Hackers exposed ventilation and cooling system blueprints for Units 3 and 4, common control room floor layouts, supplier lists, and 2024 inspection records. These documents do not include the core reactor systems supplied by Russia’s Rosatom, but they provide insights into supporting infrastructure and access pathways. Such information could help adversaries understand how essential systems function and where vulnerabilities may exist.
Experts point to one especially concerning element: the files reveal who has access to key systems and how those systems connect. In 2020, Nickolas Roth, senior director at the Nuclear Threat Initiative, warned that the breach represents a serious risk to plant security because information about supporting systems can assist those seeking to plan future cyber or physical attacks.
Non-core leaks still create major dangers. Although attackers did not reach reactor controls, the exposed auxiliary data weakens the plant’s overall security posture. Blueprints and layouts related to cooling, ventilation, and access systems can help adversaries identify potential weak points. Such information becomes particularly valuable in hybrid threats, where cyber intrusions and physical sabotage risks increasingly overlap.
Nuclear facilities rely on defense-in-depth strategies, meaning they protect operations through multiple independent layers of security. When sensitive information reveals how those layers connect, it can undermine confidence, trigger costly security reviews, and increase pressure on operators to strengthen safeguards.
This event reflects a repeating pattern. Kudankulam suffered a 2019 malware infection that authorities linked to a North Korean hacking group, though officials said operational systems were unaffected at the time. That attack compromised parts of the plant’s administrative network. World Leaks has also previously targeted major companies, including Tata, in extortion attempts. India’s rapid infrastructure expansion has created growing cybersecurity challenges, particularly as critical projects increasingly depend on private contractors and external service providers.
The latest breach raises broader questions about whether cybersecurity measures are keeping pace with India’s nuclear ambitions. Expanding infrastructure requires not only engineering expertise and investment but also stronger oversight of every organization connected to critical facilities.
India is expanding nuclear privatization faster than it is strengthening contractor cybersecurity. Modi’s administration wants private capital and faster execution to meet ambitious energy targets. Reliance’s role at Kudankulam reflects this approach. However, the breach highlights possible gaps in contractor vetting, monitoring, and cybersecurity enforcement among companies that manage sensitive data through third-party providers.
Russia and potential future partners from the United States or elsewhere should closely monitor such developments. Nuclear cooperation depends on confidence in supply chains and security practices. Repeated cybersecurity failures can delay projects, increase costs, and create concerns among international partners. This is not an unavoidable consequence of rapid development but a governance challenge that requires stronger audits, uniform security standards, and greater investment in domestic cybersecurity capabilities.
The contrast now carries heavier consequences. India’s nuclear program has long represented technological ambition and strategic independence. The Kudankulam breach demonstrates that modern nuclear security depends not only on protecting reactors but also on securing the digital networks, contractors, and supporting systems surrounding them.
Modi’s administration can still turn this setback into an opportunity by establishing stronger cybersecurity standards across the nuclear sector. Until India matches its ambitious nuclear vision with equally robust safeguards, the dream of atomic self-reliance will remain exposed to preventable digital risks.

