Verify any claim · lenz.io
Claim analyzed
Tech“Files relating to the Kudankulam Nuclear Power Plant, described as India’s largest nuclear power plant, were exposed in a data breach.”
Submitted by Bright Heron 13c5
The conclusion
Open in workbench →Available reporting strongly supports that Kudankulam-related files were exposed online in a breach, and the plant is widely described as India's largest nuclear power plant. Multiple major outlets align with official acknowledgments that non-core documents were involved. The main caveat is that not every leaked file's authenticity or sensitivity was independently verified.
Caveats
- The reporting does not show that reactor control, safety, or core nuclear systems were compromised.
- The breach appears tied to contractor or balance-of-plant files, so broader claims about a full plant-system hack would overstate the evidence.
- Some leaked files were reported before full independent authentication, so document sensitivity and provenance should not be assumed beyond what officials and major outlets confirmed.
Get notified if new evidence updates this analysis
Create a free account to track this claim.
Sources
Sources used in the analysis
BENGALURU, July 15 (Reuters) - Ransomware group World Leaks has posted on the dark web a huge cache of files related to India's largest nuclear plant, including purported blueprints of parts of its facilities and supplier details — information it labelled as coming from Reliance Group. Reuters reviewed the documents, which were dated from 2016 to mid-2025, but could not verify their authenticity. The 19,000 files appeared to be the most sensitive of a total 858,000 Reliance files on the World Leaks website.
In response to reports indicating that a ransomware group had accessed highly sensitive information from a contractor's server related to the Kudankulam Nuclear Project (KNPP), Nuclear Power Corporation of India Ltd. issued a statement on Wednesday, July 15, 2026, dismissing the notion of a "sensitive data breach." Earlier in the day, multiple sources from NPCIL confirmed the data leak but emphasized that the files involved were not related to the safety of the KKNPP plant or nuclear safety.
A data breach has reportedly revealed files linked to India's largest nuclear power plant, according to the Reuters news agency. Ransomware group World Leaks posted on the dark web a huge cache of files related to Kudankulam Nuclear Power Plant, including purported blueprints of parts of its facilities and supplier details – information it labelled as coming from Reliance Group, said Reuters. Nearly 19,000 files totalling 14.3 gigabytes that appear for the search term 'KKNP' – an acronym for the nuclear plant – in the data have been online since June 11, according to independent cybersecurity researcher Rakesh Krishnan, who first alerted Reuters to the leak.
Nuclear Power Corporation of India Ltd., which is leading construction and operation of reactors at the Kudankulam nuclear plant, as well as Anil Ambani's Reliance Group, whose arm Reliance Infra was involved with building infrastructure at two units, Wednesday said its core systems were untouched by a "cyber security incident", after ransomware group World Leaks posted a huge cache of files related to the plant on the dark web and claimed data breach. NPCIL reiterated that "the information claimed to be available in the public domain pertains only to conventional balance of plant common service facilities and does not relate to any nuclear safety or nuclear security-related systems or information".
The Nuclear Power Corporation of India Limited (NPCIL) on Wednesday denied reports of a "sensitive data breach" at the Kudankulam Nuclear Power Project, asserting that no sensitive nuclear information or critical systems had been compromised after a ransomware group claimed to have leaked thousands of project-related files on the dark web. The clarification came after Reuters reported that the ransomware group World Leaks had published more than 19,000 files linked to the Tamil Nadu-based nuclear plant, including engineering blueprints, vendor lists, inspection records and operational documents allegedly sourced from a server belonging to project contractor Reliance Infrastructure. NPCIL said the information in question related only to the Balance of Plant (BoP) package, common service facilities of a conventional nature that are not part of the plant's nuclear safety or nuclear security systems.
The article states that data related to the Kudankulam nuclear power plant was leaked online by the hacking group World Leaks, and that among 858,000 Reliance files, 19,000 secret files were identified as belonging to Kudankulam. It adds that Reliance said the breach occurred at the third-party Yotta data centre.
On Tuesday, July 15, 2026, news emerged regarding a significant data breach involving the Kudankulam Nuclear Power Plant, where several gigabytes of sensitive information were reportedly compromised and leaked following a ransomware attack. The leaked data has surfaced on World Leaks, a dark web platform operated by cybercriminals who target susceptible organizations with ransomware, threatening to disclose the information unless a ransom is paid.
According to a report by Reuters, a ransomware group called World Leaks has claimed to have leaked thousands of files linked to India's largest nuclear power plant, including alleged blueprints, supplier details, and project documents. Independent cybersecurity researcher Rakesh Menon said the breach includes nearly 19,000 files totaling 14.3 gigabytes that appear for the search term KKNPP, an acronym for the nuclear power plant; the 19,000 files appear to be the most sensitive of a total 858,000 Reliance Infra files on the World Leaks website. NPCIL stated that the material in the public domain relates only to conventional balance of plant common service facilities and does not involve any nuclear safety or nuclear security systems.
The article says thousands of confidential documents related to the infrastructure and suppliers of Tamil Nadu’s Kudankulam nuclear plant were leaked on the dark web, and that 19,000 files were identified from a larger set of 858,000 Reliance files. It reports that the hackers claimed the data came from Anil Ambani’s Reliance Group, a contractor at the plant.
The video report states that files related to the Kudankulam Nuclear Power Plant (KNPP) in Tamil Nadu have been exposed in a significant data breach. It explains that thousands of documents were uploaded, with the claim that these documents were stolen from servers of Anil Ambani’s Reliance Group and include important information related to the Kudankulam nuclear project. The report further notes that about 8.58 lakh (858,000) files of the group were uploaded, of which approximately 19,000 files are said to be linked specifically to the Kudankulam nuclear plant, including meeting records, insurance documents, technical proposals and other project-related files.
NDTV reported that World Leaks had posted files linked to the Kudankulam Nuclear Power Plant on the dark web, including purported blueprints of parts of the plant, supplier details, inspection records and equipment reviews. The report also said a senior atomic scientist described the incident as unrelated to nuclear security.
The article says 19,000 important files, including control-room drawings and ventilation structure documents, were reported as leaked on the dark web, and that the Central government’s CERT-In agency was conducting an intensive investigation. It also says the files were allegedly stolen from Reliance’s server used for construction work.
Experts from Group-IB, who discovered and analysed an archive containing dtrack, a remote-administration tool attributed to North Korean group Lazarus, said that analysis revealed that the logs contained data from a compromised machine running Windows that belonged to an employee of the Nuclear Power Corporation of India Limited (NPCIL). The report says the archive's main file with the compromised data is dated January 30, 2019, more than six months before they were detected.
The post describes a "data breach at Kundankulam plant" and says that "the leak allegedly includes blueprints and supplier details." It refers to a segment where WION journalists provide more details, indicating that the exposed materials are project-related files tied to the Kudankulam nuclear facility and its contractors. The wording suggests that confidential technical and vendor information connected to the plant has been published online following the breach.
The article reports that the World Leaks hacker group published about 19,000 confidential files tied to Kudankulam on the website “World Leaks,” and that the leaked set was part of 858,000 Reliance files. It says NPCIL issued a clarification about the alleged data leak.
This WION Dispatch post states: "India probes nuclear plant 'data breach' The leak allegedly includes blueprints and supplier details." The accompanying description notes that the incident involves data linked to the Kudankulam Nuclear Power Plant and references alleged blueprints and supplier information that have reportedly been exposed as part of the breach, prompting an official probe.
NPCIL confirmed that a malware had indeed infected its system at the Kudankulam Nuclear Power Plant (KKNPP), a day after KKNPP officials had categorically asserted that the systems at the plant could not be accessed by anyone outside the network as they were all isolated. 'Investigation also confirms that the plant systems are not affected,' he asserted. The cyberintrusion came to light after a data dump pointed to a 'dtrack' malware, which can be used as a remote administrator tool, having infected systems at the KKNPP.
The article says World Leaks posted documents related to Kudankulam on the dark web and that the files included infrastructure details and supplier information. It also reports a claim that this was India’s largest nuclear power plant.
The document discusses a prior cyber incident at the Kudankulam Nuclear Power Plant involving malware later identified as "Dtrack". It notes that a threat actor breached master domain controllers at the Kudankulam plant and at ISRO with this malware, and that NPCIL was alerted on September 4. Initially, KNPP officials denied having suffered any malware infection, but within 24 hours NPCIL admitted to the security breach, stating: "Identification of malware in NPCIL system is correct." The paper reports that the attack was attributed to the North Korean threat actor Lazarus and that a large amount of data was stolen during the breach, with VirusTotal classifying the malware as part of the DTrack family.
The article says nearly 19,000 files related to Kudankulam were posted by the World Leaks group and that the incident is the second reported cyber-security issue involving the plant. It also notes that the outlet quoted a senior nuclear scientist saying the leak had no connection to nuclear safety.
The article says World Leaks published roughly 19,000 files linked to Kudankulam, that they were described as documents and supplier details, and that Reliance said it experienced a partial data breach at Yotta, a third-party data service provider. It frames the incident as a national-security concern.
The Nuclear Power Corporation of India Limited (NPCIL), which operates the Kudankulam Nuclear Power Plant, has categorically stated that there has been no impact on core nuclear systems due to the reported data breach on dark web. The organisation highlighted that the plant operates on an air-gapped system, ensuring that core operational infrastructure is not connected to the internet, significantly reducing risks of cyber intrusion.
NPCIL is the public sector company responsible for the operation of nuclear power plants in India, including the Kudankulam Nuclear Power Plant, which is frequently described in media as India’s largest nuclear power plant by capacity. Public communications after the 2026 incident emphasized that any leaked files were linked to conventional balance-of-plant facilities and contractor systems rather than core nuclear safety or security systems, underscoring that the exposure arose from a contractor’s server rather than the plant’s internal nuclear control networks.
BBC Tamil reported then that claims of a cyberattack on Kudankulam were false and that the plant said its computers were not connected to the internet. This is a separate earlier allegation, but it is relevant as background showing previous public disputes over cyber claims involving the plant.
What do you think of the claim?
Your challenge will appear immediately.
Challenge submitted!
For developers
This same pipeline is available via API.
Verify your AI's output programmatically.
/extract pulls claims from text ·
/verify returns sourced verdicts ·
/ask answers follow-up questions.
Continue your research
Verify a related claim next.
Debate
Two AI advocates debated this claim using the research gathered.
Argument for
Source 1 (Reuters) and Source 3 (Al Jazeera) confirm that ransomware group World Leaks posted 19,000 files including blueprints and supplier details from the Kudankulam Nuclear Power Plant—explicitly described as India's largest—on the dark web after breaching a Reliance contractor server, with the leak verified by independent researcher Rakesh Krishnan. Sources 4 (Times of India), 5 (India Today), and 7 (The Hindu) further establish the exposure occurred as part of 858,000 Reliance files, directly supporting that files relating to the plant were exposed in a data breach regardless of NPCIL's clarification on scope.
The Proponent overstates what the evidence “confirms”: Reuters explicitly says it reviewed the cache but could not verify the files' authenticity and reports only that World Leaks labelled the material as coming from Reliance (Source 1, Reuters), while Al Jazeera merely repackages Reuters and the researcher's keyword-based observation (“KKNP” search term) rather than independently validating provenance (Source 3, Al Jazeera). Moreover, NPCIL's statements do not just “clarify scope” but directly contest the characterization of a plant-file breach by asserting the publicly posted material is conventional balance-of-plant contractor documentation and that core systems were untouched, which undercuts the motion's implication that Kudankulam plant files were exposed as such (Source 2, The Hindu; Source 4, Times of India; Source 5, India Today).
Argument against
The motion asserts exposed “files relating to” Kudankulam, but Reuters explicitly says it “could not verify their authenticity” and that the cache was merely “labelled as coming from Reliance Group,” which means the central premise (that genuine Kudankulam files were exposed) is unproven and could be misattribution or fabrication (Source 1, Reuters). Moreover, the plant operator NPCIL publicly dismissed the notion of a “sensitive data breach” and said the material in the public domain pertains only to conventional balance-of-plant facilities rather than the nuclear plant's systems, undercutting the claim that Kudankulam plant files were meaningfully exposed in a breach (Source 2, The Hindu; Source 4, Times of India; Source 5, India Today).
The Opponent's emphasis on Reuters' inability to verify authenticity in Source 1 ignores that the same source, along with Source 3, confirms the 19,000 files were posted on the dark web and matched to Kudankulam via the 'KKNP' search term by independent researcher Rakesh Krishnan. The Opponent's citation of NPCIL statements in Sources 2, 4, and 5 commits a straw-man fallacy by equating denials of sensitive nuclear data with denial of any file exposure, when those statements explicitly acknowledge the public-domain material from the Reliance contractor breach.
Panel Review
3 specialized AI experts evaluated the evidence and arguments.
Reviewer 1 — The Logic Examiner
Reuters reports that a ransomware group posted a large cache on the dark web containing 19,000 files that appear related to Kudankulam (e.g., matching the 'KKNP' term) and were described as including purported blueprints and supplier details, with multiple outlets echoing that plant-linked files were exposed even while authenticity could not be fully verified and NPCIL disputed sensitivity rather than the existence of publicly posted contractor/BoP documents (Sources 1, 2, 4, 5, 7). Because the claim only asserts exposure of files relating to Kudankulam (not that they were authenticated as genuine nuclear-safety documents or that core systems were breached), the evidence supports the conclusion that such files were exposed in a data breach, making the claim mostly true despite residual uncertainty about provenance/authenticity of every file (Source 1).
Reviewer 2 — The Source Auditor
The most reliable sources in this pool are Reuters (Source 1, high-authority wire service), The Hindu (Sources 2 and 7, high-authority Indian newspaper), Al Jazeera (Source 3, high-authority international outlet), Times of India (Source 4), and India Today (Source 5). All of these high-authority sources consistently confirm that files relating to the Kudankulam Nuclear Power Plant were posted on the dark web by ransomware group World Leaks, that the plant is described as India's largest nuclear power plant, and that the breach originated from a contractor (Reliance Infrastructure) server. The claim as stated — that 'files relating to the Kudankulam Nuclear Power Plant were exposed in a data breach' — is well-supported: even NPCIL's own statements (reported in Sources 2, 4, and 5) acknowledge the existence of the leaked files while disputing their sensitivity, which actually confirms rather than refutes the core claim. Reuters' caveat about being unable to verify authenticity is a standard journalistic disclaimer, not a denial of the breach itself, and multiple independent sources corroborate the exposure. The claim does not assert that nuclear safety systems were compromised, only that files relating to the plant were exposed, which the totality of high-authority evidence confirms.
Reviewer 3 — The Precision Analyst
Multiple high-authority sources confirm that approximately 19,000 files related to the Kudankulam Nuclear Power Plant, India's largest nuclear plant, were leaked on the dark web following a data breach at contractor Reliance Group (Sources 1, 3, 5). Although the Nuclear Power Corporation of India (NPCIL) clarified that the breach did not compromise core nuclear safety or security systems, they acknowledged that conventional balance-of-plant files were exposed (Sources 4, 5).