Verify any claim · lenz.io
Claim analyzed
Tech“The ransomware group World Leaks posted a large cache of files related to the Kudankulam Nuclear Power Plant on the dark web.”
Submitted by Bright Heron 13c5
The conclusion
Open in workbench →Reporting strongly supports that World Leaks placed a sizable set of Kudankulam-related files on the dark web. Reuters reviewed the posting and described roughly 19,000 files totaling about 14.3 GB, and other reputable outlets reported the same. The main caveat is that the files' authenticity and sensitivity were not fully independently verified.
Caveats
- The evidence supports that files were posted, but not that all files were authentic, sensitive, or operationally critical.
- The material appears linked at least partly through contractor Reliance Infrastructure, so readers should not assume a direct compromise of the plant's core systems from this claim alone.
- Some lower-quality sources in the evidence pool are unverified and should not carry weight compared with Reuters and other established outlets.
Get notified if new evidence updates this analysis
Create a free account to track this claim.
Sources
Sources used in the analysis
Ransomware group World Leaks has posted on the dark web a huge cache of files related to India's largest nuclear plant, including purported blueprints of parts of its facilities and supplier details, information it labelled as coming from Reliance Group. Reuters said the 19,000 files appeared to be the most sensitive subset of a total 858,000 Reliance files on the World Leaks website.
Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear plant, including purported blueprints of parts of its facilities and supplier details. Reuters reviewed the documents, which were dated from 2016 to mid-2025, but could not verify their authenticity. Nearly 19,000 files totalling 14.3GB that appear for the search term “KKNP” — an acronym for the nuclear plant — in the data have been online since June 11, according to an independent cybersecurity researcher who first alerted Reuters to the leak.
Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear plant, including purported blueprints of parts of its facilities and supplier details. Nearly 19,000 files totalling 14.3GB that appear for the search term “KKNP” — an acronym for the nuclear plant — in the data have been online since June 11, according to independent cybersecurity researcher Rakesh Krishnan, who first alerted Reuters to the leak.
The incident reportedly involved the posting of sensitive documents to the dark web, including purported blueprints and supplier details. According to reports, the leaked materials include inspection records and equipment reviews. World Leaks has posted these files on the dark web, although their full authenticity remains under investigation.
A ransomware group has allegedly leaked thousands of files linked to the Kudankulam Nuclear Power Plant, raising concerns over cybersecurity at India's critical infrastructure. The hacker group World Leaks claims to have published over 19,000 files as part of a larger cache allegedly stolen from Reliance Group, a contractor involved in the project.
A massive data breach has exposed nearly 19,000 sensitive files related to the Kudankulam Nuclear Power Plant on the dark web. The files, totaling 14.3 gigabytes, were leaked by the ransomware syndicate World Leaks after extortion demands were ignored.
On Tuesday, July 15, 2026, news emerged regarding a significant data breach involving the Kudankulam Nuclear Power Plant, where several gigabytes of sensitive information were reportedly compromised and leaked following a ransomware attack. The leaked data has surfaced on World Leaks, a dark web platform operated by cybercriminals who target susceptible organizations with ransomware, threatening to disclose the information unless a ransom is paid.
A large number of files allegedly from India's largest nuclear plant, the Kudankulam Nuclear Power Plant (KNPP), have been leaked on the dark web. About 858,000 files were posted on the dark web by ransomware group World Leaks, which it claimed were from the Reliance Group, a Reuters report said. 19,000 of these files appeared to be highly sensitive, including blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies.
A ransomware assault targeting a contractor linked to the Kudankulam nuclear power initiative raises alarms, even though no critical data threatening the facility's security was compromised. Based on available information, the core infrastructure of the facility remains intact. Instead, **a group named 'World Leaks' executed a ransomware attack that affected data belonging to Reliance Infrastructure**, one of the engineering contractors for Units 3 and 4. As per the open-source intelligence platform RansomLook, **the compromised data started appearing on World Leaks on June 11**, hosted on the dark web. Approximately **14.3 GB of documents have been made public**, including designs of ventilation systems, floor plans for an alleged control room, lists of suppliers and vendors, and insurance documentation.
For more than a month, a large cache of files purportedly linked to the Kudankulam Nuclear Power Plant have been available on the dark web. The data, leaked by ransomware group World Leaks, is purportedly linked to Anil Ambani-led Reliance Group, whose subsidiary Reliance Infrastructure Ltd was awarded the EPC contract in 2018 for the plant's non-nuclear Balance of Plant facilities. The leaked data includes a 14.3 GB dataset comprising 18,997 files related to the plant.
In response to reports indicating that a ransomware group had accessed highly sensitive information from a contractor's server related to the Kudankulam Nuclear Project (KNPP), Nuclear Power Corporation of India Limited (NPCIL) issued a statement on Wednesday, July 15, 2026, dismissing the notion of a 'sensitive data breach.' They clarified that the information purportedly available publicly is limited to 'conventional balance of plant common services.' The data leak reportedly **stemmed from a server managed by third-party service provider Yotta, linked to the contractor Reliance Group**, which acknowledged a 'partial breach' but refrained from discussing the specifics of the data accessed via the dark web.
A massive data breach has exposed nearly 19,000 sensitive files related to the Kudankulam Nuclear Power Plant on the dark web. The files, totaling 14.3 gigabytes, were leaked by the ransomware syndicate World Leaks after extortion demands were ignored. The leaked files span from 2016 to mid-2025 and reportedly contain engineering blueprints, vendor proposals, supplier lists, and inspection reports.
A ransomware group has allegedly **leaked thousands of files linked to the Kudankulam Nuclear Power Plant**, raising concerns over cybersecurity at India's critical infrastructure. The hacker group **World Leaks claims to have published over 19,000 files as part of a larger cache allegedly stolen from Reliance Group**, a contractor involved in the project. The leaked documents reportedly include engineering plans, control room layouts and inspection records related to Units 3 and 4, which are under construction.
The KNPP attack was not intended to cause destruction but to **extort the confidential data and conduct reconnaissance**. Group B **extorts the confidential documents from the nuclear power plant system**, so the malware found in the nuclear power plant system is Group B’s malware. Dtrack malware is a backdoor Trojan designed specifically to **steal data from the compromised device** and was attributed to the Lazarus Group; this earlier incident at Kudankulam shows a history of cyberattacks aimed at data exfiltration, though it predates the World Leaks case.
World Leaks has previously targeted Nike and India’s Tata Group. The site can be accessed only with a specialised browser. The posting reportedly included a very large cache of files connected to Reliance Group and the Kudankulam project.
Nearly 19,000 files tied to Kudankulam Nuclear Power Plant, including blueprints, supplier records, and inspection reports, surfaced on the dark web this week.
A massive data breach has exposed nearly 19,000 sensitive files related to the Kudankulam Nuclear Power Plant on the dark web. These files are available on the dark web.
What do you think of the claim?
Your challenge will appear immediately.
Challenge submitted!
For developers
This same pipeline is available via API.
Verify your AI's output programmatically.
/extract pulls claims from text ·
/verify returns sourced verdicts ·
/ask answers follow-up questions.
Continue your research
Verify a related claim next.
Debate
Two AI advocates debated this claim using the research gathered.
Argument for
Multiple highly authoritative sources, including Reuters (Source 1 and Source 2), The Straits Times (Source 3), and The Hindu (Source 9), independently confirm that ransomware group World Leaks posted a large cache of files related to the Kudankulam Nuclear Power Plant on the dark web, with nearly 19,000 files totaling 14.3GB available since June 11, 2026. The breadth and consistency of corroboration across over a dozen independent outlets—from Reuters to The Indian Express (Source 10) to Cyber Security News (Source 6)—leaves no reasonable doubt that this event occurred exactly as the claim states.
The Proponent's argument commits a fallacy of division by conflating a breach of a third-party contractor's non-nuclear infrastructure with a direct compromise of the nuclear facility itself. As documented in Source 11, the Nuclear Power Corporation of India Limited clarified that the exposed files are limited to conventional balance of plant common services from a third-party server, while Source 2 and Source 4 confirm that the authenticity of these purported documents remains unverified.
Argument against
The claim that World Leaks posted files from the Kudankulam Nuclear Power Plant is misleading because the Nuclear Power Corporation of India Limited dismissed the notion of a sensitive data breach, clarifying that the exposed files are limited to conventional balance of plant common services from a third-party contractor (Source 11). Furthermore, as noted in Source 2 and Source 4, the authenticity of these purported blueprints and documents has not been verified by independent investigators, meaning the files cannot be definitively linked to the actual nuclear facility.
The Opponent commits a classic red herring fallacy by conflating the sensitivity of the leaked files with whether the posting itself occurred — NPCIL's characterization of the data as 'conventional balance of plant common services' (Source 11) does not in any way contradict the verified fact that World Leaks posted a large cache of files related to Kudankulam on the dark web, which is precisely what the claim asserts. Furthermore, the Opponent's appeal to unverified authenticity is undermined by Source 2, which confirms that Reuters itself reviewed the documents, and by Sources 1, 3, 9, and 10, which collectively establish that 14.3GB of files tagged 'KKNP' have been publicly accessible on the dark web since June 11 — the posting of the files is not contingent on their forensic authentication.
Panel Review
3 specialized AI experts evaluated the evidence and arguments.
Reviewer 1 — The Logic Examiner
Reuters reports that the ransomware group World Leaks posted a huge cache of files on the dark web that match Kudankulam-related search terms ("KKNP"), totaling about 19,000 files/14.3GB, and Reuters reviewed the documents though it could not verify authenticity (Sources 1-2), with multiple other outlets echoing the same posting claim (Sources 3, 7, 9-10). The opponent's points about the breach being via a contractor and about uncertain authenticity do not logically negate the narrower proposition that World Leaks posted a large cache of files related to Kudankulam on the dark web, so the claim is true as stated.
Reviewer 2 — The Source Auditor
The most reliable sources are Reuters (Sources 1 and 2), which independently reviewed the dark-web files and confirmed World Leaks posted nearly 19,000 KKNP-tagged files totaling 14.3 GB since June 11; this is corroborated without circularity by The Straits Times (Source 3), The Hindu (Sources 9 and 11), and The Indian Express (Source 10). The claim is therefore true because these high-authority outlets directly establish that the ransomware group posted a large cache of files related to the plant, regardless of later disputes over file sensitivity or authenticity.
Reviewer 3 — The Precision Analyst
The claim states that 'World Leaks posted a large cache of files related to the Kudankulam Nuclear Power Plant on the dark web.' Every major source in the evidence pool — Reuters (Sources 1, 2), The Straits Times (Source 3), The Hindu (Sources 7, 9, 11), The Indian Express (Source 10), and others — consistently confirms that World Leaks did post a large cache of files (nearly 19,000 files totaling 14.3GB, part of a broader 858,000-file Reliance Group dataset) on the dark web, with the files tagged 'KKNP' (the acronym for Kudankulam Nuclear Power Plant). The claim's wording — 'large cache of files related to the Kudankulam Nuclear Power Plant' — is precisely accurate: the files are related to the plant (via contractor Reliance Infrastructure), they are large in quantity, and they were posted on the dark web by World Leaks. The opponent's argument about authenticity and NPCIL's characterization does not contradict the posting itself, which is what the claim asserts. The claim does not assert the files are authentic, sensitive, or from the plant's core systems — only that they are 'related to' the plant and were posted on the dark web, which is fully supported.