Kudankulam Nuclear Power Plant (KKNPP) Data Leak & Cybersecurity of Critical Infrastructure

  • 20 Jul 2026

In News:

A ransomware group named World Leaks allegedly leaked internal documents related to the Kudankulam Nuclear Power Plant (KKNPP) on the dark web, reviving concerns over the cybersecurity of India's critical infrastructure. While the Nuclear Power Corporation of India Limited (NPCIL) clarified that the leaked material was limited to non-critical facilities outside the reactor island, the incident has renewed focus on protecting strategic assets from cyber threats.

About the Recent Data Leak

The leaked documents reportedly included engineering drawings, inspection records, technical reports, meeting minutes and official correspondence. NPCIL stated that these documents did not relate to reactor operations or nuclear safety, as the highly secured reactor island remained unaffected. Nevertheless, the incident highlights that even non-operational networks associated with strategic installations can become targets for ransomware and cyber espionage.

2019 Kudankulam Cyberattack

The present incident recalls the 2019 cyberattack on Kudankulam, one of India's most significant cyber intrusions involving nuclear infrastructure.

The attack was traced to DTrack malware, linked to the North Korea-backed Lazarus Group, a hacking organisation known for cyber espionage and financial attacks. The malware infected the administrative network's domain controller, potentially exposing user credentials and sensitive information. Investigations suggested that attackers were particularly interested in India's thorium-based nuclear programme.

The malware reportedly entered the network through phishing emails containing malicious links sent to serving and retired nuclear scientists using official email accounts. NPCIL later clarified that only the internet-connected administrative network was compromised, while the reactor control systems remained isolated and unaffected.

Air-Gapped Networks

Nuclear facilities rely on air-gapped networks, which are physically isolated from external networks to minimise cyber risks.

They generally operate through two separate networks:

  • Operational Technology (OT) Network: Controls reactors, turbines and other critical plant operations.
  • Information Technology (IT) Network: Supports administrative functions such as communication, procurement and documentation.

Although air-gapping significantly enhances security, it is not completely foolproof. Malware can still enter through infected USB devices, maintenance equipment, insider threats or phishing attacks. Global incidents such as the Stuxnet attack on Iran's nuclear programme demonstrate that even isolated systems remain vulnerable.

Why Cybersecurity of Nuclear Infrastructure Matters

Nuclear installations constitute Critical Information Infrastructure (CII), where cyberattacks can have consequences far beyond data theft.

Potential risks include:

  • Theft of sensitive scientific and engineering information.
  • Strategic cyber espionage.
  • Disruption of operational systems.
  • Erosion of public confidence in nuclear safety.
  • Threats to national security, energy security and environmental safety during geopolitical conflicts.

As ransomware groups and state-sponsored cyber actors become increasingly sophisticated, protecting both operational and administrative networks has become an essential component of national security.

Measures to Strengthen Cybersecurity

India has adopted multiple institutional and technical safeguards to improve cyber resilience.

  • CERT-In (Indian Computer Emergency Response Team): National nodal agency for responding to cybersecurity incidents.
  • National Critical Information Infrastructure Protection Centre (NCIIPC): Established under the Information Technology Act, 2000, to secure critical infrastructure across strategic sectors.
  • National Cyber Security Policy, 2013: Provides the national framework for enhancing cybersecurity and cyber resilience.
  • Regular cybersecurity audits, penetration testing and continuous network monitoring.
  • Deployment of air-gapped operational networks, stronger access controls and improved security protocols for sensitive installations.

Challenges

Despite these measures, several challenges persist. Administrative networks often remain exposed to phishing attacks and insider threats. Growing digitalisation of critical infrastructure increases the attack surface, while sophisticated ransomware groups and state-sponsored hackers continue to evolve their capabilities. Balancing greater private sector participation in strategic sectors with robust cybersecurity standards is another emerging concern.

Way Forward

India needs to adopt a comprehensive Zero Trust Architecture, strengthen cyber hygiene through continuous employee training, enhance AI-enabled threat detection, conduct regular red-team exercises for critical infrastructure, improve coordination between CERT-In, NCIIPC and sectoral agencies, and develop indigenous cybersecurity solutions for strategic installations. Greater investment in cyber resilience, supply chain security and secure operational technologies will be essential to safeguard critical national infrastructure.