Reliance Industries confirmed a partial data breach on a server hosted by Mumbai-based third-party provider Yotta, with leaked files including data related to Tamil Nadu’s Kudankulam Nuclear Power Plant. The breach involves over 858,253 files totaling 1.2 TB, with 19,000 files (14.3 GB) publicly accessible on the dark web since June 11, according to medianama.com.
The Nuclear Power Corporation of India (NPCIL) has been in contact with Reliance regarding the breach, while the Indian Computer Emergency Response Team (CERT-In) is investigating the incident, Reuters reported. Independent cybersecurity researcher Rakesh Krishnan initially flagged the leak on the World Leaks platform. Reliance’s connection to Kudankulam stems from a 2018 contract worth more than Rs 1,081 crore for work on the plant’s third and fourth units.
The leaked database, accessible through a ransomware group’s onion website, contains a vast amount of sensitive information. Reliance has not disclosed the specific nature of the compromised data. The incident highlights ongoing cybersecurity challenges for critical infrastructure projects in India, especially those involving private contractors and third-party service providers.
The breach was first detected on June 11, with the leaked files remaining publicly available on the dark web since then, according to medianama.com. NPCIL and CERT-In continue their probe into the incident as Reliance manages the fallout from the data exposure.