VidBodh AcademyThe art and science of civil services preparation

Science and Technology › Computing and AI

हिन्दी — Read in Hindi

Cyber security and data protection

Data protection under the Digital Personal Data Protection Act, 2023, how cyber attacks work, including those on artificial intelligence systems and critical infrastructure, cyber crime, and the agencies that respond. It serves GS3 answers on cyber security.

Foundation note: The Digital Personal Data Protection Act, 2023

Prelims and Mains

LeadCyber security of critical infrastructure: the Kudankulam leakJuly 2026

Why in news

A ransomware group published about 19,000 files relating to the Kudankulam nuclear power plant in July 2026. The files were taken from a contractor's data held with a third party provider, and not from the plant's own network.

Background

  • Critical information infrastructure is the computer systems whose failure would harm national security, the economy, public health or safety: power, banking, telecom, transport.
  • Under the Information Technology Act, 2000, the National Critical Information Infrastructure Protection Centre (NCIIPC) protects such systems.
  • The Indian Computer Emergency Response Team (CERT-In) is the national agency that responds to cyber incidents.
  • Ransomware is malicious software that locks or steals data, after which the attackers demand payment.
  • Kudankulam, in Tamil Nadu, is India's largest nuclear power station, with reactors of Russian design.

What happened

  • The attackers reached a server used by a contractor that held an engineering contract for the plant.
  • The operator says the files concern the conventional, non nuclear support systems of Units 3 and 4, and not nuclear safety systems.
  • The concern is that such documents let an adversary map the support systems and look for weak points.
  • The plant had an earlier incident in 2019, when malware infected its administrative network.

The lesson: the supply chain

  • An organisation is only as secure as its weakest vendor.
  • A nuclear plant keeps its control systems cut off from the internet, an air gap. Its contractors' offices are not so protected.
  • Supply chain attacks are a standard way into well defended targets.

The new risk: artificial intelligence

  • A government threat report for banking and payments names AI asymmetry as the defining risk: work that once needed a skilled team is now done at machine speed by attackers with few resources.
  • CERT-In's guidelines of June 2026 require equipment makers and technology providers to use AI assisted security testing, monitoring and patching.
  • The duty is shifting from the user to the manufacturer.

The way forward

  • Extend security rules and audits to contractors of critical infrastructure.
  • Require prompt reporting of breaches by vendors, as CERT-In requires of others.
  • Keep sensitive engineering data on controlled servers in India.
  • Build skilled staff in each critical sector, with regular drills.

Prelims facts

  • CERT-In works under the Ministry of Electronics and Information Technology; NCIIPC protects critical information infrastructure.
  • Both draw their mandate from the Information Technology Act, 2000.
  • Kudankulam is in Tamil Nadu and uses Russian VVER pressurised water reactors.

Open the lead on its own page

The Kudankulam plant is India's largest nuclear power station, and the files published on it by a ransomware group came from a contractor's data held by a third party, which is the supply chain weakness typical of attacks on critical infrastructure.

What changed

  1. 15 Jul 2026LeadCyber security of critical infrastructure: the Kudankulam leak

CERT-In and AI driven threats

Copy link to CERT-In and AI driven threats

Prelims and Mains

The Indian Computer Emergency Response Team is the national agency for cyber incidents.

Also filed elsewhere

Download a copy

Every article on this page, in full.