Cyber security of critical infrastructure: the Kudankulam leak
LeadPrelims and MainsJuly 2026
Why in news
A ransomware group published about 19,000 files relating to the Kudankulam nuclear power plant in July 2026. The files were taken from a contractor's data held with a third party provider, and not from the plant's own network.
Background
- Critical information infrastructure is the computer systems whose failure would harm national security, the economy, public health or safety: power, banking, telecom, transport.
- Under the Information Technology Act, 2000, the National Critical Information Infrastructure Protection Centre (NCIIPC) protects such systems.
- The Indian Computer Emergency Response Team (CERT-In) is the national agency that responds to cyber incidents.
- Ransomware is malicious software that locks or steals data, after which the attackers demand payment.
- Kudankulam, in Tamil Nadu, is India's largest nuclear power station, with reactors of Russian design.
What happened
- The attackers reached a server used by a contractor that held an engineering contract for the plant.
- The operator says the files concern the conventional, non nuclear support systems of Units 3 and 4, and not nuclear safety systems.
- The concern is that such documents let an adversary map the support systems and look for weak points.
- The plant had an earlier incident in 2019, when malware infected its administrative network.
The lesson: the supply chain
- An organisation is only as secure as its weakest vendor.
- A nuclear plant keeps its control systems cut off from the internet, an air gap. Its contractors' offices are not so protected.
- Supply chain attacks are a standard way into well defended targets.
The new risk: artificial intelligence
- A government threat report for banking and payments names AI asymmetry as the defining risk: work that once needed a skilled team is now done at machine speed by attackers with few resources.
- CERT-In's guidelines of June 2026 require equipment makers and technology providers to use AI assisted security testing, monitoring and patching.
- The duty is shifting from the user to the manufacturer.
The way forward
- Extend security rules and audits to contractors of critical infrastructure.
- Require prompt reporting of breaches by vendors, as CERT-In requires of others.
- Keep sensitive engineering data on controlled servers in India.
- Build skilled staff in each critical sector, with regular drills.
Prelims facts
- CERT-In works under the Ministry of Electronics and Information Technology; NCIIPC protects critical information infrastructure.
- Both draw their mandate from the Information Technology Act, 2000.
- Kudankulam is in Tamil Nadu and uses Russian VVER pressurised water reactors.
See also: CERT-In and AI driven threats
Sources: The Indian Express, 15 Jul 2026 · The Indian Express, 17 Jul 2026: Kudankulam project files surface on the dark web through a contractor's breach (opens in a new tab) · The Hindu, 16 Jul 2026: Leak of Kudankulam nuclear plant data sparks 'commotion' (opens in a new tab) · PIB, 13 Jul 2026: Report Highlights AI Asymmetry and Emerging Cyber Trends to Strengthen Security and Resilience in India's BFSI and Payments Ecosystem (opens in a new tab) · PIB, 30 Jul 2026: CERT-In Conducts 10 Cyber Security Exercises on AI-Driven Cyber Threats with 1,470 Participants from 345 Government and Private Organisations (opens in a new tab)
Earlier coverage: Kudankulam data leak · The monthly magazine, July 2026
