VidBodh AcademyThe art and science of civil services preparation

Why in news

A ransomware group published about 19,000 files relating to the Kudankulam nuclear power plant in July 2026. The files were taken from a contractor's data held with a third party provider, and not from the plant's own network.

Background

  • Critical information infrastructure is the computer systems whose failure would harm national security, the economy, public health or safety: power, banking, telecom, transport.
  • Under the Information Technology Act, 2000, the National Critical Information Infrastructure Protection Centre (NCIIPC) protects such systems.
  • The Indian Computer Emergency Response Team (CERT-In) is the national agency that responds to cyber incidents.
  • Ransomware is malicious software that locks or steals data, after which the attackers demand payment.
  • Kudankulam, in Tamil Nadu, is India's largest nuclear power station, with reactors of Russian design.

What happened

  • The attackers reached a server used by a contractor that held an engineering contract for the plant.
  • The operator says the files concern the conventional, non nuclear support systems of Units 3 and 4, and not nuclear safety systems.
  • The concern is that such documents let an adversary map the support systems and look for weak points.
  • The plant had an earlier incident in 2019, when malware infected its administrative network.

The lesson: the supply chain

  • An organisation is only as secure as its weakest vendor.
  • A nuclear plant keeps its control systems cut off from the internet, an air gap. Its contractors' offices are not so protected.
  • Supply chain attacks are a standard way into well defended targets.
How a supply chain attack reaches a protected plant through a contractor's server.
How a supply chain attack reaches a protected plant through a contractor's server.Source: The Indian Express, 15 July 2026; Press Information Bureau, July 2026

The new risk: artificial intelligence

  • A government threat report for banking and payments names AI asymmetry as the defining risk: work that once needed a skilled team is now done at machine speed by attackers with few resources.
  • CERT-In's guidelines of June 2026 require equipment makers and technology providers to use AI assisted security testing, monitoring and patching.
  • The duty is shifting from the user to the manufacturer.

The way forward

  • Extend security rules and audits to contractors of critical infrastructure.
  • Require prompt reporting of breaches by vendors, as CERT-In requires of others.
  • Keep sensitive engineering data on controlled servers in India.
  • Build skilled staff in each critical sector, with regular drills.

Prelims facts

  • CERT-In works under the Ministry of Electronics and Information Technology; NCIIPC protects critical information infrastructure.
  • Both draw their mandate from the Information Technology Act, 2000.
  • Kudankulam is in Tamil Nadu and uses Russian VVER pressurised water reactors.