INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
India Allegedly Leaked Nuclear Plant Files
| 2026-07-20 18:20 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On July 20, 2026, allegedly leaked nuclear plant files from India's Kudankulam Nuclear Power Plant were posted online by the cybercrime group World Leaks. The target country is India and specifically Units 3 and 4 of the power plant under construction near southern India. According to sources, including Reliance Group and Yotta data center provider, nearly 19,000 files totaling about 14.3 GB related to Kudankulam were published by World Leaks, containing documents such as engineering drawings, supplier information, inspection records, insurance documents, meeting records, and more from between 2016 and mid-2025. The attack appears to have been carried out through exposed remote desktop services, phishing or exploitation of a Fortinet vulnerability, although the exact intrusion vector is unknown. As of now, there are no reported security breaches affecting safety or security at the nuclear plant.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Lazarus GroupLazarus Group
Target & Sectors
DPRK
DPRK
energyenergy
Incident Timeline
2026/07/20
Threat actors using World Leaks published nearly 19,000 files totaling about 14.3 GB related to Kudankulam nuclear plant without compromising sensitive information affecting safety or security.
Click on any entity below to view its context and source!
threat_actor
Lazarus Group
In 2019, malware later linked by researchers to North Korea's Lazarus Group was
discovered
on an internet-connected administrative network at the plant.
data_breach
19,000 files
According to Krishnan, nearly 19,000 files totaling about 14.3 GB related to Kudankulam were published by World Leaks.
data_breach
14.3 GB
According to Krishnan, nearly 19,000 files totaling about 14.3 GB related to Kudankulam were published by World Leaks.
financial
$1.5 Entities
It demanded $1.5 million and later published what it said were confidential engineering documents after alleging the company had refused to pay.
Tactical Metrics
Metrics
data_breach
19,000
Files
Click for context!
According to Krishnan, nearly 19,000 files totaling about 14.3 GB related to Kudankulam were published by World Leaks.
Metrics
data_breach
14
Gb
According to Krishnan, nearly 19,000 files totaling about 14.3 GB related to Kudankulam were published by World Leaks.
Metrics
financial
1,500,000
Financial Impact
It demanded $1.5 million and later published what it said were confidential engineering documents after alleging the company had refused to pay.
Intelligence Sources
TheRecord
2026-07-20
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:17
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
the Nuclear Power Corporation of India Limited
entity
6x
timeline
Temporal Reference
2019
date
3x
industry
Targeted Sector
Media
sector
3x
tactic
Cyber Operation Type
Ransomware
tactic
2x
target region
Target Country
India
country
2x
general metric
Units
3
units
Contextual Telemetry
Context Block
6 METRICS
target region
Target Region
DPRK
region
threat actor
APT Group
Lazarus Group
actor
attribution
Attributing Entity
CERT-In
authority
data breach
Files
19,000
files
data breach
Gb
14
gb
financial
Financial Impact
1,500,000
entities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.