New Delhi
A ransomware and data extortion group calling itself World Leaks has claimed to have breached systems linked to Reliance Group and published what it says is a massive cache of data containing documents related to the Kudankulam Nuclear Power Plant (KKNPP) project, including records associated with Units 3 and 4 that are currently under construction.
The Sunday Guardian accessed the online repository where the hackers have hosted the data and found that the published dataset comprises approximately 1.2 TB of data containing 858,253 files. An examination of the repository further showed that the dataset was made publicly available on 13 June, nearly a month before the incident came into the public domain.
According to the repository structure, the data is divided into two principal directories.Â
One directory, labelled RCS.COM, contains about 29,491 files with a stated size of 105 GB, while another directory, labelled server, contains approximately 828,762 files with a stated size of 1.1 TB.
Within the server directory, The Sunday Guardian found what appeared to be an organised internal file repository comprising folders such as document_control_center, finance, HR, QUALITY and user_data. Inside the document_control_center directory was a dedicated folder titled “01-Nuclear KKNPP-3&4 Power Project”, indicating records relating to the Kudankulam Nuclear Power Plant Units 3 and 4 project.
The repository contained folders titled Minutes of Meeting (MOM), Letter Client to Reliance (Site), Letter Reliance (Site) to Client, Transmittals Reliance (HO) to Client, Technical Spec & TER, DBR & Concept Notes, Approved ISN Documents, Vendor Letter, Site In-Out Going Letters to NPCIL, CIVIL-CAT-1 Documents, and NCR, indicating the presence of engineering records, project correspondence, technical specifications, vendor communications and quality-related documentation.
The repository also contained meeting records spanning multiple years. Visible folders included meeting records dated March, April and November 2022, as well as a folder referring to a signed Minutes of Meeting for a meeting held on 13 July 2023 between Reliance Infrastructure and NPCIL. Several PDF and archived meeting documents dating back to 2018 were also visible.
While examining the repository, The Sunday Guardian deliberately withheld specific filenames, technical drawings, engineering specifications and other potentially sensitive information. This report is limited to describing the broad categories of documents contained in the dataset so as to establish the nature and apparent scope of the claimed breach without placing sensitive project information in the public domain.
Some of the documents reviewed by The Sunday Guardian related specifically to the Kudankulam project. However, given the scale of the published cache, comprising more than 858,000 files, it was not possible to independently verify every document contained in the repository or establish the authenticity of each file.
The apparent directory structure suggests the material originated from an internal document management system used for project execution. However, the existence of files in the published repository does not by itself establish that every document is authentic or that all of the material was exfiltrated from the claimed source.
Following the disclosure of the incident, Reliance Infrastructure said there had been a partial breach involving data stored on a server hosted by third-party data centre operator Yotta and that the government had been informed. The company did not specify what information had been compromised.
Yotta said it detected suspicious activity on a Reliance Infrastructure server that it hosts on 29 May and immediately terminated the activity, preventing the suspected ransomware execution. The company said Reliance Infrastructure subsequently informed it towards the end of June that external threat actors were claiming a data breach. Yotta added that it has not independently verified those claims but has shared the findings of its technical investigation with Reliance Infrastructure and is supporting the ongoing investigation.
The incident is being examined by government agencies, including CERT-In. The documents reviewed by The Sunday Guardian appear to include project management, engineering and administrative records relating to the Kudankulam Units 3 and 4 project. Based on the material examined by this newspaper, there is no indication that reactor control systems or operational nuclear systems were part of the repository reviewed.