Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

World Leaks dumps 19,000 files tied to India nuclear plant

Jesse William McGrawBy Jesse William McGrawJuly 16, 2026Updated:July 18, 2026No Comments4 Mins Read71 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
World Leaks dumps 19,000 files tied to India nuclear plant, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

The extortion group World Leaks published roughly 19,000 files, about 14.3GB, tied to India’s Kudankulam Nuclear Power Plant after contractor Reliance Infrastructure refused to pay. The files, posted in mid-July 2026 out of a claimed 858,000-document haul, include ventilation and cooling blueprints, floor layouts, supplier lists, and internal records spanning 2016 to mid-2025. The breach traces to a Reliance server hosted in a third-party data center, with suspicious activity first detected on May 29, 2026. It is a textbook refuse-and-leak outcome against critical national infrastructure.

// KEY FACTS

Threat actor
World Leaks
Victim
Reliance Infrastructure (contractor to Kudankulam Nuclear Power Plant) · Critical infrastructure / energy · India
Timeline
Attack: 2026-05-29  ·  Disclosed: 2026-07-15
Data claimed
19,000 files / 14.3 GB published of 858,000 claimed · Ventilation and cooling blueprints, floor layouts, supplier lists, meeting records, insurance policies (2016 to mid-2025)
Ransom status
Reliance refused to pay; data published after refusal
Verification
Files posted publicly and reviewed by researchers; incident acknowledged to the hosting provider

Who is World Leaks?

World Leaks is an extortion-only operation widely tracked as the successor to Hunters International, which itself descended from the Hive ransomware brand. The group dropped file encryption in favor of pure data theft and leak-site extortion, a shift that mirrors a broader 2026 move away from encryption. For the wider pattern, see our analysis of how ransomware ditched encryption, and track new listings on the Ransomtracker live feed.

What data was exposed?

The published set is a fraction of what World Leaks claims to hold. The 19,000 leaked files include mechanical drawings for ventilation and cooling systems, building floor plans, equipment reviews, supplier and vendor lists, meeting records, and insurance documents. The Nuclear Threat Initiative warned the material poses a “serious risk to the safety of the plant” because it can show an adversary “not just who has access to the project but which systems that access reaches.”

KUDANKULAM // BREACH TIMELINE AND DATA VOLUME May 29Intrusiondetected Jun 11Files appearonline RefusalReliancewill not pay Jul 15Publicleak DATA PUBLISHED vs CLAIMED Published now 19,000 files / 14.3 GB Total claimed 858,000 files held by World Leaks Source: leaked via third-party hosted Reliance Infrastructure server

How did the breach happen?

The compromise did not hit the reactor’s operational systems. It hit a Reliance Infrastructure server sitting in a commercial data center, where the contractor stored project documentation. This is a supply-chain exposure: the plant’s most sensitive engineering records lived on a vendor’s IT estate, outside the tightly controlled nuclear operational network. Once the attacker had that server, the refuse-and-leak playbook did the rest.

What this means for critical infrastructure

Nuclear operators harden their operational technology heavily, but the paper trail around a plant, blueprints, supplier lists, access records, often lives with contractors on ordinary corporate networks. Those records are an intelligence goldmine even when the reactor controls are untouchable. The defensive takeaway is that critical-infrastructure data governance has to extend to every contractor that touches design documentation, with the same segmentation, monitoring, and third-party assurance the core plant receives.

Frequently asked questions

Was India’s Kudankulam reactor itself hacked?

No. The breach hit a Reliance Infrastructure server holding project documentation in a third-party data center, not the plant’s operational control systems. The exposure is of engineering and administrative files.

Who is World Leaks?

World Leaks is a data-theft extortion group tracked as the successor to Hunters International, itself linked to the former Hive brand. It steals and publishes data rather than encrypting systems.

How much data was leaked?

World Leaks published about 19,000 files totaling roughly 14.3GB. The group claims to hold around 858,000 Reliance documents in total.

Did Reliance Infrastructure pay the ransom?

No. Reliance refused to pay, and World Leaks published the stolen files after that refusal.

Why is leaked blueprint data dangerous even without control-system access?

Blueprints, supplier lists, and access records can map who and what reaches critical systems, giving an adversary the targeting information needed to plan a future physical or cyber operation.

Sources and further reading

  • Cybernews: India nuclear plant blueprints posted online (July 15, 2026)
  • Al Jazeera: Data breach reportedly targets India’s Kudankulam nuclear plant (July 16, 2026)
  • Business Standard: Kudankulam files exposed in data breach (July 15, 2026)
  • Ransomnews Ransomtracker: live ransomware victim feed
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleVibe coding is shipping vulnerabilities at scale in 2026
Next Article Scattered Spider duo jailed 5.5 years over £29M TfL hack
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.