The extortion group World Leaks published roughly 19,000 files, about 14.3GB, tied to India’s Kudankulam Nuclear Power Plant after contractor Reliance Infrastructure refused to pay. The files, posted in mid-July 2026 out of a claimed 858,000-document haul, include ventilation and cooling blueprints, floor layouts, supplier lists, and internal records spanning 2016 to mid-2025. The breach traces to a Reliance server hosted in a third-party data center, with suspicious activity first detected on May 29, 2026. It is a textbook refuse-and-leak outcome against critical national infrastructure.
Who is World Leaks?
World Leaks is an extortion-only operation widely tracked as the successor to Hunters International, which itself descended from the Hive ransomware brand. The group dropped file encryption in favor of pure data theft and leak-site extortion, a shift that mirrors a broader 2026 move away from encryption. For the wider pattern, see our analysis of how ransomware ditched encryption, and track new listings on the Ransomtracker live feed.
What data was exposed?
The published set is a fraction of what World Leaks claims to hold. The 19,000 leaked files include mechanical drawings for ventilation and cooling systems, building floor plans, equipment reviews, supplier and vendor lists, meeting records, and insurance documents. The Nuclear Threat Initiative warned the material poses a “serious risk to the safety of the plant” because it can show an adversary “not just who has access to the project but which systems that access reaches.”
How did the breach happen?
The compromise did not hit the reactor’s operational systems. It hit a Reliance Infrastructure server sitting in a commercial data center, where the contractor stored project documentation. This is a supply-chain exposure: the plant’s most sensitive engineering records lived on a vendor’s IT estate, outside the tightly controlled nuclear operational network. Once the attacker had that server, the refuse-and-leak playbook did the rest.
What this means for critical infrastructure
Nuclear operators harden their operational technology heavily, but the paper trail around a plant, blueprints, supplier lists, access records, often lives with contractors on ordinary corporate networks. Those records are an intelligence goldmine even when the reactor controls are untouchable. The defensive takeaway is that critical-infrastructure data governance has to extend to every contractor that touches design documentation, with the same segmentation, monitoring, and third-party assurance the core plant receives.
Frequently asked questions
Was India’s Kudankulam reactor itself hacked?
No. The breach hit a Reliance Infrastructure server holding project documentation in a third-party data center, not the plant’s operational control systems. The exposure is of engineering and administrative files.
Who is World Leaks?
World Leaks is a data-theft extortion group tracked as the successor to Hunters International, itself linked to the former Hive brand. It steals and publishes data rather than encrypting systems.
How much data was leaked?
World Leaks published about 19,000 files totaling roughly 14.3GB. The group claims to hold around 858,000 Reliance documents in total.
Did Reliance Infrastructure pay the ransom?
No. Reliance refused to pay, and World Leaks published the stolen files after that refusal.
Why is leaked blueprint data dangerous even without control-system access?
Blueprints, supplier lists, and access records can map who and what reaches critical systems, giving an adversary the targeting information needed to plan a future physical or cyber operation.
