The leak of contract files related to the Kudankulam nuclear power plant — posted on the dark web — underscores the need for India to overhaul its procurement rules to better protect critical systems and strengthen cyber resilience.
Details of the incident
On July 14, Nuclear Power Corporation of India Ltd (NPCIL) reported that a ransomware group known as “World Leaks” had accessed files related to the plant via an external server operated by a private vendor. Exposed documents — technical blueprints, supplier information, inspection reports and equipment reviews — were found on the dark web. Authorities rated the incident as medium severity; the plant’s physical security was not immediately threatened.
A second wake-up call for Indian nuclear security
This is the second major incident affecting Kudankulam since 2019, when the Lazarus group, linked to the North Korean state, attempted to infiltrate the plant’s administrative network using the DTrack malware. Kudankulam remains the only Indian site operating pressurized water reactors, which heightens the importance of securing its supply chains and external contractors.
NPCIL’s response — necessary but incomplete
In response to the leak, NPCIL announced several corrective measures: enhanced audits of vendors and third‑party data centers, stronger encryption for classified documents, and continuous dark‑web monitoring. These steps aim to limit reuse and dissemination of compromised data, but they address consequences more than the underlying cause of the vulnerability.
Strengthening cyber resilience through procurement reform
The use of servers and services provided by private vendors highlights weaknesses in a procurement framework that does not always enforce strict security requirements. To improve cyber resilience, procurement policies must impose clear supplier security obligations, mandate independent audits, require robust encryption, and implement monitoring and control mechanisms across the full contract lifecycle. Without these reforms, technical fixes will remain insufficient against espionage and supply‑chain attacks.
The signal sent by the Kudankulam leak goes beyond a single vendor incident: it highlights the need for a national strategy that ties technical requirements to procurement rules to protect critical infrastructure and reduce the attack surface.

