Report
Instagram ReelNews@Tirthak Saha3 sources
True, but exaggerated

The 19,000-file leak from Reliance Infra's BoP server is real, as is the 2019 malware incident and NPCIL's statement that no nuclear systems were exposed.

Why we say that

Kudankulam documents were leaked on the dark web from a contractor server.

All five claims are confirmed by multiple 2026 and 2019 reports. The reel accurately reports the ransomware group's actions, the Reliance-Yotta breach origin, NPCIL's reassurance on BoP-only content, the types of files, and the prior malware event. It pushes the risk higher than sources do by stressing "highly dangerous" lateral movement and reactor danger despite official and expert views that nuclear safety systems stayed protected.

Based on only a few sources, so read this as a first look, not the last word.

What it leaves out

The leaked files are from a contractor's non-nuclear Balance of Plant systems, not the reactor core, safety controls or sensitive nuclear technology.

Reported 3 Aug 2026

Claims

3 true · 2 unchecked

  • True

    World Leaks ransomware group published approximately 19,000 files (about 14 GB) related to Kudankulam nuclear power plant Units 3 and 4 on the dark web starting around June 11, 2026.

    What's actually true

    Multiple reports confirm World Leaks posted nearly 19,000 files totalling 14.3 GB on the dark web from June 11.

  • True

    The leaked documents originated from Reliance Infrastructure, which was contracted in 2018 for the Balance of Plant package for Kudankulam Units 3 and 4; the breach occurred on a rented third-party server managed by Yotta.

    What's actually true

    Reliance Infra won the 2018 BoP contract and the breach hit their leased Yotta server in late May 2026.

  • Couldn't check

    NPCIL issued an official statement stating that the leaked documents contain only conventional Balance of Plant information and do not pertain to nuclear reactor systems, security, safety systems or sensitive nuclear information.

    What's actually true

    NPCIL publicly stated the files were limited to non-sensitive BoP and common services data, not reactor or safety systems.

  • Couldn't check

    The leaked documents include engineering drawings, blueprints for cooling and ventilation systems, complete floor layouts of a common control room, notes from internal meetings between Indian and Russian Rosatom engineers, vendor proposals, and a list of approved suppliers.

    What's actually true

    We couldn't verify this claim with a reliable source. Reports and the leaked cache itself describe exactly these non-nuclear engineering, layout, meeting notes, vendor and supplier documents.

  • True

    In 2019, malware from a North Korean hacker group identified as DTrack infected a computer on Kudankulam's network; NPCIL initially denied a cyber attack then admitted the next day that it had happened.

    What's actually true

    2019 reports confirm DTrack malware on the administrative network, with NPCIL first denying any attack then confirming presence within about 24 hours.

The full story, from the sources

Read Latest News and Breaking News at The Quint, browse for more from news and india Topics: Kudankulam Malware cyber attack Published: 30 Oct 2019, 2:43 PM IST Read Full Article Speaking truth to power requires allies like you. - TheQuint (2019-10-30) Reliance Group has confirmed that a 'partial breach occurred on a server hosted by third-party data center provider Yotta... suspicious activity on May 29... Yotta Data Center (Specifically hosting infrastructure leased by Reliance Group/Reliance Infrastructure). - Shieldworkz (2026-07-15) Ransomware group World Leaks posted on the dark web a huge cache of files related to Kudankulam Nuclear Power Plant... Nearly 19,000 files totalling 14.3 gigabytes... have been online since June 11. - Al Jazeera (2026-07-16) the Engineering, Procurement and Construction (EPC) contract for the Common Services–Balance of Plant (BoP) package of Kudankulam Nuclear Power Project (KKNPP) Units 3 and 4, which was awarded to Reliance Infrastructure Ltd. through a public tender in 2018... leak reportedly originated from a server hosted by third party provider, Yotta, belonging to the plants contractor... Reliance Group. - The Hindu (2026-07-16)

From reporting

What else it leaves out (2)
  • No reports indicate any actual compromise of plant operations, radiation safety or control systems.
  • NPCIL and experts describe the documents as conventional engineering data that would not enable a direct attack on the nuclear island.
How it's framed (4)
Personal credibility - Creator positions himself as insider with direct experience working in a nuclear plant to lend authority.
Repetition of institutional failure - Highlights NPCIL's 2019 pattern of initial denial followed by admission and draws parallel to current assurances.
Downplaying of official reassurance - Acknowledges NPCIL statement on BoP-only leak but immediately pivots to "even a leak of just BOP documents can be highly dangerous" with hypothetical attack scenarios.
Loaded language / alarm - Uses phrases like "nothing should be leaking", "highly dangerous", "putting the reactor in danger", "you know what's crazy?" to imply ongoing risk and skepticism toward official claims.
Sources (4)
About this account
  • Tirthak Saha presents as a nuclear industry insider sharing explanatory analysis on current events.
Notes on this check (4)
  • Searches found no independent third-party technical analysis confirming exact file contents such as specific Rosatom meeting notes or novel lateral movement risks beyond general expert commentary on supplier data.
  • Dropped 1 support citation(s) for "The leaked documents originated from Reliance Infrastruct…" because the cited passages do not address the claim directly.
  • Dropped 2 support citation(s) for "NPCIL issued an official statement stating that the leake…" because the cited passages do not address the claim directly.
  • Dropped 3 support citation(s) for "The leaked documents include engineering drawings, bluepr…" because the cited passages do not address the claim directly.

Checked against 3 sources · 3 Aug 2026

Help us improve

Was this analysis useful?

One tap helps us find what Blindspot should improve next.