HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Partial Breach of Contractor Data Exposes Non‑Nuclear Engineering Docs for Kudankulam Plant

World Leaks published thousands of files tied to Reliance Infrastructure, a subcontractor for India's Kudankulam Nuclear Power Plant. The leak stems from a suspected ransomware‑related intrusion on a Yotta‑hosted server. While safety systems were not compromised, the event highlights the need for SOC 2‑ready vendor‑risk controls and continuous monitoring.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
therecord.media

Partial Breach of Contractor Data Exposes Non‑Nuclear Engineering Docs for Kudankulam Plant

What Happened — A cyber‑crime group called World Leaks published thousands of files that appear to originate from Reliance Infrastructure, a subcontractor building balance‑of‑plant (BoP) facilities for India’s Kudankulam Nuclear Power Plant. The files were hosted on Indian data‑center provider Yotta, which detected suspicious activity, halted a suspected ransomware execution, and shared forensic results with the contractor.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a third‑party data breach that SOC 2‑ready organizations must anticipate, monitor, and evidence in their Vendor Management program (CC6.1).
  • Continuous monitoring of third‑party environments and documented remediation actions provide the audit trail needed to demonstrate due diligence under SOC 2 and related regulatory frameworks.

Who Is Affected – Nuclear power operators, engineering contractors, data‑center providers, and any organizations that rely on third‑party infrastructure for critical projects.

Recommended Actions

  • Review and tighten remote‑desktop exposure and phishing defenses for all third‑party connections.
  • Map the incident to SOC 2 CC6.1 (Vendor Management) and CC7.1 (System Operations) controls, collect logs, and retain forensic reports as audit evidence.
  • Initiate a formal third‑party risk reassessment, updating contracts to require continuous security monitoring and breach‑notification clauses.

Source: The Record

Technical Notes – The breach may have stemmed from exposed Remote Desktop Services, a phishing campaign, or exploitation of a Fortinet vulnerability (no public CVE confirmed). Exfiltrated data includes engineering drawings, supplier lists, inspection records, and insurance documents for the BoP package (≈ 19,000 files, 14.3 GB). Source: same as above

📰 Original Source
https://therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →