Partial Breach of Contractor Data Exposes Non‑Nuclear Engineering Docs for Kudankulam Plant
What Happened — A cyber‑crime group called World Leaks published thousands of files that appear to originate from Reliance Infrastructure, a subcontractor building balance‑of‑plant (BoP) facilities for India’s Kudankulam Nuclear Power Plant. The files were hosted on Indian data‑center provider Yotta, which detected suspicious activity, halted a suspected ransomware execution, and shared forensic results with the contractor.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a third‑party data breach that SOC 2‑ready organizations must anticipate, monitor, and evidence in their Vendor Management program (CC6.1).
- Continuous monitoring of third‑party environments and documented remediation actions provide the audit trail needed to demonstrate due diligence under SOC 2 and related regulatory frameworks.
Who Is Affected – Nuclear power operators, engineering contractors, data‑center providers, and any organizations that rely on third‑party infrastructure for critical projects.
Recommended Actions –
- Review and tighten remote‑desktop exposure and phishing defenses for all third‑party connections.
- Map the incident to SOC 2 CC6.1 (Vendor Management) and CC7.1 (System Operations) controls, collect logs, and retain forensic reports as audit evidence.
- Initiate a formal third‑party risk reassessment, updating contracts to require continuous security monitoring and breach‑notification clauses.
Source: The Record
Technical Notes – The breach may have stemmed from exposed Remote Desktop Services, a phishing campaign, or exploitation of a Fortinet vulnerability (no public CVE confirmed). Exfiltrated data includes engineering drawings, supplier lists, inspection records, and insurance documents for the BoP package (≈ 19,000 files, 14.3 GB). Source: same as above