Nuclear Data on the Dark Web: Why the Kudankulam Breach Exposes India's DPDP Act Supply Chain Gap
A ransomware group leaked 14.3 GB of Kudankulam nuclear plant data in July 2026. India's DPDP Act breach notification rules aren't in force yet — and that gap is costing the country dearly.

#Nuclear Data on the Dark Web: Why the Kudankulam Breach Exposes India's DPDP Act Supply Chain Gap
On June 11, 2026, a ransomware group called World Leaks published 14.3 gigabytes of sensitive data from India's largest nuclear facility on the dark web — blueprints, supplier details, engineering meeting minutes, and a $112 million insurance policy for Kudankulam Nuclear Power Plant. India's Digital Personal Data Protection Act exists. Its breach notification rules do not — not yet. The gap between those two facts is the story.
The breach became public knowledge through media reporting on July 16 and 17, first covered by The Week and picked up by Al Jazeera and Eastern Herald. At a moment when India's corporate sector is scrambling to meet the DPDP Act's November 2026 Consent Manager deadline, this incident is a jarring reminder that data protection law without enforced data breach rules is an incomplete shield.
#What Was Leaked and How
Kudankulam, a nuclear power station in Tamil Nadu built in collaboration with Russia's Rosatom, contracted Reliance Infrastructure as the EPC (Engineering, Procurement, Construction) contractor for the common services of Units 3 and 4. Reliance Infrastructure used servers managed by Yotta Data Services, a private commercial cloud provider, to store project documentation.
Yotta detected suspicious activity on May 29, 2026. By June 11, World Leaks had already published 19,000 files — the most sensitive portion of a 858,000-file haul — on the dark web. The published documents span from 2016 to mid-2025 and include:
- Engineering drawings and technical blueprints for cooling and ventilation systems
- Complete floor layouts of the common control room
- Internal meeting minutes between Indian and Russian engineers
- Vendor proposals and supplier lists for Units 3 and 4
- A $112 million terrorism insurance policy for the facility
Reliance Infrastructure confirmed a "partial breach" and reported it to government authorities — but only by the end of June, weeks after Yotta had already detected the intrusion.
The Nuclear Power Corporation of India Limited (NPCIL) issued a statement dismissing the material as routine "balance of plant" information, arguing that core safety systems remain secure and air-gapped from external networks. Security experts disagreed sharply. A senior official at the Nuclear Threat Initiative described the exposure as posing a "serious" risk, noting that physical blueprints allow adversaries to identify structural vulnerabilities that can bypass digital protections entirely.
#The DPDP Act's Enforcement Gap: What the Law Says, What It Doesn't Do Yet
India's Digital Personal Data Protection Act 2023, operationalised through the DPDP Rules notified in November 2025, contains explicit breach notification obligations. Under Rule 7, a Data Fiduciary that experiences a personal data breach must:
- Notify the Data Protection Board of India without delay
- Notify each affected Data Principal
- Submit a detailed breach report to the Board within 72 hours
Failure to comply carries penalties of up to ₹200 crore.
There is one critical problem with applying those rules to the Kudankulam breach: they are not in force yet. The full compliance deadline for Data Fiduciaries — including breach notification obligations — is May 13, 2027. Until that date, the DPDP Act's penalty framework for breach reporting remains dormant.
This is not a minor footnote. It means that when Reliance Infrastructure detected a breach on its data stored with a third-party cloud provider, there was no statutory DPDP obligation compelling them to notify a data protection regulator within any specific timeframe under the new law. The only obligation that applied — and which appears to have been violated — is the one India has had since 2022: CERT-In's six-hour reporting requirement.
#The CERT-In Problem: A Law That Should Have Applied
India's Computer Emergency Response Team issued binding directions in April 2022 requiring all entities to report cybersecurity incidents to CERT-In within six hours of detection. This includes ransomware attacks and data exfiltration events. CERT-In has confirmed it has opened a formal investigation into the Kudankulam breach.
The timeline here is deeply uncomfortable. Yotta detected suspicious activity on May 29. World Leaks published 19,000 files on June 11. Reliance Infrastructure notified government authorities "by end of June." That is at best 30 days from detection to official notification — and at worst, Reliance may not have known the scale of what had been taken until external actors made it impossible to ignore.
Even without the DPDP Act's breach rules in force, CERT-In's six-hour reporting mandate applies to cybersecurity incidents affecting Indian entities. Whether Reliance Infrastructure filed that report within the required window is not yet publicly confirmed. CERT-In's investigation is ongoing.
This matters enormously to the DPDP Act conversation because it illustrates a principle that India's data protection regulators have not yet had to enforce: a chain of data processors is only as secure as its weakest link. Under the DPDP Act's framework, Yotta would be classified as a Data Processor — an entity processing personal data on behalf of a Data Fiduciary (Reliance). Once the Act's obligations take full effect, Data Fiduciaries bear responsibility for ensuring their processors maintain equivalent security standards.
That contractual and legal chain did not function in this case.
#Supply Chain Data Protection: The DPDP Act's Biggest Blind Spot
The Kudankulam breach illustrates what may become India's most pressing data protection challenge: supply chain accountability.
Under the DPDP Act, a Data Fiduciary (the entity that determines the purpose and means of processing data) is responsible for ensuring that any Data Processor it engages implements appropriate security safeguards. The Act and Rules define security in terms of "reasonable safeguards to prevent personal data breach," but leave the specific technical and organisational measures largely to the discretion of the Data Fiduciary.
For entities that will eventually be designated as Significant Data Fiduciaries — MeitY has proposed an accelerated SDF notification timeline, with SDFs required to comply by November 2026 rather than May 2027 — the obligations are even stricter: mandatory Data Protection Impact Assessments, independent audits, and algorithmic accountability.
What the Act does not do — and what this breach makes painfully clear is needed — is establish specific supply chain security standards for critical infrastructure contractors. NPCIL, as a government entity, would likely fall under Section 17's government exemption from the DPDP Act's full obligations. Reliance Infrastructure, as a private contractor handling infrastructure data for a government entity, sits in a grey zone. Yotta, as the cloud provider, is a Data Processor with contractual but not yet statutory DPDP obligations.
The result: three entities in the data chain, none of them clearly bound by the enforcement framework that would have required timely breach reporting.
#What "Air-Gap" Security Cannot Protect Against
NPCIL's defence — that the plant's core operational systems are air-gapped from external networks — reflects a security model that no longer covers the actual exposure surface of modern critical infrastructure projects.
The Kudankulam breach did not penetrate reactor controls. It penetrated the commercial cloud storage of a private contractor. The data that ended up on the dark web includes the kind of information that an adversary would use not to hack a system remotely, but to understand its physical layout, identify component suppliers, and plan a physical intervention.
Engineering blueprints, vendor supply chains, and construction specifications are not personal data in the narrow sense the DPDP Act primarily addresses. They are national security-adjacent infrastructure data. Yet they traveled through a commercial cloud provider — Yotta — without the kind of sovereign, hardened security architecture one might expect for nuclear project documentation.
Former government official E.A.S. Sarma, quoted in coverage of the breach, called for "an independent investigation into the circumstances surrounding the leak" and for "foolproof security firewalls to prevent hacking" across all nuclear plants. The gap he identifies is not one that the DPDP Act, even fully enforced, is designed to close. It requires a broader critical infrastructure data governance framework that India does not yet have.
#The Compliance Calendar Context
This breach surfaces at a moment of acute pressure on India's data protection landscape:
November 13, 2026 is when the Consent Manager framework becomes operational — the first major DPDP compliance milestone that directly affects how Data Fiduciaries collect and manage user consent across platforms. Organisations must register consent management systems with the Data Protection Board, which is itself still in the process of appointing its Chairperson and four Members.
EY India research cited across compliance analyses finds that approximately 83 percent of organisations have not yet begun comprehensive DPDP Act implementation. Nearly 81 percent have not updated or drafted DPDP-compliant privacy policies.
MeitY proposed in January 2026 to accelerate SDF compliance timelines from May 2027 to November 2026, and to bring cross-border data transfer restrictions for Significant Data Fiduciaries into force immediately — signals that the government itself recognises the urgency of closing enforcement gaps faster than the original schedule allowed.
Against this backdrop, a major breach at a nuclear facility's contractor — with a weeks-long delay between detection and notification — is not an isolated incident. It is a preview of what happens when enforcement infrastructure lags behind the threats that exist in practice.
#What Indian Businesses and Policymakers Must Take From This
For corporate India preparing for DPDP compliance: The Kudankulam breach is not someone else's problem because you don't process nuclear data. Every organisation that shares data with third-party vendors — cloud providers, SaaS platforms, logistics partners, marketing agencies — faces the same supply chain exposure. The DPDP Act will require you to be accountable for your processors' security practices. Map your data processors now, before the obligation becomes enforceable, not after a breach has already made the front page.
For policymakers: The phased enforcement timeline that keeps breach notification rules dormant until May 2027 creates a window in which India experiences real-world breaches with no statutory accountability mechanism under the new law. The CERT-In six-hour rule is not a substitute — it covers cybersecurity incidents, not the rights of affected data principals to be informed. Accelerating the breach notification provisions — even selectively for critical infrastructure operators and their contractors — would close a gap this breach has made unmistakably visible.
For the Data Protection Board: When it is fully constituted, one of the Board's first test cases will likely involve breach notification. The Kudankulam precedent — delayed notification, contractor chain responsibility, government exemption ambiguity — will shape how the Board interprets its mandate. Getting these interpretations right matters for every regulated entity in India.
#Conclusion: A Law Without Teeth Is Still the Right Law
India's Digital Personal Data Protection Act is the right framework for the country's data governance needs. The fact that its enforcement timeline leaves critical gaps — as the Kudankulam breach has demonstrated — is not an argument against the law. It is an argument for accelerating it.
Nuclear blueprints are now on the dark web. The breach notification rules that would have compelled faster disclosure, mandatory affected-party notification, and a statutory investigation timeline are 10 months from being enforceable. That is the reality India is operating in today.
The question is not whether the DPDP Act is adequate. The question is whether the country can afford to wait until May 2027 to find out.
For a deeper look at how the Consent Manager framework affects your organisation before November 2026, see our /resources section. If you're building a consent management strategy, our /consent-manager guide walks through what the DPDP Rules require.

