fbpx
UPSC Editorial Analysis

Kudankulam Nuclear Cybersecurity Incident

Syllabus: Internal Security [GS 3]

Context

The contractor server linked to Kudankulam Nuclear Power Plant (KNPP) is a victim of ransomware, and its leaked data includes approximately 19,000 files. The officials stated that there was a partial data breach in auxiliary systems, but no breaches were detected in the critical reactor control and nuclear safety systems. The incident brings to the fore threats to critical infrastructure in the cyber realm.

Background of the Incident

  • The Breach: The cyber-extortion group “World Leaks” published 19,000 sensitive project files spanning 2016 to mid-2025 on the dark web.
  • Source: The files were retrieved from a third-party hosted server that was operated by Yotta Data Services, used by the contractor, Reliance Infrastructure. The plant’s common services are under an engineering, procurement and construction contract with Reliance Infrastructure.
  • Affected Components: The documents primarily pertained to Units 3 and 4, which are currently under construction.

Nature of the Leaked Data

  • What was leaked: The exposed information allegedly contained engineering designs for ventilation and cooling systems, common control room layouts, vendor proposals, equipment inspection logs, and supplier information.
  • What didn’t get leaked: The Nuclear Power Corporation of India Limited (NPCIL) and government officials confirmed that the leaked information was limited to conventional “Balance of Plant” common services. It wasn’t an issue of the core systems of the reactors, which are provided by Russia’s Rosatom.

Significance for National Security

  • Intelligence Preparation for Cyberwarfare: Although the “nuclear island” systems are fully protected, information about auxiliary cooling systems, vendor listings and facility layouts allows the adversary to plan and determine physical or cyber vulnerabilities.
  • Supply Chain Vulnerability: Complex supply chains are used for nuclear plants. If a private contractor has a database that is compromised, it can open up the ecosystem to a wider range of third-party risks.
  • Historical Context: This comes after an administrative network at Kudankulam got infected with malware attributed to the Lazarus Group in 2019, showing how Indian CII continues to be targeted.

India’s Cyber Security Framework & Mitigation

  • Air-Gapped Networks: Operating the nuclear reactors is an OT network, which is physically “air-gapped” (no connection to the public internet or external networks). This is an important line of defense to keep external ransomware attacks from changing the way physical plants work.
  • Role of NCIIPC: The National Critical Information Infrastructure Protection Centre (NCIIPC) is the designated nodal agency for securing critical infrastructure.
  • Role of CERT-In: The Indian Computer Emergency Response Team (CERT-In) is responsible for investigating the breach, tracking the threat actors, and enhancing enterprise cybersecurity.

Way Forward

  • Strict Vendor Guidelines: Establishing stringent cybersecurity compliance and auditing mandates for all third-party contractors and vendors associated with critical national projects.
  • Real-Time Threat Intelligence: Tightening up public-private threat sharing to identify unusual activity on the contractor’s servers before data is stolen.
  • Capacity Building: Ongoing evaluation of the capacity of the supply chain infrastructure to ensure that IT systems are operating to the highest international levels of nuclear security. 

Source: The Hindu

image_pdfDownload as PDF
Alt Text Alt Text

    Image Description





    Related Articles

    Back to top button
    Shopping cart0
    There are no products in the cart!
    0