Security & Trust 26 min ago0Add to bookmarks

Security researchers have found data attributed to Reliance Industries and India's largest nuclear power plant circulating on dark web marketplaces—the second documented breach at Kudankulam in seven years.
In plain terms: Researchers have found data attributed to Reliance Industries and the Kudankulam Nuclear Power Plant - India's largest - on dark web markets. The scope is under investigation, but operational data is reportedly included. This is the second documented exposure at Kudankulam following the 2019 malware incident on its administrative network.
The 2019 breach was publicly acknowledged only after researchers forced disclosure. The current finding suggests the 2019 exposure was broader than officially stated, or that a subsequent breach occurred and went undetected. Critical infrastructure disclosure culture in South Asia differs sharply from Western regimes: incidents typically surface through independent researchers or dark web monitoring rather than formal notification.
The pattern matters beyond India. Nuclear facility networks worldwide share similar architectural assumptions - air-gapped operational networks, administrative networks connected to corporate systems - that the 2019 Kudankulam incident and this finding have now challenged twice at the same facility.
So what: The Kudankulam case is becoming a template for how nuclear facility breaches unfold: initial exposure minimized, subsequent breach confirmed years later by external researchers. For critical infrastructure operators, the lesson is that air-gap assumptions on administrative networks need adversarial testing, not just policy assurances.
Article produced by artificial intelligence, reviewed under human editorial control.