Ease My PrepEase My Prep
All Articles
Science & TechIndian Express20 July 2026

Not the first data breach at Kudankulam: Recalling 2019 cyberattack that targeted thorium info

Practice PYQs on this topic

500+ questions on Science & Tech with explanations

Open App

๐Ÿ“Œ Summary:

  • A data breach has exposed information linked to the Kudankulam Nuclear Power Plant (KKNP), India's flagship nuclear project in Tamil Nadu's Tirunelveli district

  • For nearly a month, documents purportedly linked to the plant โ€” engineering drawings, inspection records, minutes of meetings, technical reports and official correspondence โ€” have circulated on the dark web after being leaked by the ransomware group World Leaks

  • NPCIL (Nuclear Power Corporation of India Ltd), which operates the plant, has downplayed the leak, maintaining the documents relate only to non-critical facilities OUTSIDE the 'reactor island' and pose no risk to nuclear safety; the reactor island is the central, highly protected section where all nuclear processes and critical safety operations take place

  • Why it matters: the breach renews cybersecurity concerns over India's critical and strategic infrastructure, particularly as the government has begun opening the tightly regulated civil nuclear sector to private participation

  • It is NOT the first such incident at Kudankulam โ€” in 2019 malware attributed to a North Korean hacking group was detected in the plant's administrative network

  • The 2019 incident, in detail: it was not confined to KKNP but also affected ISRO; it became public on October 28, 2019 after plant data appeared on virustotal.com, an online malware scanning service

  • Attribution: investigations by multiple cybersecurity agencies attributed the intrusion to DTrack malware, linked to the North Korea-backed Lazarus Group โ€” "an umbrella name that typically describes hacking activity which advances Pyongyang's interests"

  • DTrack belongs to the same malware family linked to the 2016 cyberattack on an Indian private bank's ATM network, which spread across the banking system and forced replacement of an estimated 2.9-3.2 million compromised debit and credit cards

  • Attack mechanism: DTrack targeted the 'domain controller' of KKNP's online network โ€” the central server acting as the network's 'gatekeeper' that verifies authenticity of all other devices โ€” exposing credentials such as passwords

  • Motive: Seoul-based IssueMakersLab claimed the attack was meant to steal information on India's thorium-based nuclear power, a technology Indian scientists have worked on for decades

  • Entry point: IssueMakersLab claimed the attackers targeted senior Indian nuclear scientists, including those who continued using official institutional email accounts for research after retirement; malware-laced links sent to their official and personal accounts spread through the plant's IT systems once opened while connected to the network. The attackers were said to have prior knowledge of the plant's IP network

  • Official response pattern: KKNP officials first denied any attack was possible on the plant's standalone control system; a day later NPCIL admitted an intrusion, saying the Department of Atomic Energy investigated immediately and that CERT-In had flagged the matter on September 4, 2019. NPCIL said the infected PC belonged to a user on the internet-connected administrative network, isolated from the critical internal network, and that plant systems were unaffected

  • How high-security setups work: most operate two "air-gapped" (separate) networks โ€” a standalone control system isolated from any internet-connected administrative network

๐ŸŽฏ UPSC Relevance: GS3 (Internal Security) โ€” cyber security of critical information infrastructure, state-sponsored cyber attacks and attribution, and the security implications of privatising strategic sectors. Links to GS3 Science & Technology on India's thorium programme and to governance questions on disclosure and CERT-In's role.

๐Ÿ“ Prelims Facts:

  • Kudankulam Nuclear Power Plant is in Tirunelveli district, Tamil Nadu; operated by NPCIL

  • 'Reactor island' = the central protected zone of a nuclear plant housing nuclear processes and critical safety operations

  • The current leak is attributed to the ransomware group World Leaks

  • The 2019 attack used DTrack malware, linked to the North Korea-backed Lazarus Group; it also affected ISRO

  • CERT-In (Computer Emergency Response Team-India) flagged the 2019 breach on September 4, 2019; it became public on October 28, 2019

  • The 2016 Indian bank ATM attack from the same malware family forced replacement of an estimated 2.9-3.2 million cards

๐Ÿ”‘ Key Term: Air Gap โ€” a security measure in which a critical network is kept physically and logically isolated from any internet-connected or less-secure network, so that malware cannot traverse from the administrative side to control systems. Air-gapped systems can still be compromised through removable media or insider access, which is why breaches of the administrative network remain serious.

Kudankulamcyber securityNPCILCERT-Incritical infrastructure

UPSC Classification

Prelims (GS1)
Mains
PrelimsMains

See PYQs related to โ€œScience & Techโ€

Every classification tag above links to actual UPSC questions asked on that topic โ€” with answer, explanation and elimination logic. Only in the app.

Download App