Threat Intelligence Brief
Curated summary with source attribution
Source: indianexpress.com
Threat Risk: Medium
Victim: Critical Infrastructure Contractor
Incident: Exfiltration of project and engineering data from a third-party server hosting Reliance Infrastructure files.
Impact: Exposure of internal designs, inspection records, and administrative correspondence for the plant’s Balance of Plant facilities.
Attacker: World Leaks
Analysis: The breach occurred through a third-party data center hosting servers for Reliance Infrastructure, a contractor for the plant’s non-nuclear facilities. By targeting the contractor rather than the plant operator, attackers successfully exfiltrated sensitive engineering designs and correspondence. This incident underscores how the weakest link in the supply chain can compromise the confidentiality of critical infrastructure data.
Recommendations: Conduct rigorous security audits of third-party data hosting and cloud service providers.; Implement strict data encryption and segmentation for all critical infrastructure project documentation.; Enforce zero-trust access controls for external vendors and EPC contractors.
Source: The Indian Express
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source