Threat Intelligence Brief
Curated summary with source attribution
Source: thehindu.com
Threat Risk: Medium
Victim: Reliance Infrastructure / Kudankulam Nuclear Power Project
Incident: Ransomware group World Leaks accessed and leaked over 19,000 technical files from a contractor’s server.
Impact: Exposure of engineering blueprints, vendor lists, and operational records for supporting plant infrastructure.
Attacker: World Leaks
Analysis: The breach occurred on a server hosted by a third-party provider for Reliance Infrastructure, a contractor managing the plant’s Balance of Plant systems. While officials claim core nuclear safety remains intact, the leak includes sensitive blueprints for cooling and ventilation systems. This incident underscores the persistent risk posed by supply chain vulnerabilities in critical infrastructure.
Recommendations: Implement stringent security audits and compliance mandates for third-party EPC contractors.; Enforce strict data minimization and encryption for technical blueprints shared with vendors.; Adopt a Zero Trust architecture for servers hosting critical infrastructure documentation.
Source: The Hindu
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source