Sci-Tech · 16 Jul 2026

Kudankulam data breach supply chain

With reference to the 2026 Kudankulam Nuclear Power Plant (KKNPP) data leak, consider the following statements:

  1. The leaked data originated from a breach of KKNPP's own air-gapped reactor control and safety network.
  2. The leaked files pertained to conventional "Balance of Plant" facilities common to thermal plants as well, not to nuclear safety or security systems.
  3. This was the first cyber incident to affect Kudankulam, with no prior comparable breach on record.

Which of the statements given above is/are correct?

A1 only
B2 only
C1 and 3 only
D2 and 3 only

Tests the ability to precisely separate what was and was not compromised in a multi-layered infrastructure breach - a distinction requiring careful reading rather than surface-level headline recall.

Subscribe / Login in App →
About this question

Why in news

Over 19,000 files linked to the Kudankulam Nuclear Power Plant were leaked on the dark web by a ransomware group after a breach at a contractor's third-party-hosted server, detected on May 29, 2026.

Why for UPSC

UPSC has asked about India's National Cyber Security Strategy comprehensively (2022, GS3); this question tests whether aspirants can correctly separate what was and was not breached - a common source of media conflation in this specific case.

Prelims summary

The Kudankulam breach occurred at a third-party contractor's server, not the plant's own air-gapped core network and involved only conventional "Balance of Plant" data - this being the second such incident after 2019's DTrack malware attack.

On web, answers are shown once after a test — no save or reattempt. For unlimited reattempts, Hindi medium, and Mentor Observations, use the TAN App.