Inside WorldLeaks: How Ransomware Gangs Are Breaching Critical Infrastructure Through the Supply Chain.

Inside WorldLeaks: How Ransomware Gangs Are Breaching Critical Infrastructure Through the Supply Chain.

Nearly 19,000 files linked to the Kudankulam Nuclear Power Plant surfaced on the dark web after an alleged breach of a contractor. This OSINT investigation unpacks who WorldLeaks is, how the group operates, and why cybercriminals are increasingly exploiting the weakest links in critical infrastructure—the supply chain rather than the facilities themselves.

Nearly 19,000 files allegedly linked to India’s Kudankulam Nuclear Power Plant appeared on the dark web after the ransomware group WorldLeaks claimed responsibility for breaching the systems of one of the project’s contractors. Although Indian authorities say no nuclear safety systems were compromised, the incident once again demonstrates how cybercriminals are increasingly targeting the broader supply chain surrounding critical infrastructure rather than the infrastructure itself.

In this OSINT analysis, OBC dives into the technical aspects of the recent alleged data breach, WorldLeaks’ origin and attack patterns.

What is meant by a ransomware group?

A ransomware group is a set of cybercriminals who infiltrate computer networks to steal, encrypt, or hold an organisation’s data for ransom. Traditionally, these groups deploy ransomware, malicious software that encrypts files and renders them inaccessible until a ransom is paid. But over time, ransomware operations have adopted the method called ‘double extortion’, in which groups not only infiltrate a network but also exfiltrate sensitive data before launching an attack.

The recent data breach

The alleged breach first came to light after the ransomware group ‘WorldLeaks’ listed Reliance Infrastructure Limited on its dark web leak portal, claiming to have exfiltrated data linked to the Kudankulam Nuclear Power Plant (KKNPP), India’s largest nuclear facility in Tamil Nadu.

The preliminary inspection of the dark web portal reveals that the breached data, under the name ‘Reliance Group’, was last updated on June 13.

Screenshot from the WorldLeaks’ dark web portal.

On searching ‘kknp’ within the 1.2 terabytes of the alleged Reliance group’s breach data, we noticed that 18,997 files, which amount to 14.3 gigabytes, belong to the Kudankulam Nuclear Power Plant.

Screenshot from the World Leaks’ dark web portal.

Reliance Infrastructure Limited was awarded the Engineering, Procurement and Construction (EPC) contract for the Common Services – Balance of Plant (BoP) package for Kudankulam Nuclear Power Project (KKNPP) Units 3 and 4 in 2018. The contract scope includes engineering, procurement, construction, and commissioning of conventional support infrastructure for the project.

Reliance Group acknowledged a ‘partial breach’ of data hosted on a server operated by third-party data centre provider Yotta. It said it had informed the Government of India about the incident. However, the company did not disclose what specific data had been compromised.

Though NPCIL has clarified that these facilities are separate from the plant’s nuclear safety and nuclear security systems, the alleged breach highlights an evolving trend in which cybercriminal groups increasingly view the wider supply chain surrounding critical infrastructure as a more accessible route to obtaining high-value information.

WorldLeaks: The group behind the breach

WorldLeaks is a relatively new threat actor that emerged publicly in January 2025, shortly after the ransomware group Hunters International announced it was moving away from traditional ransomware attacks. Unlike conventional ransomware gangs that encrypt victims’ systems before demanding payment, WorldLeaks has positioned itself as a data extortion group that exfiltrates high-value data after unlawfully accessing a network.

After a successful operation, the group threatens the victims with the public release of the stolen information through the group’s dark web leak portal unless a ransom is paid. On May 15, 2025, the group introduced an ‘insider programme’, inviting journalists and researchers to register for early access to the leaked data, which many threat investigators point out as a method to maximise public exposure and pressure the victim.

A screenshot shows details about the ‘insider programme’ on the WorldLeaks dark web portal.

However, on May 3, 2026, they restricted this access only to verified journalists, which, according to the portal, would facilitate ‘responsible’ use of information and credible media reporting.

A screenshot shows details about the ‘insider programme’ on the WorldLeaks’ dark web portal.

Details regarding WorldLeaks’ country of origin are still disputed. Although several cyber threat intelligence organisations suggest a direct link between the threat group and Russia, publicly available information that supports this claim is scarce.

On the contrary, Group-IB, a global threat-hunting and cyber-intelligence company headquartered in Singapore, analysed Hunters International’s affiliate panel and found that the administrators communicated in Russian. A blog published by Group-IB on April 2, 2025, states with high confidence that the first operational notices published to affiliates were written in Russian before being translated, a strong indication that the operators are Russian-speaking.

The blog further describes WorldLeaks as a successor project focused on data extortion, launched by Hunters International on January 1, 2025, and announced that ransomware had become too risky and less profitable.

Other independent reports from 2025 also projected a high chance that WorldLeaks is a direct rebrand of Hunter International.

According to Ransomware.live, a website that monitors ransomware groups and attacks, the top five sectors that WorldLeaks targets are healthcare, manufacturing, business services, technology and consumer services. It reveals that the group has launched 101 attacks over the last twelve months, and so far, the highest number of attacks targeted the US, followed by the UK, Brazil, Germany, and Canada.

The alleged data breach linked to the Kudankulam Nuclear Power Plant reflects a broader shift in how cybercriminals are manoeuvring themselves around critical infrastructure. Rather than trying to infiltrate heavily protected operational technology environments, they are exploiting the weakest link in the supply chain supporting them, which includes contractors, suppliers, and third-party service providers that support these critical infrastructures. These attacks also highlight that being ‘completely secure’ is a myth.

Sujith A

Sujith A

Open Source Intelligence Researcher and Mis/Disinformation tracker. Passionate about investigations and a big fan of Sherlock Holmes.

View all posts by Sujith A
Share Email
Top