Data breach revives memories of 2019 cyberattack at Kudankulam, Pg15
Ransomware group World Leaks exposes Kudankulam Nuclear Power Plant data, reigniting critical infrastructure cybersecurity fears after 2019 North Korean attack.
A recent data breach has exposed information purportedly linked to the Kudankulam Nuclear Power Plant (KKNP) in Tamil Nadu.
The ransomware group World Leaks claimed responsibility for leaking numerous documents on the dark web.
Nuclear Power Corporation of India Ltd (NPCIL), which operates the plant, stated that the leaked documents pertain to 'non-critical facilities' outside the 'reactor island' and pose no risk to nuclear safety.
The incident has revived concerns about cybersecurity for India's critical infrastructure, recalling a 2019 cyberattack on KKNP.
Detailed Insights:
The leaked documents, circulating on the dark web for nearly a month, include engineering drawings, inspection records, meeting minutes, and technical reports.
NPCIL clarified that the breach originated from a third-party contractor's server, specifically Reliance Infrastructure Limited, which was awarded the contract for conventional Balance of Plant facilities for Units 3 and 4.
The 2019 cyber incident at KKNP involved DTrack malware detected within the plant's administrative network.
This DTrack malware was attributed to the North Korea-backed Lazarus Group, known for targeting financial institutions and research centers.
The 2019 attack also reportedly affected the Indian Space Research Organisation (ISRO) and previously impacted an Indian private bank's ATM network in 2016.
NPCIL initially denied the 2019 attack but later confirmed an intrusion on an internet-connected administrative PC, isolated from the critical internal network.
The Computer Emergency Response Team-India (CERT-In), the national nodal agency for cybersecurity incidents, was involved in the investigation of the 2019 breach.
High-security setups like nuclear power plants often use "air-gapped" networks, which are physically isolated from external networks, though these are not considered foolproof.
Key Concepts Involved:
Ransomware: Malicious software that encrypts data or blocks access to it until a ransom is paid, often involving data exfiltration and public leaking.
Dark Web: A part of the internet that is not indexed by conventional search engines and requires specific software to access, often used for illicit activities.
Air-gapped networks: A security measure where a computer or network is physically isolated from unsecured networks, including the internet, to prevent unauthorized access.
Critical Infrastructure: Systems and assets, whether physical or virtual, so vital to a country that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety.