Sentence 1 of 20
The ransomware attack against a contractor involved in the Kudankulam nuclear power project is concerning, even if nothing threatening the plant’s integrity was stolen.
Sentence Breakdown
Part 1
The ransomware attack against a contractor
The cyberattack using malicious software (that locks data for money) against a third-party company hired to do work
Part 2
involved in the Kudankulam nuclear power project
which is working on India’s Kudankulam nuclear energy plant
Part 3
is concerning,
is a cause for worry,
Part 4
even if nothing threatening the plant’s integrity was stolen.
even though no information that could harm the safety or physical/operational soundness of the plant was taken.
Sentence 2 of 20
In 2019, malware was found on the same facility’s administrative network, but the NPCIL maintained that the operational reactor network was unaffected.
Sentence Breakdown
Part 1
In 2019, malware was found
In the year 2019, harmful software was discovered
Part 2
on the same facility’s administrative network,
on the office and business computer network of the Kudankulam plant,
Part 3
but the NPCIL maintained
but the Nuclear Power Corporation of India insisted
Part 4
that the operational reactor network was unaffected.
that the systems controlling the nuclear reactor itself were not harmed or reached.
Sentence 3 of 20
The new incident extends the same theme.
Sentence Breakdown
Part 1
The new incident
The latest cybersecurity event (the ransomware attack)
Part 2
extends the same theme.
continues the same pattern (of cyberattacks happening at nuclear facilities).
Sentence 4 of 20
India’s breach disclosure regime is inconsistent and often plainly opaque.
Sentence Breakdown
Part 1
India’s breach disclosure regime
The system of laws and rules in India for reporting cyberattacks and data leaks
Part 2
is inconsistent and often plainly opaque.
is not regular (changes from case to case) and is often completely hidden from the public.
Sentence 5 of 20
Affected organisations tend to believe admitting a breach will damage public confidence, share prices, contracts, and invite regulatory scrutiny.
Sentence Breakdown
Part 1
Affected organisations tend to believe
Companies that are hacked usually think
Part 2
admitting a breach will damage public confidence, share prices, contracts,
confessing to a data leak will hurt trust from citizens, lower the value of their stocks, ruin business agreements,
Part 3
and invite regulatory scrutiny.
and attract strict investigations by government authorities.
Sentence 6 of 20
So, they tend to ease their language in public statements and avoid disclosure until compelled.
Sentence Breakdown
Part 1
So, they tend to ease their language
Therefore, they usually make their wording less serious or direct (softening the news)
Part 2
in public statements
in official announcements made to the news and public
Part 3
and avoid disclosure until compelled.
and do not reveal the details of the leak until they are forced to do so.
Sentence 7 of 20
Many organisations also lack mature incident response capabilities, not uncommonly because they treat cybersecurity as a matter of compliance rather than necessity.
Sentence Breakdown
Part 1
Many organisations also lack
A lot of companies also do not have
Part 2
mature incident response capabilities,
well-developed and effective systems to handle the aftermath of a cyberattack,
Part 3
not uncommonly because they treat cybersecurity
quite frequently because they view security of computer systems
Part 4
as a matter of compliance rather than necessity.
simply as a checkbox exercise to satisfy government rules rather than a vital necessity to protect data.
Sentence 8 of 20
So, assessing what data has been affected in the early stages of an attack becomes technically impossible.
Sentence Breakdown
Part 1
So, assessing what data has been affected
Therefore, finding out exactly what information was stolen or damaged
Part 2
in the early stages of an attack
at the beginning of a cyberattack
Part 3
becomes technically impossible.
becomes practically impossible due to technological limits or lack of proper tracking systems.
Sentence 9 of 20
According to public information, the facility’s core infrastructure is unaffected; instead, a group called ‘World Leaks’ mounted a ransomware attack compromising systems belonging to Reliance Infrastructure, one of the engineering contractors of Units 3 and 4.
Sentence Breakdown
Part 1
According to public information,
Based on what has been officially told to the public,
Part 2
the facility’s core infrastructure is unaffected;
the main operational parts of the nuclear plant (like the reactors) are safe and not hacked;
Part 3
instead, a group called ‘World Leaks’ mounted a ransomware attack
rather, a hacking collective known as ‘World Leaks’ launched a cyberattack demanding ransom
Part 4
compromising systems belonging to Reliance Infrastructure,
weakening security and accessing computers owned by Reliance Infrastructure,
Part 5
one of the engineering contractors of Units 3 and 4.
which is one of the third-party firms hired to build or manage reactor Units 3 and 4 of the plant.
Sentence 10 of 20
The data in the incident were hosted by Yotta Data Services, which said it detected suspicious activity on its servers on May 29.
Sentence Breakdown
Part 1
The data in the incident were hosted by Yotta Data Services,
The information involved in the leak was stored on the servers of Yotta Data Services,
Part 2
which said it detected suspicious activity
which stated that it spotted unusual and potentially harmful actions
Part 3
on its servers on May 29.
on its computer systems on May 29 (several weeks before the leak became public).
Sentence 11 of 20
According to open-source intelligence platform RansomLook, the data began appearing on World Leaks on June 11.
Sentence Breakdown
Part 1
According to open-source intelligence platform RansomLook,
Based on information from RansomLook, a website that tracks ransomware data leaks,
Part 2
the data began appearing
the stolen files started to show up
Part 3
on World Leaks on June 11.
on the ‘World Leaks’ hacking website on June 11.
Sentence 12 of 20
However, the NPCIL issued a formal clarification only on July 15, following widespread media reports.
Sentence Breakdown
Part 1
However, the NPCIL issued
However, the Nuclear Power Corporation of India released
Part 2
a formal clarification only on July 15,
an official explanation only on July 15 (more than a month after the data appeared online),
Part 3
following widespread media reports.
after many newspapers and television channels started reporting on the data leak.
Sentence 13 of 20
Some 14.3 GB of files have been released, including the layouts of ventilation systems, floor plans of an alleged “control room”, supplier and vendor lists, and insurance paperwork.
Sentence Breakdown
Part 1
Some 14.3 GB of files have been released,
About 14.3 gigabytes of computer files have been made public by the hackers,
Part 2
including the layouts of ventilation systems,
which contain the structural drawings of the air circulation and cooling systems,
Part 3
floor plans of an alleged “control room”,
architectural drawings of what is claimed to be a control room,
Part 4
supplier and vendor lists, and insurance paperwork.
names of companies that sell goods/services to the plant, and documents related to insurance.
Sentence 14 of 20
While the files have not been independently authenticated, the actors and their incentives merit a closer look.
Sentence Breakdown
Part 1
While the files have not been independently authenticated,
Even though the released documents have not been proven to be genuine by third-party experts,
Part 2
the actors and their incentives
the people behind the attack (the hackers) and their reasons or motivations
Part 3
merit a closer look.
deserve to be studied carefully.
Sentence 15 of 20
The NPCIL has said that the files only pertain to infrastructure beyond the facility’s nuclear island.
Sentence Breakdown
Part 1
The NPCIL has said
The Nuclear Power Corporation of India has stated
Part 2
that the files only pertain to infrastructure
that the leaked files only relate to supporting systems and buildings
Part 3
beyond the facility’s nuclear island.
outside the core area containing the nuclear reactor and safety systems.
Sentence 16 of 20
However, such information can still serve so-called intelligence preparation activities.
Sentence Breakdown
Part 1
However, such information can still serve
However, these types of documents can still be useful for
Part 2
so-called intelligence preparation activities.
what are known as planning actions to gather details before launching a future cyber or physical attack.
Sentence 17 of 20
India is the third-most breached country and has already brooked similar attacks against AIIMS Delhi, airlines, and State government portals.
Sentence Breakdown
Part 1
India is the third-most breached country
India ranks third globally in terms of the number of successful data leaks and cyber intrusions
Part 2
and has already brooked similar attacks
and has already suffered or tolerated comparable cyber intrusions
Part 3
against AIIMS Delhi, airlines, and State government portals.
targeting the premier medical institute AIIMS Delhi, airline networks, and government websites.
Sentence 18 of 20
In this milieu, the government has positioned Kudankulam as the centrepiece of India’s nuclear power ambitions.
Sentence Breakdown
Part 1
In this milieu,
In this environment or background context (of frequent cyberattacks),
Part 2
the government has positioned Kudankulam
the government has projected or placed Kudankulam
Part 3
as the centrepiece of India’s nuclear power ambitions.
as the most important part of India’s plans for nuclear energy expansion.
Sentence 19 of 20
As CERT-In is conducting an investigation and Reliance and Yotta have shared their findings with the government, CERT-In and NPCIL should also clarify the nature and authenticity of the files, whether data were exfiltrated before detection, and whether any credentials or supplier accounts have been exposed.
Sentence Breakdown
Part 1
As CERT-In is conducting an investigation
Since the Indian Computer Emergency Response Team is carrying out an inquiry
Part 2
and Reliance and Yotta have shared their findings with the government,
and the two companies, Reliance and Yotta, have given their analysis to the authorities,
Part 3
CERT-In and NPCIL should also clarify the nature and authenticity of the files,
CERT-In and the Nuclear Power Corporation of India must make clear what kinds of files were leaked and if they are genuine,
Part 4
whether data were exfiltrated before detection,
whether the information was stolen and transferred out of the system before the hack was discovered,
Part 5
and whether any credentials or supplier accounts have been exposed.
and whether any passwords, usernames, or vendor accounts have been revealed to the public.
Sentence 20 of 20
Radical transparency is impossible here but basic cyber-hygiene and proactive communication are non-negotiable.
Sentence Breakdown
Part 1
Radical transparency is impossible here
Complete and total openness (sharing every detail) is not possible in sensitive areas like nuclear energy
Part 2
but basic cyber-hygiene and proactive communication
but standard computer security safety practices and actively sharing information beforehand
Part 3
are non-negotiable.
are absolutely mandatory and must be done.