
India's rapid data centre expansion is creating a security blind spot, with facilities increasingly targeted by cyberattacks, physical disruptions, and geopolitical threats. A recent incident at the Kudankulam Nuclear Power Plant saw…
India's rapid data centre expansion is creating a security blind spot, with facilities increasingly targeted by cyberattacks, physical disruptions, and geopolitical threats. A recent incident at the Kudankulam Nuclear Power Plant saw nearly 19,000 files, including blueprints and supplier details, leaked on the dark web after ransomware group World Leaks claimed a breach via a contractor. Reliance Group said there was a 'partial breach' of data stored on a server hosted by Yotta Data Services, which isolated the affected server on May 29 and said only that single customer-managed server was impacted.

Data centres attracted $1.56 billion in foreign investment in the first half of 2026, driven by AI and cloud demand. According to Afcom's State of Data Centre 2026 report, human threats like insider attacks and external manipulation are the top concern, followed by ransomware, AI-powered identity attacks, and DDoS attacks. IBM's 2026 Cost of a Data Breach Report said the average cost of a breach in India reached Rs 25.5 crore, up 15.9% from Rs 22 crore in 2025. Operators must comply with the DPDP Act, Cert-In regulations, and the IT Act. Experts say contractual obligations increasingly define cybersecurity responsibilities between data centres and their customers.
India has over 130 operational data centres, with another 50+ under construction. The Kudankulam breach is not the first: in 2019, the plant's network was hit by a DDoS attack attributed to North Korean actors. The real gap is that India's data centre security standards remain voluntary, not mandatory. The Bureau of Indian Standards released a data centre security code of practice in 2023, but adoption is low. Customers in banking, insurance and government have the most at stake, as a single breach can trigger regulatory penalties under the DPDP Act and Cert-In reporting rules, plus class-action suits. Watch for whether the upcoming Digital India Act makes security standards compulsory for data centres.
Source: inc42.com
This story was synthesised by AI from the source linked above.