India's data centres attracted $1.56 Bn in foreign investment in H1 2026, yet face an average cost of ₹25.5 Cr per data breach. Rapid expansion for AI and cloud services has made these critical facilities prime targets for cyber, physical, and geopolitical threats. The recent Kudankulam nuclear plant contractor breach highlights growing risks to national security infrastructure.
How We Got Here
Data centres have evolved into critical infrastructure, powering AI and financial systems, driving the $1.56 Bn investment inflow. Last month, files allegedly linked to the Kudankulam Nuclear Power Plant surfaced after a ransomware attack on a contractor's server hosted by Yotta.
The Numbers
- Human threats, including insider attacks, are the biggest security concern per Afcom's State of Data Centre 2026 report.
- Ransomware, AI-powered identity attacks, and advanced persistent threats (APTs) are also cited as major risks.
- The Kudankulam-linked breach involved nearly 19,000 files, including facility blueprints, surfacing on the dark web.
- Yotta Data Services isolated the compromised customer-managed server on May 29 after detecting suspicious activity.
- Reliance Group confirmed a "partial breach" involving data stored on a server hosted by Yotta Data Services.
What Happens Next
🇮🇳 Why This Matters for India
For founders building B2B SaaS in Bangalore or Pune, relying on cloud providers, this raises immediate questions about their own liability and vendor due diligence.
The Take
The focus on massive foreign investment obscures the glaring lack of consistent security standards across India's data centre value chain. The real losers are SMEs in Hyderabad and Chennai who assume their data is safe, only to face huge financial and reputational costs for their vendors' vulnerabilities.
Source:
Inc42 ↗