DPI Brief — July 16, 2026
1. Kudankulam Nuclear Plant Data Breach — Ransomware Hits Critical Infrastructure Contractor (L7: Trust)
Ransomware group World Leaks has posted a massive cache of files on the dark web related to India’s largest nuclear power plant at Kudankulam, Tamil Nadu. The leaked data includes purported blueprints of facility components and supplier details, which the group claims originated from Reliance Group — a contractor at the plant. Reliance confirmed a “partial breach” of data hosted on a server operated by Yotta, an Indian data centre service provider, and stated the government has been informed.
The Nuclear Power Corporation of India (NPCIL) confirmed it is communicating with Reliance about the breach, while CERT-In — India’s national cybersecurity agency — is investigating the incident. NPCIL has previously maintained that Kudankulam’s operational control systems are air-gapped from external networks, limiting the immediate safety implications. However, the breach of contractor data from a third-party data centre raises serious questions about supply chain cybersecurity in India’s critical infrastructure sector.
Source: Reuters, Insurance Journal
2. UPI Expands to Greece — Now Live in 10 Countries (L2: Payments)
NPCI International Payments Limited (NIPL) launched UPI services in Greece on June 30, 2026, through a partnership with Eurobank. This makes Greece the first European country to enable UPI-based inward remittances, allowing the Indian diaspora to send money home instantly. UPI is now accepted in 10 countries: Bhutan, Nepal, UAE, Singapore, France, Sri Lanka, Mauritius, Qatar, Cambodia, and Greece.
India’s payments infrastructure continues to process record volumes — 22.72 billion transactions in June 2026 alone. The RBI and NIPL are targeting expansion to 20 countries by FY 2028-29, with active engagements in Africa and South America. The Greece launch also opens the door for UPI acceptance at merchant locations, strengthening India’s position as a global digital payments leader.
Source: NPCIL / MyScheme, NPCI International
3. TRAI Seeks IT Act Powers to Regulate Caller ID Apps in Spam Fight (L7: Trust)
The Telecom Regulatory Authority of India (TRAI) has formally requested MeitY to designate it as an “authorised agency” under the IT Act, a move that would give it direct enforcement powers against caller identification platforms like Truecaller, Hiya, and Whoscall. The dispute centres on TRAI’s February 2025 amendments that created the 140 series for telemarketing and 1600 series for banking/financial service calls, with a directive that third-party apps must not block or tag these numbers as spam.
Truecaller’s CEO has publicly criticised TRAI’s rules, arguing they have worsened India’s spam problem by preventing apps from warning users about misuse of these designated number series. TRAI reports that over 51 million calls from the 140/1600 series have been flagged by users as spam, suggesting widespread misuse of the whitelisted channels. The regulator is also exploring partnerships with Meta (WhatsApp) and Google to integrate user-reported spam data with India’s DLT and DND systems. The regulatory turf war between TRAI and caller ID platforms highlights the growing complexity of governing digital communication infrastructure.
Source: MediaNama, Indian Express, CIOTechOutlook
4. India Unveils ₹62,500 Crore Mobile Phone Manufacturing Scheme (L4: Commerce / Digital Economy)
The government unveiled the Mobile Phone Manufacturing Scheme worth ₹625 billion (~$6.5 billion), a five-year programme to succeed the expiring PLI scheme. Incentives range from 2.25% to 5% of eligible sales, with an additional 1.5% for sourcing key components domestically. The scheme targets India’s growing smartphone manufacturing ecosystem — the country produced ~$60 billion worth of mobile phones in FY 2024-25, with exports surging 127-fold over the past decade to $21.7 billion.
The announcement comes alongside an expanded semiconductor push, as India positions itself as an alternative to China in global electronics supply chains. India currently accounts for 18% of global smartphone production versus China’s 63%. The new scheme explicitly links incentives to export performance and component localisation, signalling a shift from pure assembly to deeper value-chain integration.
Source: TechCrunch, Zee News
5. GeM Crosses ₹5 Lakh Crore GMV in FY 2025-26 — Digital Procurement Matures (L6: Governance)
The Government e-Marketplace (GeM) achieved a record gross merchandise value of over ₹5 lakh crore in FY 2025-26, pushing cumulative procurement past ₹18.4 lakh crore since its 2016 launch. The platform now hosts over 68,000 buyer organisations and more than 60 lakh sellers, including MSMEs, women-led enterprises, startups, and self-help groups.
GeM’s fully digital, cashless procurement model has become mandatory for most government purchases under the General Financial Rules 2017. The platform’s recent updates include enhanced cybersecurity measures, improved compliance features, and better vendor onboarding — reinforcing its role as a cornerstone of India’s digital governance infrastructure. The record volumes underscore how deeply digital procurement has penetrated India’s public sector.
Source: Clarity UPSC
Published by DPI Watch — Tracking India’s Digital Public Infrastructure, layer by layer.