The Haldia Naphtha Pipeline Fire: What We Know So Far

Last updated July 14, 2026
Satellite view of the Haldia Petrochemicals complex in West Bengal, India, site of the June 2026 naphtha pipeline fire, marked with a red circle

In June 2026, a naphtha pipeline caught fire at Haldia Petrochemicals Limited (HPL) in West Bengal, India. The fire did not move inward into the plant. It moved outward: into houses on the other side of the fence, onto a nearby railway, and onto a neighbouring company’s LPG line.

Reports put the injured at roughly 20 to more than 35, and the dead at somewhere between one and six. Both plant workers and residents were hurt.

No cause has been established, and nothing here is a root cause analysis. HPL’s preliminary statement points at an unauthorized naphtha theft point near the line, an illegal tap, and Reuters reports the fire happened at a place where naphtha has been stolen from before. That one detail puts the incident outside the boundary most functional safety engineers work inside.

What is Haldia Petrochemicals, and where does it sit?

HPL runs a naphtha-based petrochemical complex at Haldia, an industrial port town in West Bengal, in eastern India. The heart of the complex is a naphtha cracker: a furnace that heats naphtha with steam until the larger molecules break apart into smaller ones, mainly ethylene and propylene, the feedstock for plastics. It is rated at roughly 700,000 tonnes per year of ethylene.

The Haldia Petrochemicals complex in West Bengal, India, showing above-ground pipe racks of the kind involved in the 2026 naphtha pipeline fire
The Haldia Petrochemicals complex, photographed in 2018 — not an image of the June 2026 fire. Photo by খাঁ শুভেন্দু via Wikimedia Commons, CC BY-SA 4.0.

Haldia is a dense industrial port cluster. A refinery, an LPG import terminal, storage terminals, and the pipelines that move product between them all sit within a few square kilometres of each other, and houses sit directly against that infrastructure.

What is naphtha, and what is the hazard?

Naphtha is a liquid hydrocarbon mixture that boils in roughly the gasoline range and serves as the cracker’s feedstock.

Its flash point sits below normal ambient temperature, so it gives off an ignitable vapor with no heating at all. A puddle of it at room temperature is already producing fuel.

The vapor is denser than air. It settles at grade, runs downhill, spreads along the ground, and burns back to the source when it finds an ignition source. Even by the standards of the process industry, naphtha is a very dangerous substance.

What happened in June?

Reporting conflicts on the details, and the conflicts are worth naming rather than smoothing over.

Residents told local reporters they had been smelling naphtha since the night before. If that holds, the release ran for hours before it ignited.

Fire was first spotted on the naphtha pipeline in the small hours of the morning, preceded by an explosion residents heard from their homes. Accounts of the first alarm range from around 2:45 a.m. to around 4:30 a.m. The fire crossed the plant boundary into Chiranjibpur, the neighbourhood outside, destroying homes. It damaged overhead electrical equipment on a nearby railway line and suspended train services. The source was isolated early, but the fire could not be extinguished until the inventory left inside the pipeline burned itself out.

Casualty reporting is inconsistent. Injury counts run from roughly 20 to more than 35. Some outlets describe the injured as primarily factory workers, others as mostly local residents; two HPL security personnel are named among them. The death toll is reported anywhere from one to six.

How far the fire actually spread

The fire never significantly entered the process plant. HPL reported operations unaffected. It went outward instead, into houses, onto the railway, and onto the LPG line of the neighbouring IndianOil Petronas terminal (IPPL), a separate company operating an LPG import and bottling facility next door. HPL’s own statement says the pipe leakage spread to IPPL’s LPG line and hampered its services.

Flame impingement on an LPG line is the precursor condition for the worst outcome available at a site like this. It did not go. There is no report of a secondary release or explosion at IPPL.

That makes this a near-miss sitting inside an incident, and near-misses are the most instructive events in process safety precisely because the consequence did not arrive to distract from the mechanism.

For any reader with a fence line: a release on one operator’s asset can put flame on another operator’s inventory, and neither hazard study is likely to contain the other’s scenario.

What caused the release?

The reporting keeps collapsing two separate questions: what opened the line, and what lit it. They have different answers and different owners. Three accounts are in circulation, and only two of them are about the release.

An illegal tap

HPL’s preliminary statement identifies an unauthorized naphtha theft point near the line as the suspected location, and says it suspects the fire started while people were attempting to steal product by damaging the pipeline.

Reuters reports the fire occurred at a place where naphtha has been stolen from in the past, and HPL added that it has repeatedly warned local communities against unauthorized handling of petroleum products. Illegal tapping was a known, recurring condition at this location.

A thief wants product in a hose, not product on the ground. A fire means the tap was botched, or was never under control to begin with.

A mechanical leak or rupture

Police and several outlets describe a pipe leakage or rupture as the starting point, without reference to theft. This is the mechanical integrity story: corrosion, external damage, weld or flange failure, and the inspection program that should have caught it. It is the account that stands if the theft point turns out to be incidental to the release.

HPL’s own statement says the incident occurred due to a pipe leakage, and in the same breath says it suspects the fire started during an attempt to steal product by damaging the pipeline. On HPL’s telling, these are not two hypotheses. They are one hypothesis described from opposite ends.

Lightning was hypothesized, but it does not explain the release

The state fire service suggested early on that a lightning strike during heavy rain and thunderstorms may have started the fire.

Lightning is a credible ignition source for a flammable atmosphere. It is a poor explanation for the release, unless a release was already underway. It does not compete with the other two. A release from any cause, ignited by any source, produces the same fire.

How common are illegal taps?

Illegal tapping is unfortunately more common than people realize, and it is not a developing-world problem. Concawe, the European oil industry’s research body, has tracked spillages on European cross-country pipelines since 1971. Theft-related spillages numbered 28 across the entire period from 1971 to 2012. Then came 18 in 2013, 54 in 2014, and 87 in 2015. In 2016, 60 of the 66 recorded spillages were theft-related. In 2023, six of eight were. Enforcement has pushed the totals down since the peak, but in several recent years theft has caused the majority of all recorded spillages on European oil pipelines.

Method spans a wide range of skill, from a coupling welded onto the live line and drawn from quietly for years, down to an angle grinder or a metal spike. Every version is unpermitted hot work or mechanical breach on a live, pressurized hydrocarbon line. The illegal tap carries its own ignition source.

The crude end is where the fires come from. A well-made tap does not burn, it draws. A fire during the act, which is what HPL describes, points to the other end of the range, and Concawe records that thieves faced with a large leak commonly flee and leave the line open.

The consequences are on the record. A 2019 pipeline explosion in Mexico linked to fuel thieves killed more than 130 people. Haldia is not an outlier. It is a category.

A sophisticated example

Mexican fuel theft, run at industrial scale by organised crime, is the most heavily documented version of the problem. Authorities have found taps reached by tunnels dug toward Pemex lines, and taps installed in pairs.

One tap draws fuel out. The other pumps water in, holding the line pressure where the monitoring system expects to see it, so the pressure-drop alarm never fires. The thief is not evading the monitoring system. He is feeding it false data so it reports normal.

Buried lines and above-ground lines

Cross-country pipelines are buried as standard, and burial is partly a security measure in its own right: it puts the pipe out of reach and out of sight. Most illegal taps target buried lines anyway, and the theft starts with excavation.

Above-ground lines, common inside plants and terminals on racks and sleepers, are easier to reach and easier to see, which pushes the theft toward the crude end. No published data separates theft on buried lines from theft on above-ground lines, so treat the split as unquantified. What is not in doubt is that burial is not protection.

The pattern in India

In July 2026, Indian Oil Corporation found an illegal valve and a 40-foot buried offtake line spliced into a crude pipeline in Tonk district, Rajasthan. It was discovered only after engineers chased down an abnormal pressure drop that had been developing for weeks.

Was this a process safety failure?

Possibly, and it is hard to say without more information. What is more likely is that it was not a safety instrumented system (SIS) failure.

An illegal tap is not a process deviation

A safety instrumented function (SIF) detects a defined process condition crossing a defined limit and drives the process to a safe state. Someone cutting into a transfer line from the outside produces no such condition. Pressure barely moves, flow barely moves, and nothing crosses a trip point until the line is already open to atmosphere and the fire has started.

IEC 61511 draws this line in its own definitions. Human error is defined as action or inaction producing an inappropriate result, and the standard states plainly that malicious action is excluded from it.

The standard’s security requirements, in Clause 8.2.4, require a security risk assessment of the SIS itself. That covers threats to the instrumented system. It is not a physical security requirement for hydrocarbon pipework, and it does not reach an illegal tap.

The thief works below, or around, the detection threshold

Pipeline leak detection works mostly by mass balance: meter what goes into the line, meter what comes out, correct for the inventory in the pipe, and alarm when the numbers stop agreeing. The alarm threshold has to sit above flowmeter uncertainty, or the system alarms constantly on measurement noise.

A draw small enough to hide inside meter error is invisible to it. The water-injection trick goes further and holds the measured pressure where the system expects it.

Concawe found that automated leak detection was involved in detecting only about 15% of underground pipeline spillages across their full survey period, improving in recent years, while nearly half were first found by someone other than the operator, sometimes by the people who caused the leak. At Haldia, if the residents are right, the detection layer that worked was a human nose.

The illegal tap creates a hazardous area that was not planned for

Area classification under IEC 60079-10-1 is driven by sources of release. The body of a pipeline is a sealed pressure envelope: welded joints, no gaskets, no packing, no moving seals, nothing to leak from. The classified zones live at the fittings, where the openings are, and the long runs between them are unclassified, correctly so.

An illegal tap creates a source of release in an unclassified area. No Ex-rated equipment, no gas detection, no ignition-source control, because under any legitimate reading of the design there was nothing there to release.

Then the thief cuts, welds, or drives a spike at that point. The same hot work inside the fence would need a hot work permit, gas testing, isolation, and a fire watch. And a sophisticated illegal tap is not a one-night event: it stays in the line, a standing source of release in an area no drawing classifies and no gas detector watches.

The illegal tap did not defeat the protection. It relocated the hazard to a place the protection was never asked to look.

Diagram showing a pipeline where the classified hazardous area sits at the flange while an illegal tap creates a source of release in the unclassified welded run
Area classification follows sources of release. An illegal tap creates one in an area no drawing classifies and no gas detector watches.

So where should the protection have come from?

How the pipeline industry defends against illegal taps

The pipeline industry has a name for this threat: third party interference. It covers everything from a careless excavator operator to an organised theft gang. Functional safety literature barely mentions it. Pipeline literature is full of it.

Separation distance and land use planning. Passive, and it does not depend on anyone doing anything. It decides whether a pipeline fire stays an industrial event or becomes a housing fire. At Haldia the fire crossed the fence and burned homes.

Physical security and surveillance. Right-of-way patrol, fencing, access control, aerial and drone survey, community engagement. The only layer that stops an illegal tap before it exists.

Remotely operated shut-off valves. Sectionalising valves that shut in the source and bound the inventory available to feed a fire. The one instrumented layer in the set, and at Haldia it did its job.

Leak detection. API RP 1130 covers computational pipeline monitoring and API RP 1175 covers leak detection program management. Beyond mass balance, negative pressure wave detection listens for the rarefaction wave that travels back up the line at the speed of sound when a rupture opens. All of these alarm to an operator. None is a SIF.

Mechanical integrity. In-line inspection tools that run down the bore looking for metal loss, cathodic protection, wall thickness survey, right-of-way condition. These find the damage after the fact, and only if the illegal tap is metal and the tool can see it.

Table of pipeline protection layers against illegal taps showing which stop the tap and which a LOPA can credit
The layers most likely to have prevented Haldia are precisely the ones a LOPA cannot count.

Where the H&RA could have caught it

IEC 61511 Clause 8.2 requires the hazard and risk assessment (H&RA) to identify hazardous events, the sequences that lead to them, and the risk reduction required, which is where an initiating event like third party interference would sit. However, the same standard excludes malicious action from its definition of human error, and scopes its security requirement to the SIS itself. It is a tricky situation.

A known, recurring condition should be evaluated. Naphtha had been stolen from this location before, and HPL had been warning communities off the line.

None of which makes the analysis easy. Deliberate interference is a genuinely hard initiating event to carry. It is intelligent rather than random, so it does not respond to redundancy, and the frequency data a layer of protection analysis (LOPA) depends on does not exist for it in any usable form. An engineer trying to put a number on the tapping rate at this site would be guessing, and would know it.

What regulations apply?

Who regulates process safety in India?

The Factories Act 1948, amended after Bhopal to add Sections 41A through 41H, is the foundation. The Manufacture, Storage and Import of Hazardous Chemicals (MSIHC) Rules 1989, made under the Environment (Protection) Act 1986, carry the major-accident duties: safety reports, notification, on-site and off-site emergency plans, and accident reporting above threshold quantities.

Enforcement sits at state level, through the Chief Inspector of Factories or the Directorate of Industrial Safety and Health, which here means West Bengal. There is no single unified statute equivalent to OSHA PSM or COMAH.

Who regulates the pipeline?

The Petroleum and Explosives Safety Organisation (PESO) licenses petroleum installations under the Petroleum Act 1934 and the Petroleum Rules 2002. The Oil Industry Safety Directorate (OISD) publishes the sector’s technical safety standards and runs third-party audits. The Petroleum and Natural Gas Regulatory Board (PNGRB) sets the Technical Standards and Specifications including Safety Standards (T4S) for petroleum and petroleum product pipelines, which adopt ASME B31.4.

Whether this naphtha line falls under the pipeline regime or is treated as in-plant piping under the Factories Act has not been publicly established, and it determines who owns the finding.

Does India require functional safety and IEC 61511?

Not by a statute that names it, which is the same pattern seen in Qatar. IEC 61511 arrives through engineering standards, OISD standards, owner specifications, and procurement, as the recognized good engineering practice for a SIS rather than as a cited legal requirement.

The functional safety work at an Indian cracker looks like the functional safety work anywhere. What differs is who checks it and how the requirement reaches the engineer.

Who investigates an incident like this?

The illegal tap hypothesis makes this messy. If it was theft, it is a police matter, and a criminal investigation asks different questions than a process safety investigation. One wants to know who did it. The other wants to know why the site was exposed to it.

India has no independent national accident investigation board comparable to the US Chemical Safety Board, so findings are released at the discretion of the operator and the state, if at all. That is why incidents like this generate a great deal of news coverage and very little transferable learning.

What we do not know at the time of writing (July 2026)

  • Whether the release came from an illegal tap, a mechanical failure, or something else, and whether lightning played any role at all.
  • Whether an illegal tap was found, what it looked like, and how long it had been there.
  • Whether the line at the fire location was buried or above ground.
  • How long the release ran before it ignited, and whether anything other than a resident’s nose detected it.
  • The casualty count, which still varies widely across sources, and whether those hurt were mainly workers or mainly residents.
  • Whether third party interference appeared as an initiating event in HPL’s hazard study, and whether any investigation report will ever be published.

Frequently Asked Questions

I had never heard of illegal pipeline taps before this. How common are they, really?

Common enough that in several recent years they have caused most of the recorded spillages on European oil pipelines, which is not the answer most engineers expect. Concawe logged 28 theft-related spillages across the whole of 1971 to 2012, then 87 in 2015 alone and 60 out of 66 in 2016. Enforcement has knocked the peak down since, but Europe is the well-policed end of this problem, not the bad end. If your line runs through populated ground, assume someone has looked at it.

How should a functional safety engineer think about illegal taps?

Start by admitting there is no clean answer. IEC 61511 appears to exempt this, since it excludes malicious action from its definition of human error and scopes its security requirement to the SIS itself rather than to the pipework. That reading is debatable, and reasonable engineers argue it. Whether a HAZOP or a LOPA ought to carry deliberate interference at all is unsettled, and the frequency data you would need to do it properly does not exist.

What you can do is name the boundary out loud. Put third party interference on the table in the hazard study, say plainly that no SIF covers it, and record where the protection actually lives. That is worth more than letting everyone assume an instrumented function has it handled.

This fire could clearly have been far worse. Is that a process safety win?

To some extent, yes. Isolation worked. The source was shut in, so the fire burned down to the inventory already trapped in the line rather than being fed indefinitely. That is the difference between a bad night and a catastrophe, and it is worth saying out loud even while the rest of the picture looks poor.

If leak detection can’t take IPL credit, why do we bother having it?

Because it is not a prevention layer, it is a consequence-limiting one. Leak detection alarms to an operator, it does not act, so it does not clear the bar for an independent protection layer (IPL). What it does do is shorten the release duration, and release duration sets the size of the cloud, the size of the fire, and how far the fire reaches. A LOPA cannot count it. That has nothing to do with whether it is worth having. Do not confuse “no IPL credit” with “no value.”

How do I justify spending on right-of-way security when the LOPA can’t credit it?

This is the uncomfortable part. The layers most likely to have prevented Haldia are precisely the ones a LOPA cannot count: the patrols, the fence, the community engagement, the surveillance. A LOPA is a tool for allocating instrumented risk reduction, not a complete account of what keeps a plant safe, and treating it as the latter is how a site ends up defending against the hazards it can quantify instead of the ones it has.

Further Reading

From SIL Safe

External resources

News coverage of the Haldia fire:

Standards, data, and background:

Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.

Image credits: the satellite view of the Haldia complex contains modified Copernicus Sentinel data (2025), Sentinel-2 cloudless by EOX IT Services (CC BY 4.0), with labels © OpenStreetMap contributors. The photograph of the Haldia Petrochemicals complex is by খাঁ শুভেন্দু via Wikimedia Commons, licensed CC BY-SA 4.0; it shows the complex in 2018 and is not an image of the June 2026 fire.

✉︎ Get the next one in your inbox

The SIL Safe newsletter sends a couple of practical breakdowns like this a month.

Subscribe →

Leave the first comment