The modernization of industrial control systems (ICS) in critical infrastructures has created new vulnerabilities associated with coordinated cyber and physical attacks. Current modeling techniques for identifying these attacks at Nuclear Power Plants (NPPs) are either oversimplified or focused on cyber-only or physical-only attacks. The goal of this paper is to provide insights on simultaneous cyber and physical attacks at NPPs. An attack in which adversaries create a Small Break Loss of Coolant Accident (SBLOCA) while at the same time launching a false data injection attack to mimic normal data and prevent NPP shutdown is discussed. False data injection attack scenarios using NPP real-time process data are also provided.