A student claimed to have hacked the websites of Indian Institute of Technology Kanpur (IIT Kanpur) and Indian Institute of Technology Madras (IIT Madras) after being denied admission to IIT Kanpur's newly introduced Bachelor of Cyber Security programme.
He may now receive another opportunity to prove his abilities.
According to Press Trust of India (PTI), IIT Kanpur is considering evaluating the student's technical skills rather than immediately pursuing legal action. The move comes after the student publicly claimed responsibility for the breach and said his intention was to demonstrate his cybersecurity capabilities.
The student allegedly left a message on the IIT Kanpur website stating: "Site is hacked. All I need is just a fair chance."
Social media posts brought the incident into the spotlight
The incident surfaced earlier this week after the student posted on X and Reddit, claiming he had gained access to sections of the websites of IIT Kanpur and IIT Madras following his rejection from the undergraduate cybersecurity programme.
According to his posts, he:
- Completed the admission application process.
- Paid the required application fee.
- Uploaded all mandatory documents.
- Submitted evidence of his cybersecurity work.
- Was not shortlisted for the next stage of the admission process, including the hackathon used for candidate evaluation.
The student said he did not intend to cause damage and instead wanted to showcase his technical abilities after missing out on an opportunity to participate in the selection process.
IIT Kanpur says admission is closed for this year
Speaking to PTI, IIT Kanpur Director Manindra Agrawal said the student had not been shortlisted because he lacked prior experience in cybersecurity.
He added that admissions for the current academic session have already concluded, making admission this year impossible.
However, Agrawal said the institute plans to invite the student to campus for a formal assessment of his technical capabilities.
According to Agrawal:
- The student will undergo a proper technical evaluation.
- If he demonstrates the required competence, IIT Kanpur will consider giving him an opportunity during the next admission cycle.
- The student did gain access to certain sections of the official websites of IIT Kanpur and IIT Madras.
Institute opts for counselling before legal action
Agrawal also said senior faculty members and engineers have been asked to meet the student and explain that unauthorised access to computer systems is illegal and should not be repeated.
According to PTI, an IIT Kanpur official, speaking on condition of anonymity, said the institute had initially considered filing an FIR. Instead, it decided to first verify the student's claims and evaluate his technical abilities before determining the next course of action.
A history of recognising cybersecurity talent
The case is not the first time IIT Kanpur has engaged with young cybersecurity researchers.
The anonymous institute official told PTI that earlier this year, IIT Kanpur offered a position at its C3iHub to a young individual who had identified security vulnerabilities in the CBSE online screen-marking portal.
The latest incident highlights the delicate balance educational institutions face between enforcing cybersecurity laws and identifying exceptional technical talent. While IIT Kanpur has made it clear that unauthorised system access is illegal, its decision to evaluate the student's capabilities signals an effort to separate technical aptitude from the method used to demonstrate it.
