IIT Madras and IIT Kanpur: Student Hacks IIT Kanpur Website After Rejection, Gets Technical Assessment

IIT Madras and IIT Kanpur: Student Hacks IIT Kanpur Website After Rejection, Gets Technical Assessment

IIT Kanpur Assesses Student Hacker’s Skills After Website Breach

A recent cybersecurity incident involving the IIT Kanpur and IIT Madras websites has taken an unusual turn after the institutes opted to evaluate the technical abilities of the student responsible rather than pursue immediate legal action. The breach came to light when the student, who was rejected from IIT Kanpur’s newly launched undergraduate cybersecurity program, posted details of the hack on X (formerly Twitter) and Reddit.

The student claimed he accessed parts of both institutions’ websites to demonstrate his skills, leaving a message on IIT Kanpur’s site stating, “Site is hacked. All I need is just a fair chance.” He argued that he had completed the admission process paying fees, submitting documents, and providing evidence of his cybersecurity work but was not shortlisted for a hackathon, a key stage in the program’s selection process.

IIT Kanpur Director Manindra Agrawal confirmed the breach, explaining that the student was excluded due to a lack of prior cybersecurity experience. While admission for the current academic year is closed, the institute plans to conduct a formal technical assessment of the student’s abilities. If he proves competent, he may be considered in the next admission cycle. Agrawal also noted that senior faculty would counsel the student on the legal and ethical implications of unauthorized access.

Initially, IIT Kanpur considered filing a First Information Report (FIR) but decided to verify the student’s claims first. This approach aligns with the institute’s past recognition of young cybersecurity talent earlier this year, IIT Kanpur offered a position at its C3iHub to a researcher who identified vulnerabilities in the CBSE online marking portal.

While the incident raises concerns about cybersecurity practices at premier institutions, IIT Kanpur’s response prioritizes skill evaluation over immediate legal consequences. The student’s actions, though unauthorized, may still open a pathway for future admission if his technical assessment is successful.

Source: https://thecyberexpress.com/iit-kanpur-website-hack/

IIT Kanpur cybersecurity rating report: https://www.rankiteo.com/company/iit-kanpur

Antaragni, IIT Kanpur cybersecurity rating report: https://www.rankiteo.com/company/antaragni-iit-kanpur

"id": "IITANT1785399889",
"linkid": "iit-kanpur, antaragni-iit-kanpur",
"type": "Breach",
"date": "1/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Education',
                        'location': 'Kanpur, India',
                        'name': 'IIT Kanpur',
                        'size': 'Large',
                        'type': 'Educational Institution'},
                       {'industry': 'Education',
                        'location': 'Chennai, India',
                        'name': 'IIT Madras',
                        'size': 'Large',
                        'type': 'Educational Institution'}],
 'attack_vector': 'Unknown',
 'description': 'A student rejected from IIT Kanpur’s undergraduate '
                'cybersecurity program hacked the websites of IIT Kanpur and '
                'IIT Madras to demonstrate his skills. The institutes opted to '
                'evaluate his technical abilities rather than pursue immediate '
                'legal action.',
 'impact': {'brand_reputation_impact': 'Potential reputational harm to IIT '
                                       'Kanpur and IIT Madras',
            'legal_liabilities': 'Considered but not pursued (FIR was '
                                 'initially considered)',
            'systems_affected': 'IIT Kanpur and IIT Madras websites'},
 'investigation_status': 'Ongoing (technical assessment of student)',
 'lessons_learned': 'Need for stronger cybersecurity practices in educational '
                    'institutions; potential benefits of evaluating young '
                    'cybersecurity talent before legal action.',
 'motivation': 'Demonstrate skills for admission consideration',
 'post_incident_analysis': {'corrective_actions': 'Formal technical assessment '
                                                  'of the student; potential '
                                                  'future admission '
                                                  'consideration; review of '
                                                  'cybersecurity practices.',
                            'root_causes': 'Potential vulnerabilities in IIT '
                                           'Kanpur and IIT Madras websites; '
                                           'lack of prior cybersecurity '
                                           'experience evaluation in admission '
                                           'process.'},
 'recommendations': 'Conduct formal technical assessments for rejected '
                    'applicants with demonstrated skills; enhance website '
                    'security; provide ethical hacking guidance to students.',
 'references': [{'source': 'News Article'}],
 'response': {'communication_strategy': 'Public statement by IIT Kanpur '
                                        'Director',
              'law_enforcement_notified': 'Considered but not pursued'},
 'stakeholder_advisories': 'Senior faculty to counsel the student on legal and '
                           'ethical implications.',
 'threat_actor': 'Student hacker (rejected applicant)',
 'title': 'IIT Kanpur and IIT Madras Website Breach by Rejected Student',
 'type': 'Unauthorized Access'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.