Rejected for cybersecurity course, student hacks two IIT websites to prove his merit
RNA Media illustration for representation.
New Delhi: A student denied a seat in the newly launched Bachelor of Cyber Security programme at the Indian Institute of Technology, Kanpur, breached the websites of both IIT-Kanpur and IIT-Madras earlier this week after his application was turned down. Rather than pursue legal action, the institute has decided to test the young hacker’s technical abilities directly, with a possible route back into the admission process if he proves himself.
The episode came to light after the student posted screenshots on Reddit and X detailing how he had broken into the two institutional websites. On the IIT-Kanpur site, he reportedly left behind a message reading “site hacked, all I need is a fair chance” – a line that quickly circulated on social media and drew attention to the case.
According to his own account, he had completed every step of the application – paying the fee, uploading the required documents and submitting proof of prior cybersecurity work – but was still left out of the shortlist. That exclusion, he said, also cost him a place in the hackathon that forms part of the admission process for the course.
Second chance, not a free pass
The institute’s director, Manindra Agrawal, told PTI that the student had been excluded because he lacked prior formal experience in cybersecurity, not because of any flaw in his application. Agrawal, a computer scientist and Padma Shri awardee who has led IIT Kanpur since 2024, is himself a founding figure behind C3iHub, the institute’s dedicated cybersecurity innovation centre.
He added that this year’s admission cycle had already been completed, so the student could not simply be slotted in retroactively. Even so, he said the institute would call the student in, assess his technical skills through a formal test and, if he cleared it, consider him for the following year’s intake.
The decision not to press charges appears deliberate rather than lenient. Senior faculty and engineers at the institute are understood to have reviewed the intrusion before Agrawal’s statement, weighing the seriousness of an unauthorized breach against the possibility that the student’s claims about his skills were genuine.
This is not the first time IIT Kanpur has responded this way to an uninvited demonstration of technical skill. Earlier this year, a similar opportunity was extended to another individual who had flagged vulnerabilities in the CBSE’s online answer-script portal before being brought into C3iHub’s fold – a precedent that appears to have shaped how the institute chose to handle this latest case.
High-stakes course draws scrutiny
The Bachelor of Cyber Security programme itself is a new addition to IIT Kanpur’s undergraduate offerings, part of a broader expansion of cybersecurity education at the institute that already includes MTech and MS by Research tracks, some seats reserved for candidates sponsored by defence and other government agencies. The hackathon-style admission component – unusual for an undergraduate programme in India – was designed to test applied skill rather than examination scores alone, which may explain why a rejected but evidently capable applicant felt his abilities had gone unrecognized.
Whether the institute’s gamble pays off will depend on what the promised assessment turns up. For now, the case has reopened a familiar debate in Indian technical education on how to reward demonstrated skill without legitimizing the unauthorized means used to display it.