Key Takeaways
- An applicant who was rejected from IIT‑Kanpur’s new Bachelor of Cyber Security program hacked the institute’s website (and IIT Madras’s) to showcase his abilities.
- The student left a message stating, “Site is hacked. All I need is just a fair chance,” and shared proof of the intrusion on social media.
- IIT‑K officials confirmed the breach, stated the denial was due to lack of prior cyber‑security experience, and said admission for the current cycle is closed.
- Instead of pursuing legal action, the institute plans to invite the student for a formal skills assessment; strong performance could earn him a place in the next admission cycle.
- Faculty and senior engineers will counsel the student that unauthorised system access is illegal and must not be repeated.
- IIT‑K has a precedent of rewarding vulnerability discoverers, having offered a position at its C3iHub to a youth who found flaws in CBSE’s online screen‑marking portal.
Background of the Incident
The controversy began when a prospective undergraduate applied to IIT‑Kanpur’s newly launched Bachelor of Cyber Security (B.C.S.) programme for the academic year 2024‑25. After completing the online application, paying the prescribed fee, uploading all required documents, and submitting evidence of his prior cyber‑security work, the applicant received a rejection notice. According to his own statements, the decision left him feeling unfairly treated, especially because he believed his qualifications matched the programme’s expectations. The denial prompted him to take an unconventional route to prove his competence: he accessed the institute’s public‑facing websites without authorization.
Student’s Claims and Motivation
In a series of posts on X (formerly Twitter) and Reddit, the student described his actions as a demonstration of skill rather than an attempt to cause damage. He alleged that he breached both the IIT‑Kanpur and IIT Madras websites, capturing screenshots of the altered pages and leaving a plain‑text message that read, “Site is hacked. All I need is just a fair chance.” By publicising the intrusion, he aimed to draw attention to his technical abilities and to argue that the admission committee had overlooked his talent. He stressed that his motive was not malicious—no data was exfiltrated, no services were disrupted—but rather to secure a reconsideration of his application.
Evidence Shared Online
To substantiate his claims, the student posted screenshots showing administrative panels, server directories, and modified homepage banners on the IIT domains. The images displayed timestamps and URLs that appeared to corroborate his narrative of having gained access to certain sections of the sites. While the screenshots circulated widely, they also raised questions about the extent of the breach: whether the student had merely defaced a public page or had penetrated deeper into the institute’s internal networks. IIT‑K officials later confirmed that the intrusion was limited to publicly accessible sections, but they did not disclose the exact depth of access to protect ongoing security investigations.
IIT‑Kanpur’s Official Response
IIT‑Kanpur Director Professor Manindra Agrawal addressed the matter in a press interview with PTI, acknowledging that the student had indeed accessed parts of the institute’s website. He clarified that the rejection was based on the applicant’s lack of prior cyber‑security experience, a criterion explicitly stated in the admission brochure for the B.C.S. programme. Agrawal noted that the admission process for the current academic session had already concluded, making immediate enrollment impossible. However, he announced an alternative pathway: the institute would invite the student to campus for a formal technical evaluation. If the assessment demonstrated sufficient competence, the student could be considered for admission in the next cycle.
Institutional Counseling and Legal Considerations
Recognising the legal implications of unauthorised computer access, IIT‑K senior faculty members and network engineers were tasked with meeting the student to counsel him on cyber‑ethics and the law. The institute emphasized that, regardless of intent, breaking into a system without permission violates the Information Technology Act, 2000, and could attract criminal charges. The counseling sessions aimed to redirect the student’s enthusiasm toward legitimate avenues such as bug‑bounty programmes, capture‑the‑flag contests, and authorized penetration‑testing projects. An unnamed IIT‑K official revealed that the administration had initially contemplated filing a First Information Report (FIR) but decided first to verify the student’s claims and assess his skill set before proceeding with any legal action.
Proposed Skills Assessment Process
The proposed evaluation will consist of a supervised, hands‑on test administered by the institute’s cybersecurity faculty. Components are likely to include: (1) a written examination covering core concepts such as cryptography, network security, and secure software development; (2) a practical lab where the candidate must identify and remediate vulnerabilities in a controlled environment; and (3) an interview discussing previous projects, problem‑solving approach, and ethical stance on hacking. Successful performance would not guarantee immediate admission but would create a strong case for the student’s inclusion in the forthcoming admission pool, potentially with a waiver of certain prerequisite experience requirements.
Precedent of Encouraging Talent
IIT‑Kanpur’s response aligns with its historical approach to nurturing young cybersecurity talent. Earlier in 2024, the institute offered a research position at its C3iHub (Centre for Cyber Security, Cyber Defence and Information Assurance) to a teenager who had responsibly disclosed vulnerabilities in the Central Board of Secondary Education’s (CBSE) online screen‑marking portal. That incident was handled through a coordinated disclosure process, resulting in a reward, public acknowledgement, and an employment offer rather than punitive measures. The current situation mirrors that philosophy: the institute seeks to transform a potentially adversarial act into an opportunity for mentorship and recruitment, provided the individual demonstrates both capability and respect for legal boundaries.
Ethical and Legal Implications for Aspiring Hackers
The episode serves as a cautionary tale for aspiring security enthusiasts. While curiosity and skill are valuable assets in cybersecurity, the means by which one exhibits those abilities must remain within legal and ethical frameworks. Unauthorised access, even when motivated by a desire for fair consideration, constitutes a criminal offense and can jeopardise future educational and career prospects. Institutions like IIT‑K are increasingly offering structured channels—such as bug‑bounty programmes, hackathons, and responsible disclosure policies—for talent to showcase their abilities safely. Prospective students are encouraged to utilise these avenues rather than resorting to illicit methods, thereby preserving both their integrity and the trust of the organisations they wish to join.
Conclusion and Outlook
IIT‑Kanpur’s decision to assess the student’s technical skills rather than immediately pursue legal action reflects a balanced approach that acknowledges both the need to uphold cyber‑law and the value of nurturing genuine talent. If the student passes the forthcoming evaluation, he may secure a place in the next B.C.S. cohort, turning a controversial episode into a constructive learning experience. For the broader cybersecurity community, the case underscores the importance of providing clear, legitimate pathways for skill demonstration and the role of educational institutions in guiding enthusiastic individuals toward ethical, productive careers in information security.

