Rejected IIT applicant hacks institute websites, gets chance to prove cybersecurity skills
IIT Kanpur decided against immediate legal action and will assess the student's abilities, with a possible admission offer if he meets the required standards.
A student who was rejected for admission to the Indian Institute of Technology (IIT) Kanpur's newly launched bachelor's programme in cybersecurity hacked the official websites of IIT Kanpur and IIT Madras, claiming he only wanted "a fair chance".
Instead of immediately taking legal action, IIT Kanpur has decided to evaluate the student's cybersecurity skills and may consider him for admission in a future academic session if he successfully clears the assessment, reports NDTV.
The student had applied for IIT Kanpur's Bachelor of Cyber Security programme but was not shortlisted in the initial selection process.
Following the rejection, he gained unauthorised access to parts of the official websites of IIT Kanpur and IIT Madras. On the IIT Kanpur website, he left a message saying, "Site is hacked. All I need is just a fair chance."
The student later posted on X and Reddit, claiming that he did not intend to damage the websites and had only hacked them to demonstrate his technical abilities.
According to his posts, he completed all stages of the admission process, submitted the required documents and fees, and shared evidence of his cybersecurity-related work.
However, he was not shortlisted, preventing him from participating in the hackathon that was part of the admission process.
IIT Kanpur Director Manindra Agrawal said the student was not selected initially because he lacked prior cybersecurity experience. As the admission process for the current academic year has already concluded, the institute cannot offer him admission immediately.
However, Agrawal said the student would be invited to the campus for a formal assessment of his technical skills. If he demonstrates the required competence, IIT Kanpur will consider admitting him in the next academic session.
He also confirmed that the student had managed to access parts of the official websites of both IIT Kanpur and IIT Madras.
Agrawal said senior faculty members and engineers would meet with the student to explain that unauthorised access to computer systems is illegal and should not be repeated.
An IIT Kanpur official, speaking on condition of anonymity, said the institute had initially considered filing a First Information Report (FIR) against the student.
However, it later decided to verify his claims and assess his technical abilities before taking further action.
The decision reflects IIT Kanpur's efforts to encourage young cybersecurity talent.
Earlier this year, the institute's C3iHub cybersecurity centre offered an opportunity to a young individual who identified a security vulnerability in the Central Board of Secondary Education's online screen-marking portal.
