The IIT Kanpur Website Hack has taken an unexpected turn after the institute decided to assess the technical skills of a student who allegedly breached parts of the IIT Kanpur and IIT Madras websites following his rejection from the newly launched undergraduate cybersecurity program. Instead of immediately pursuing legal action, IIT Kanpur said it would conduct a formal technical evaluation, though admission for the current academic session remains closed.
The incident of IIT Kanpur website hack came to light after the student shared posts on X and Reddit, claiming he had breached sections of the IIT Kanpur and IIT Madras websites after being rejected from the newly launched undergraduate cybersecurity program.
IIT Kanpur Website Hack Prompts Technical Skills Assessment
Along with screenshots of the alleged breach, he stated that his objective was not to damage the institutions but to prove his capabilities.
The student also left a message on the IIT Kanpur website that read, “Site is hacked. All I need is just a fair chance.” In his social media posts, he said he had completed the admission process by paying the required fees, submitting application forms and documents, and providing evidence of his work in cybersecurity.
However, he claimed he was not shortlisted for the hackathon, a key stage in the admission process for the IIT Kanpur cybersecurity program.
IIT Kanpur Offers Technical Assessment Instead of Legal Action
Speaking to PTI, IIT Kanpur Director Manindra Agrawal confirmed that the student had gained access to certain portions of the IIT Kanpur website. He explained that the applicant was not shortlisted because he lacked prior cybersecurity experience.

“The admission process for this academic session has already concluded, so admission is not possible now. However, we will invite the student to the institute, assess his technical skills through a proper test and, if he proves his competence, give him an opportunity in the next admission cycle,” Agrawal said.
Agrawal also confirmed that the student had accessed parts of both the IIT Kanpur and IIT Madras websites. He added that senior faculty members and engineers would meet the student to explain that unauthorized access to computer systems is illegal and should not be repeated.
IIT Kanpur Had Initially Considered Filing an FIR
According to another institute official, IIT Kanpur initially considered filing a First Information Report (FIR) over the breach. However, before taking any legal action, the institute decided to verify the student’s claims and independently assess his technical abilities.
The official, who spoke on the condition of anonymity, said IIT Kanpur has previously recognised young cybersecurity talent. Earlier this year, the institute offered a position at its C3iHub to a youth who identified vulnerabilities in the CBSE online screen-marking portal.
While the student’s actions have raised legal and ethical concerns for both IIT Kanpur and IIT Madras, the authorities have opted to focus on evaluating his skills through a structured assessment rather than immediately pursuing criminal proceedings.
Although he cannot join the current cybersecurity program, a successful technical evaluation could allow him to be considered during the next admission cycle.

