IIT-Kanpur has chosen to evaluate the technical skills of a rejected cybersecurity applicant who hacked its website, offering him a potential internship instead of an immediate FIR.

IIT-Kanpur Offers Skill Test to Applicant Who Hacked Website Following Admission Rejection

The420 Web Correspondent
4 Min Read

In an response to an unauthorized cyber intrusion, the Indian Institute of Technology Kanpur has decided against filing an immediate police complaint against an applicant who breached its official website after being rejected from its newly launched undergraduate cybersecurity programme. The student, who also claimed to have accessed systems at IIT Madras, left a message on the IIT Kanpur portal reading, “Site is hacked. All I need is just a fair chance,” before sharing screenshots on social media to demonstrate his technical proficiency.

Rather than initiating formal criminal proceedings, the institute has opted to evaluate the applicant’s technical capabilities through a formal skill assessment and is considering offering him an internship at its cybersecurity innovation hub, C3iHub. Institute authorities clarified that while admissions for the current academic session have concluded, a successful evaluation could open pathways for the candidate in the upcoming admission cycle.

Social Media Claims and Admission Dispute

The incident unfolded after the applicant posted detailed accounts and screenshots of the alleged system breaches across X and Reddit. The student asserted that he had completed the standard application process, paid the requisite registration fees, and submitted portfolio documentation of his past cybersecurity work. However, he was not shortlisted for the hackathon selection stage, effectively eliminating him from competing for a seat in the specialized degree programme.

Faced with rejection, the applicant attempted to demonstrate his practical capabilities by bypassing security controls on the institutional websites. In his online posts, the student maintained that his objective was strictly non-malicious, emphasizing that he did not alter underlying databases, extract sensitive personal records, or corrupt system files. His posts sparked widespread debate online, dividing commentators between those praising his technical ingenuity and those warning that breaching institutional infrastructure sets a dangerous legal precedent.

Institutional Response and C3iHub Internship Consideration

Explaining the rationale behind the rejection, IIT Kanpur Director Professor Manindra Agrawal stated that the applicant was not initially shortlisted because he failed to meet the baseline criteria for prior documented experience during the preliminary screening. He emphasized that because formal admissions for the current academic year have been finalized, immediate enrollment remains procedurally impossible regardless of the student’s technical demonstration.

However, recognizing the individual’s potential, Professor Agrawal announced that the institute would invite the candidate to the Kanpur campus for a comprehensive technical evaluation by senior faculty members and domain experts. If the applicant proves his competence during the controlled assessment, IIT Kanpur plans to offer him an internship position at C3iHub, the institute’s cybersecurity technology and innovation hub, while encouraging him to reapply through legitimate channels during the next academic cycle.

While opting for a constructive approach, institute authorities stressed that the gesture does not condone unauthorized system intrusion. Senior faculty and cybersecurity engineers have been tasked with counseling the student on the legal and ethical boundaries governing digital research, reinforcing that bypassing access controls constitutes a violation of IT laws regardless of motivation.

Institute officials reiterated that multiple legitimate avenues, including hackathons and open talent calls at C3iHub, exist for young researchers to showcase their expertise. By balancing talent development with strict ethical guidelines, IIT Kanpur aims to channel promising technical talent into legitimate cybersecurity careers while sending a clear signal that unauthorized hacking carries severe institutional and legal risks.

Stay Connected