Rejected by IIT Kanpur, Student Hacks Institute's Website; Gets Internship Offer Instead of FIR
In an extraordinary turn of events, a student who allegedly hacked the websites of IIT Kanpur and IIT Madras after failing to secure admission to IIT Kanpur's new Cyber Security programme may receive an internship opportunity instead of facing criminal charges. The institute has decided to assess his technical skills while warning that hacking is never an acceptable way to prove talent.
A remarkable case from Uttar Pradesh has sparked debate across India's technology and education sectors after a student who allegedly hacked the official websites of IIT Kanpur and IIT Madras following the rejection of his admission application was offered an opportunity to demonstrate his cybersecurity skills instead of immediately facing legal action.
The incident has become one of the most talked-about stories in the cybersecurity community because it raises important questions about identifying technical talent while maintaining the rule of law. While the student's actions were clearly unauthorized, IIT Kanpur has indicated that it does not want to jeopardize the future of a young individual who may possess exceptional cybersecurity abilities.
Admission Rejection Led to a Cyber Breach
According to reports, the student had applied for IIT Kanpur's newly launched Bachelor of Cyber Security programme. He claimed to have completed the application process, paid the required fees, submitted supporting documents, and provided evidence of his cybersecurity work.
However, he was not shortlisted for the next stage of the admission process. Frustrated by the rejection, the student allegedly gained unauthorized access to portions of the websites of IIT Kanpur and IIT Madras. He reportedly left a message on the IIT Kanpur website that read: "Site is hacked. All I need is just a fair chance." He later shared screenshots of the alleged breach on social media, claiming he intended to demonstrate his skills rather than cause damage.
Institute Chose Assessment Over Immediate Legal Action
Initially, IIT Kanpur considered filing a First Information Report (FIR) because unauthorized access to computer systems is a criminal offence under Indian law.
After reviewing the situation, however, institute officials decided to take a different approach. Instead of immediately pursuing criminal proceedings, IIT Kanpur announced that it would invite the student to the campus to evaluate his technical capabilities through a proper assessment.
If he demonstrates genuine cybersecurity expertise, the institute is considering offering him an internship opportunity at its cybersecurity research centre, C3iHub. Since admissions for the current academic session have already concluded, admission is not possible this year, but officials have indicated he may be encouraged to apply again in the next admission cycle.
Director Explains the Decision
IIT Kanpur Director Prof. Manindra Agrawal clarified that while the student's technical ability deserves evaluation, the method he adopted cannot be justified.
He explained that the admissions process had already been completed according to established procedures, making admission impossible for the current session. At the same time, the institute did not want to permanently damage the student's future if he genuinely possessed advanced cybersecurity skills.
The institute also plans to counsel the student regarding ethical hacking, responsible disclosure, and the legal consequences of unauthorized access to digital systems.
Why Was He Not Selected?
According to IIT Kanpur, applicants to the new Bachelor of Cyber Security programme undergo multiple stages of evaluation. Besides academic qualifications, candidates must demonstrate prior cybersecurity work and participate in an in-person assessment, including a hackathon.
Institute officials stated that the student was not shortlisted during the selection process based on the programme's admission criteria rather than any personal bias.
Ethical Hacking vs Illegal Hacking
The case has reignited discussion about the distinction between ethical hacking and cybercrime.
Ethical hackers work only with authorization. They identify security vulnerabilities after receiving permission from organizations and responsibly disclose weaknesses so they can be fixed.
In contrast, accessing websites, servers, or computer systems without permission—even if no data is stolen or destroyed—remains illegal in most jurisdictions. Cybersecurity experts stress that technical brilliance does not exempt individuals from legal or ethical responsibilities.
Many professionals argue that talented young hackers should participate in bug bounty programmes, capture-the-flag competitions, internships, and responsible disclosure initiatives rather than attempting unauthorized intrusions.
A History of Encouraging Talent
IIT Kanpur has previously demonstrated its willingness to encourage promising cybersecurity talent through legitimate channels.
Officials noted that the institute has, in the past, recognized young researchers and security enthusiasts who responsibly identified vulnerabilities and contributed positively to cybersecurity research.
The present case, however, differs because it involves unauthorized access, making it necessary for the institute to balance encouragement of talent with respect for cybersecurity laws.
Reactions from the Tech Community
The incident has generated mixed reactions online.
Some cybersecurity professionals believe IIT Kanpur has shown maturity by recognizing technical ability while emphasizing ethics and legal compliance. They argue that mentorship may help redirect exceptional talent toward constructive research.
Others caution that institutions must avoid creating the impression that hacking official systems could become a pathway to internships or employment. They stress that organizations should consistently promote responsible disclosure and lawful cybersecurity practices.
Lessons for Students
The case offers important lessons for aspiring cybersecurity professionals.
Demonstrating technical skills through authorized penetration testing, cybersecurity competitions, open-source contributions, internships, and bug bounty programmes provides legitimate opportunities to build a professional reputation.
Experts advise students never to access systems without permission, regardless of their intentions. Even actions performed "to prove a point" can have serious legal consequences and damage future career prospects.
Looking Ahead
The student is expected to undergo an assessment by IIT Kanpur's cybersecurity experts. Based on the outcome, the institute will decide whether he qualifies for an internship or other learning opportunities.
At the same time, IIT Kanpur has made it clear that unauthorized cyber intrusions remain unacceptable and should never be viewed as an acceptable route to academic or professional recognition.
The unusual episode highlights both the growing demand for cybersecurity talent and the importance of ethical conduct in the digital age. It demonstrates that while institutions may choose to nurture exceptional ability, technical excellence must always be accompanied by responsibility, integrity, and respect for the law.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0