IIT Kanpur to test student instead of filing FIR after website hack
“All I Need Is Just a Fair Chance.”
That was the message left behind by a student after hacking the website of the Indian Institute of Technology (IIT) Kanpur, where he had failed to secure admission to the BTech Cyber Security programme.
Instead of immediately filing an FIR, however, the institute has decided to give the student an opportunity.
IIT Kanpur Director Manindra Agrawal said the institute is considering offering the student an internship at its C3iHub cybersecurity centre, while making it clear that hacking institutional systems is not an acceptable way to seek opportunities.
“The admissions process at IIT Kanpur had already been closed, and there were legal and procedural aspects involved. However, we did not want to jeopardise the future of the student, which is why we have decided to give him an opportunity and are considering him for an internship at C3iHub. He can aim for admission next year,” Agrawal told India Today TV.
The incident came to light after the student hacked the institute’s website and replaced part of it with the message: “Site is Hacked, All I Need Is Just a Fair Chance.”
Soon after, the student shared screenshots of the breach on social media platforms, including X and Reddit, claiming responsibility for the hack. He maintained that he never intended to damage IIT Kanpur’s systems and only wanted to demonstrate his cybersecurity skills after being denied admission.
The post quickly gained traction on Reddit and X, with users expressing sharply divided opinions. On Reddit, many commenters praised the applicant’s apparent technical expertise, with some saying the alleged hack itself was proof of the skills the cybersecurity programme sought to identify. Others, however, cautioned that bypassing institutional security systems crossed legal and ethical boundaries, irrespective of the applicant’s grievance, and argued that such actions should not be celebrated.
One Reddit user commented: “Crazy, bro can get great opportunities outside India. Sad that we are still stuck with reservations.”
While another said: “If I was the dean of these IIT, I better give this lad an opportunity rather than national shame.”
A third user, however, said: “Sadly a terrible move on his part. Now even if they are any to give him a chance they can’t because that makes this a precedent and every site will start getting hacked to prove a point.”
WHAT IIT KANPUR DIRECTOR SAYS
According to Agrawal, applicants to IIT Kanpur’s BTech Cybersecurity programme are already given multiple opportunities to showcase their technical abilities during the admission process, including through hackathons. The student, however, could not establish his capabilities during the selection process.
While institute officials initially considered registering an FIR over the cyberattack, IIT Kanpur later chose a different approach. Rather than pursuing immediate legal action, the institute decided to encourage the student’s talent while reinforcing that such actions cannot be justified.
“We want to send a message to other students that such actions are not the right way to seek opportunities,” Agrawal said.
INTERNSHIPS AND JOB OPPORTUNITIES
He added that IIT Kanpur welcomes skilled cybersecurity enthusiasts to share their CVs for internship or job opportunities at C3iHub, the institute’s cybersecurity technology and innovation hub.
“We welcome those with expertise in cybersecurity to share their CV with us and we will consider them for internship or job at C3iHub. Students should always follow the proper and lawful process to achieve their goals and avoid indulging in activities that may have serious consequences,” he said.
The episode has sparked debate over where institutions should draw the line between recognising exceptional technical talent and enforcing cybersecurity laws.
While many have praised IIT Kanpur’s decision to avoid jeopardising a young student’s future, the institute has also emphasised that ethical hacking and responsible disclosure – not unauthorised access – remain the only acceptable ways to demonstrate cybersecurity skills.
– Ends