Quick Facts
- Nisarga Adhikary, 19, hired by IIT Kanpur cyber hub C3iHub as OSINT and threat intelligence engineer.
- He flagged five critical flaws in CBSE’s On-Screen Marking portal in a May 22, 2026 blog post.
- IIT Kanpur director Manindra Agrawal reached out directly, calling him among the institute’s youngest hires.
In This Article
A teen hacker lands big IIT Kanpur job after exposing five security flaws in the CBSE exam marking portal, joining the institute’s cybersecurity hub C3iHub.
Nisarga Adhikary, a 19-year-old who sat his Class 12 board exams this year, has been appointed Open-Source Intelligence (OSINT) and Threat Intelligence Engineer at C3iHub, the cybersecurity Technology Innovation Hub at the Indian Institute of Technology (IIT) Kanpur. The job followed his public disclosure of weaknesses in the board’s digital exam system.
This hire flips the usual script. A board that first denied a 19-year-old’s findings now indirectly benefits from his skills, since IIT Kanpur works with CBSE on its systems. Parents and students should watch the trust question closely, because the same On-Screen Marking system grades the answer sheets that decide college seats and scholarships. The deeper signal for the 2026-27 cycle is simple: India’s institutions are now scouting cybersecurity talent young, and a verified disclosure can open a full-time research role faster than a degree can. By Dr. Mayank Raj.
What is the new IIT Kanpur job at C3iHub?
C3iHub is a cybersecurity Technology Innovation Hub at IIT Kanpur, funded by the Department of Science and Technology under the National Mission on Interdisciplinary Cyber-Physical Systems. Adhikary joined this week as an OSINT and Threat Intelligence Engineer, a role focused on tracking digital threats and weaknesses in computer systems.
IIT Kanpur director Manindra Agrawal reached out to Adhikary directly after the disclosure went public. Agrawal confirmed the hire to IIT Kanpur reporters, saying Adhikary is certainly among the youngest engineers the institute has hired. The director also made clear that Adhikary is on a full-time job, not enrolled as a student.
Adhikary was candid about the pay. He said the salary is decent but lower than he expected, since he is used to working with companies based in the United States and earning in dollars. He added that he is focused on building tools people use, rather than working inside academia.
About C3iHub, IIT Kanpur
C3iHub is a Technology Innovation Hub set up at IIT Kanpur in 2020, funded by the Department of Science and Technology, Government of India. It works on the cybersecurity of cyber-physical systems, detecting weaknesses, building security tools, and incubating start-ups. IIT Kanpur, established on November 2, 1959 by an Act of Parliament, hosts over 9,500 students and nearly 600 faculty across a 1,050-acre campus, per IIT Kanpur.
What CBSE flaws did the teen hacker find?
The On-Screen Marking (OSM) system is CBSE’s digital tool where examiners grade scanned answer sheets on a computer instead of on paper. CBSE rolled it out to streamline the long Class 12 evaluation process. Adhikary explored the portal’s publicly accessible code and found multiple serious weaknesses.
According to his blog post, the code contained a hardcoded master password sitting in plain text inside frontend files, not a hash or a token reference, per his disclosure. He claimed this password could bypass the One-Time Password (OTP) check and authentication flow entirely. He said it took him less than an hour to find the flaws, and that the access control was broken enough to let someone impersonate examiners and alter student marks.
Adhikary first hacked the portal in February 2026 and reported the issues to the Indian Computer Emergency Response Team (CERT-In), India’s cybersecurity watchdog. He said the team was unable to patch most of them, which pushed him to publish his findings on May 22, 2026. CBSE first denied the claims, then was eventually forced to accept them, as reported by The Quint and ThePrint.
What is Nisarga Adhikary’s background?
Nisarga Adhikary is a 19-year-old ethical hacker and cybersecurity researcher who appeared for his Class 12 board exams in 2026. His public profile shows he has pursued cybersecurity as a hobby since Class 6 and has worked as a software engineer.
Turn Your Achievements Into Stories That Students Actually Read
Feature admissions, placements, rankings, events, research initiatives, achievements, and institutional milestones before a highly engaged education-focused audience.
“We are always scouting for talent that can help us build a stronger cybersecurity wall,” IIT Kanpur director Manindra Agrawal said, explaining why he reached out, as reported by Times of India.
His profile lists software engineering internships at multiple places, including a Singapore-based company. He described cybersecurity as more of a hobby than his main field, and said he was excited to make the jump from software engineering into a full-time security role. For students and parents tracking how careers now form, his path shows verified skill can matter as much as a formal qualification.
What This Means For You
If you are a student
Skill can open doors early. Adhikary turned a documented, responsibly reported disclosure into a full-time research job at IIT Kanpur before finishing college. If you build real technical skills and report findings ethically through proper channels like CERT-In, you create a track record that institutions notice. Never test systems you have no permission to access.
If you are a parent
Your child’s exam marks pass through digital systems now. The OSM portal grades the scanned answer sheets that decide admissions and scholarships. You have the right to use re-evaluation and re-checking options offered by CBSE if marks look wrong, and to keep copies of your child’s scorecards for your records.
If you run a college or university
Digital exam and admission systems carry real security risk. This case shows that flaws in plain code can expose student data and grades. Audit any portal that handles marks or personal records, fix issues quickly when researchers report them, and treat ethical disclosures as help rather than a threat.
If you work in policy or media
This story sits at the meeting point of student privacy, exam integrity, and cybersecurity. The slow patching after a CERT-In report raises questions about how quickly government systems respond to disclosures. The vendor accountability angle around exam software is worth tracking through the rest of the 2026 exam cycle.
What Is Next
Adhikary now begins his work at C3iHub, while questions remain about whether he will be deployed on the board’s systems, which the director said depends on the future course of action. Watch for any official CBSE statement on patching the OSM portal and for how the privacy debate shapes the next exam season. Would you report a flaw you found, or stay quiet?
Frequently Asked Questions
Last updated: June 12, 2026 at 14:30 IST
Disclaimer: This article is for general informational purposes only and is based on publicly available information at the time of publishing. Exam dates, cutoffs, fees, deadlines, eligibility criteria, and scholarship details can change without notice. Always verify the latest information from the official portal of the relevant body (CBSE) before taking any action. CampusFeed and its authors are not responsible for decisions made based on this article. This is not legal, financial, or career advice. Please consult a qualified professional for individual guidance.
Written by Dr. Mayank Raj. Published: June 12, 2026. Updated: June 12, 2026. Have a tip or correction? Write to us at editorial@campusfeed.in.