CollegeUnify network Colleges & Universities Online & Distance Education
News Education, Exams, Results, Scholarships & Govt Jobs
IITs, IIMs & National Institutes

IIT Kanpur Admission Rejection Leads Student to Hack Websites

A student denied entry into IIT Kanpur's cybersecurity programme allegedly hacked multiple websites to demonstrate the very skills that the institute's admission process failed to recognise.

IIT Kanpur Admission Rejection Leads Student to Hack Websites

Key points

  • A student rejected from IIT Kanpur's cybersecurity programme allegedly hacked websites to prove his skills
  • The incident raises questions about whether IIT admission criteria adequately assess practical cybersecurity talent
  • Unauthorised hacking is a criminal offence under India's IT Act, 2000, regardless of intent
  • IIT Kanpur hosts C3iHub, one of India's premier national cybersecurity research centres
  • Experts suggest CTF competitions and bug bounty programmes as legal alternatives to showcase cybersecurity skills

Important details

Organisation IIT Kanpur
Official website https://www.iitk.ac.in

In a striking case that has sparked debate around how India's premier technical institutions assess cybersecurity talent, a student who was reportedly turned away from IIT Kanpur's cybersecurity programme went on to hack several websites — an act he claimed was intended to prove his technical competence.

What Happened?

The individual, whose identity has not been officially disclosed, was denied admission to IIT Kanpur's cybersecurity-related academic programme. Frustrated by the rejection, he allegedly compromised a number of websites as a demonstration of his hacking abilities, arguing that the conventional admission criteria failed to capture real-world skills in the cybersecurity domain.

The incident has drawn significant attention within India's academic and technology communities, raising pointed questions about whether standardised entrance benchmarks are adequate for evaluating candidates who wish to pursue specialised fields such as ethical hacking, penetration testing, and cyber defence.

IIT Kanpur's Cybersecurity Push

IIT Kanpur is widely regarded as one of India's leading institutions in the field of cybersecurity education and research. The institute houses the C3iHub — a national cybersecurity centre of excellence — and offers advanced programmes in information security. Admission to these programmes typically follows a rigorous academic screening process, including performance in examinations such as GATE or institute-specific tests.

Critics of the current system argue that practical, demonstrable skills — such as capturing flags in hacking competitions (CTFs), contributing to bug bounty programmes, or independent security research — are often not adequately weighted during selection procedures at top institutions.

Legal and Ethical Concerns

While the student's intent may have been to showcase his abilities, cybersecurity and legal experts have been quick to point out that unauthorised access to computer systems is a criminal offence under the Information Technology Act, 2000, regardless of the motivation behind it. Sections 43 and 66 of the IT Act prescribe penalties for hacking and data theft, which can include imprisonment and heavy fines.

Ethical hacking is only legal when performed with explicit written permission from the system owner, or within sanctioned environments such as bug bounty platforms and organised Capture the Flag competitions.

Broader Debate on Admission Criteria

This episode has reignited a long-standing conversation in Indian academia about whether elite institutions like the IITs and other top colleges in India need to evolve their admission frameworks for emerging technology disciplines. Several educators and industry professionals have suggested that for fields like cybersecurity, AI, and data science, portfolios, practical assessments, and participation in recognised competitions should complement — or in some cases replace — purely exam-based selection.

Students interested in cybersecurity admissions and related programmes at institutes of national importance can explore options and eligibility criteria on CollegeUnify.

What Students Should Know

  • Unauthorised hacking, regardless of intent, is illegal under the IT Act, 2000 in India.
  • Students passionate about cybersecurity can participate legally in CTF competitions, bug bounty programmes, and open-source security projects to build verifiable portfolios.
  • IIT Kanpur's C3iHub and similar centres periodically offer internships, research fellowships, and short-term programmes in cybersecurity.
  • GATE CS and other standardised tests remain the primary gateway for postgraduate admissions at IITs in technical disciplines.
  • Several IITs and NITs have begun introducing dedicated cybersecurity electives and M.Tech specialisations in recent years.

The matter is currently under scrutiny, and no official statement from IIT Kanpur regarding punitive or legal action against the student has been confirmed at the time of publishing. CollegeUnify will continue to follow developments in this case.

Frequently asked questions

Is hacking websites to prove your skills legal in India?
No. Unauthorised access to any computer system or website is illegal under Sections 43 and 66 of the Information Technology Act, 2000, and can attract imprisonment and fines, regardless of the intent.
What cybersecurity programmes does IIT Kanpur offer?
IIT Kanpur offers advanced courses and research opportunities in information security and cybersecurity, and houses C3iHub, a national centre of excellence for cybersecurity funded by the Department of Science and Technology.
How can students legally demonstrate cybersecurity skills for admissions?
Students can legally build verifiable skill portfolios through Capture the Flag (CTF) competitions, recognised bug bounty platforms like HackerOne or Bugcrowd, open-source security contributions, and industry certifications.
What is the usual admission process for cybersecurity programmes at IITs?
Admission to M.Tech or research programmes in cybersecurity-related fields at IITs typically requires a valid GATE score in Computer Science or Electronics, followed by an institute-level interview or written test.