Most people shrug their shoulders and decide to try next time when not being selected for an academic program, but an applicant to IIT Madras’ Cybersecurity course has done things a bit differently.
Screenshots circulating on Reddit show the homepage of IIT Madras’ SSP (Staff and Students) portal, ssp.iitm.ac.in, replaced with a message reading “Site is hacked :)”, followed by a note claiming that no harm was intended and that the defacement was meant purely to draw the attention of the administration and cybersecurity authorities. The portal is currently returning a 502 Bad Gateway error, and it isn’t clear whether that is a direct result of the alleged breach.


The message left on the page lays out a long, personal account from someone who says they applied to IIT Madras’ BCyber cybersecurity programme, paid the application fee, submitted documents, and included proof of prior work in the field, only to be left off the shortlist. The person claims they have been coding since the age of 13, that their parents disapproved of the time spent on it instead of exam preparation, and that this programme represented their best shot at pursuing cybersecurity professionally instead of going the conventional JEE route.
The hacker then goes on to question the shortlisting criteria itself, naming a selected candidate and comparing percentile and board exam scores, arguing that the selection wasn’t based on academic merit either. It also claims that eight seats in the programme were left vacant because shortlisted candidates couldn’t clear the hackathon round, with several apparently scoring under 15 out of 100, while the applicant says they were capable of breaching the servers of both IIT Kanpur and IIT Madras.
The individual says they had been emailing IIT Kanpur’s administration since the results were announced, reporting vulnerabilities they had found in the institute’s systems and asking for a review of their application, without receiving a response. They also mention an email from a faculty member proposing a call, which they replied to in order to schedule a time, but say they never heard back afterward.
What follows in the screenshots is a detailed list of alleged access obtained across both institutes’ systems. At IIT Kanpur, the hacker’s claims include arbitrary file read access to the Pingala server, the ability to view and refund payments from all 1,600 applicants, database credentials, an Axis Bank API key, and the source code of the Pingala platform, along with personal data and documents such as Aadhaar cards, birth certificates, JEE scores and cybersecurity evidence submitted by every applicant. At IIT Madras, the person claims root-level remote code execution on the SSP portal’s server, access to roughly three lakh documents belonging to students, faculty and staff, internal API keys, the SSP database, payment gateway keys for Easebuzz and the fee portal, the underlying source code, and credentials for the Zmail system used to send OTPs to users, along with the ability to take the site down entirely.
Toward the end of the post, the applicant asks why they weren’t shortlisted, ruling out percentile and board marks as explanations by pointing to a selected candidate’s scores, and says their own submission included a report on a payment bypass vulnerability found in an Indian e-commerce startup that allowed orders to be placed for one rupee. They mention two other candidates who were initially rejected but got added to the list later after directly reaching the director, and say they never received a similar response despite repeated attempts.
None of the claims made in the post have been independently verified, and IIT Madras has not put out a statement on the matter yet. The BCyber programme referenced in the post is a relatively new specialised undergraduate offering focused on cybersecurity, and admissions to such programmes typically involve a mix of academic cutoffs, an evaluation of prior work, and a hackathon-style selection round, though institutes rarely disclose the exact weightage given to each.
Whether this turns out to be a genuine breach with the scale described or an exaggerated attempt to force a response from the administration, it puts a spotlight on how premier institutes handle vulnerability disclosures from outside their official bug bounty channels, and how selection processes for niche technical programmes communicate, or fail to communicate, with applicants who don’t make the cut.