CBSE seeks hacker’s aid to fix security gaps

2. Why in the News

3. Background & Evolution

4. Core Static Facts

Item Detail
Portal affected On-Screen Marking (OSM) portal
Vendor/developer COEMPT Eduteck [S1]
Ethical hacker Nisarga Adhikary, age 19 [S1]
National cyber agency involved CERT-In (reported Feb 2026) [S5]
Academic institutions assisting IIT Madras, IIT Kanpur (Directors + expert teams) [S1]
Remediation period ~2 weeks from May 24, 2026 [S1]
Data exposed Scanned answer booklets, question papers, student marks, names, emails, phone numbers, evaluator PII [S3][S5]
Root cause Misconfigured AWS storage bucket; hardcoded master password in frontend JS; client-side OTP validation; password reset without original password verification [S3][S4][S5]
Ministerial oversight Ministry of Education (Union Minister Dharmendra Pradhan) [S4]
Large-scale attack date June 2, 2026 (1.5 million hits/2 min) [S5]

5. Multi-Dimensional Analysis

Scientific/Technological - Textbook case of OWASP-style vulnerabilities: hardcoded credentials, client-side authentication logic, insecure cloud (AWS S3) configuration. [S3][S4] - Highlights weak secure software development lifecycle (SSDLC) practices among government ed-tech vendors. [S1]

Governance/Ethical - CBSE's initial denial vs. eventual admission raises transparency and accountability concerns for a statutory education body. [S1] - Delayed CERT-In response (3+ months) exposes bottlenecks in India's vulnerability-disclosure and incident-response mechanism. [S5] - Reliance on an independent ethical hacker (responsible disclosure) rather than internal audit reflects gaps in institutional cyber-hygiene. [S1]

Legal/Constitutional - Exposure of student PII (marks, names, contact details) implicates the Digital Personal Data Protection (DPDP) Act, 2023 compliance obligations of data fiduciaries like CBSE. - Raises questions on right to privacy (post-Puttaswamy) as applied to minors' educational data.

Administrative - Demonstrates inter-institutional crisis response — CBSE (implementing body), Ministry of Education (oversight), IIT Madras/Kanpur (technical remediation), CERT-In (reporting channel). [S1][S4] - Vendor accountability gap: third-party developer (COEMPT Eduteck) built a portal with multiple critical flaws. [S1]

Social - Directly affects millions of CBSE students/evaluators whose personal and academic data was at risk during the 2026 board exam cycle. [S3][S5]

6. Recent Developments (last 12–18 months)

7. Prelims Hooks

8. Mains Relevance

9. Related Topics to Study Next

10. Common Errors / Trap Areas

11. Sources