Visualização de leitura

Student Hacks IIT Kanpur Website After Rejection, Gets Technical Assessment

IIT Kanpur Website Hack

The IIT Kanpur Website Hack has taken an unexpected turn after the institute decided to assess the technical skills of a student who allegedly breached parts of the IIT Kanpur and IIT Madras websites following his rejection from the newly launched undergraduate cybersecurity program. Instead of immediately pursuing legal action, IIT Kanpur said it would conduct a formal technical evaluation, though admission for the current academic session remains closed. The incident of IIT Kanpur website hack came to light after the student shared posts on X and Reddit, claiming he had breached sections of the IIT Kanpur and IIT Madras websites after being rejected from the newly launched undergraduate cybersecurity program.

IIT Kanpur Website Hack Prompts Technical Skills Assessment

Along with screenshots of the alleged breach, he stated that his objective was not to damage the institutions but to prove his capabilities. The student also left a message on the IIT Kanpur website that read, "Site is hacked. All I need is just a fair chance." In his social media posts, he said he had completed the admission process by paying the required fees, submitting application forms and documents, and providing evidence of his work in cybersecurity. However, he claimed he was not shortlisted for the hackathon, a key stage in the admission process for the IIT Kanpur cybersecurity program.

IIT Kanpur Offers Technical Assessment Instead of Legal Action 

Speaking to PTI, IIT Kanpur Director Manindra Agrawal confirmed that the student had gained access to certain portions of the IIT Kanpur website. He explained that the applicant was not shortlisted because he lacked prior cybersecurity experience.  "The admission process for this academic session has already concluded, so admission is not possible now. However, we will invite the student to the institute, assess his technical skills through a proper test and, if he proves his competence, give him an opportunity in the next admission cycle," Agrawal said.  Agrawal also confirmed that the student had accessed parts of both the IIT Kanpur and IIT Madras websites. He added that senior faculty members and engineers would meet the student to explain that unauthorized access to computer systems is illegal and should not be repeated. 

IIT Kanpur Had Initially Considered Filing an FIR 

According to another institute official, IIT Kanpur initially considered filing a First Information Report (FIR) over the breach. However, before taking any legal action, the institute decided to verify the student's claims and independently assess his technical abilities. The official, who spoke on the condition of anonymity, said IIT Kanpur has previously recognised young cybersecurity talent. Earlier this year, the institute offered a position at its C3iHub to a youth who identified vulnerabilities in the CBSE online screen-marking portal. While the student's actions have raised legal and ethical concerns for both IIT Kanpur and IIT Madras, the authorities have opted to focus on evaluating his skills through a structured assessment rather than immediately pursuing criminal proceedings. Although he cannot join the current cybersecurity program, a successful technical evaluation could allow him to be considered during the next admission cycle. 

South Korea Military Faces Highest Cyberattack Volume Since 2021

Cyberattacks on South Korea military

Cyberattacks on South Korea military reached their highest level in five years in 2025, highlighting growing cybersecurity risks as the Ministry of National Defense struggles to retain trained cyber specialists. The rise in attacks, coupled with phishing emails and concerns over North Korea’s expanding cyber capabilities, has intensified calls for stronger defense measures.  According to data submitted by the Ministry of National Defense to Rep. Yu Yong-weon of the main opposition People Power Party and a member of the National Assembly’s National Defense Committee, cyberattacks on South Korea military systems declined from 11,700 cases in 2021 to 9,115 in 2022 before increasing to 13,599 in 2023 and 14,419 in 2024. Last year, the number surged to 18,951, representing a 108 percent increase from 2022 and a 31 percent rise compared with 2024, making it the highest annual total in the past five years. 

Cyberattacks on South Korea Military

Most cyberattacks on South Korea military networks involved attempts to gain administrator privileges and compromise military websites, accounting for 18,792 incidents in 2025. Meanwhile, phishing emails disguised as messages from trusted senders rose sharply from just 16 cases in 2023 to 127 last year, indicating that cyberattack methods have become increasingly diverse. “Recent signs indicate that North Korea has begun using AI in its hacking operations, including malware development and attempts to infiltrate organizations through fake job applications, which allude to its cyber capabilities’ increasing sophistication,” the Cyber Operations Command said in materials submitted to Yu’s office.  The concerns come as North Korea is expected to strengthen cyber operations by expanding its Reconnaissance General Bureau, while South Korea’s Defense Counterintelligence Command has been effectively dismantled. 

Ministry of National Defense Faces Cyber Workforce Challenges 

Despite rising cyberattacks on South Korea military infrastructure, the Ministry of National Defense continues to face difficulties retaining cybersecurity personnel. Since 2012, the ministry has operated a cyber officer cadet program that provides approximately 40 million won (US$26,700) in tuition support to students in designated university departments. Graduates are commissioned as officers and assigned to units including the Cyber Operations Command and the 777 Command, where they conduct cyber threat analysis, cybersecurity operations, and digital forensics.  However, data obtained by Yu’s office shows that 89 of the 104 cyber specialist officers commissioned between 2016 and 2019—around 85 percent—left in the military after completing their mandatory seven-year service. Last year, only seven of 24 graduates accepted commissions. Although those declining military service members must repay their financial assistance, some have chosen that option instead, largely due to stronger demand, higher salaries, and better working conditions in the private AI and cybersecurity sectors. 

Growing North Korean Cyber Threat 

North Korean leader Kim Jong-un recently ordered the expansion of the Reconnaissance General Bureau, the country's primary intelligence agency responsible for overseas intelligence gathering, operations targeting South Korea, and cyber activities. During an expanded meeting of the Central Military Commission of the ruling Workers’ Party, reported by the state-run Rodong Sinmun, officials proposed expanding the bureau’s responsibilities and strengthening its reconnaissance and intelligence capabilities.  Created by reorganizing the former Reconnaissance Bureau under the Korean People’s Army General Staff, the agency is believed by South Korean military intelligence to oversee around 8,400 hackers. Analysts expect that number to increase following Kim’s directive.  “At a time when North Korea is rapidly advancing its cyberattack capabilities, we cannot allow a system in which cyber specialists simply leave the military after fulfilling their mandatory service,” Rep. Yu said. “We need a systematic personnel management system that covers the recruitment, training and long-term retention of cyber experts.” 

Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure

Iranian hacker

An alleged Iranian hacker accused of hacking US infrastructure has been arrested in Montenegro following a joint operation by Montenegrin police and the U.S. Federal Bureau of Investigation (FBI). The suspect is expected to face charges related to computer fraud, hacking, conspiracy, and identity theft after authorities linked him to a years-long cyber campaign that reportedly caused more than $3.4 billion in damages. 

Iranian Hacker Faces Computer Fraud and Hacking Charges 

The 39-year-old suspect, who holds dual Iranian and Turkish citizenship, was arrested in the Adriatic coastal town of Kotor, Montenegro. According to local police, he is wanted by the Southern District Court of New York on charges of conspiracy to commit computer fraud, hacking, and identity theft.  The case will now be referred to a High Court judge in Montenegro's capital, Podgorica, where extradition proceedings are expected to begin. 

Alleged Cyberattack on USA Universities Caused Billions in Damage 

In an official statement, Montenegro's police directorate alleged that the Iranian hacker had been involved in large-scale hacking operations since 2013.  "From 2013 onward, … he carried out massive hacking attacks … targeting more than 150 universities in the United States, causing damage estimated at over $3.4 billion," the statement said.  Authorities claim the stolen data and access to compromised university accounts were used to benefit Iran's Islamic Revolutionary Guard Corps (IRGC) and other Iranian organizations, including universities. Investigators allege the campaign formed part of a broader cyberattack on USA institutions aimed at acquiring sensitive academic data and digital access. 

Extradition Process Underway 

Following the arrest, Montenegrin authorities confirmed that the suspect remains in custody while legal proceedings continue. If approved, he will be extradited to the United States to face charges tied to computer fraud, identity theft, and extensive hacking operations.  The FBI participated in the investigation that led to the arrest, although the agency was not immediately available for comment after the announcement. 

Iranian Cyber Operations Remain Under Scrutiny 

The latest arrest comes amid continued concerns over Iranian-linked cyber activity. Iran and the IRGC have long been associated with state-sponsored cyber operations targeting U.S. organizations and infrastructure.  In April, U.S. cybersecurity, intelligence, and law enforcement agencies warned that Iranian hacking campaigns targeting equipment across critical U.S. infrastructure had intensified. The warning highlighted an increase in attempted intrusions, reinforcing concerns over future cyberattacks on the USA.  The arrest marks a new development in an international investigation into one of the largest alleged cybercrime cases involving an Iranian hacker, with prosecutors pursuing charges that include conspiracy, computer fraud, hacking, and identity theft linked to billions of dollars in reported losses. 
❌