You already know government websites crash, it's a running joke by now. What you don't know is that the same broken machinery that ruins your Tatkal booking just left 2 million students' exam data sitting open on the internet, and nobody who built it will actually pay for it.
Brajesh Mishra
A 19-year-old reported a critical CBSE vulnerability to CERT-In in February 2026. Three months of silence followed, so he hacked in himself to prove it, exposing 2 million students' answer sheets with no password required. CBSE denied it on camera, then admitted it days later. The vendor's contract had no clause allowing it to be blacklisted. Two officials were transferred, not fired. This is the same lowest-bidder tender system behind every IRCTC Tatkal crash — just with catastrophically higher stakes.
Picture this, it's results day, and you're refreshing a portal your child has been dreading for a year, like clockwork, and the page won't load. You refresh again, and it's a server timeout. This is, sadly, the same story with every other government website in India, be it a Tatkal ticket, a tax deadline, or a visa form.
We already know this story, we've lived it enough times to joke about it, but what nobody tells you is why it keeps happening, and more importantly, what it would actually take to fix it.
And usually, that's where the story ends, a bad afternoon, a missed booking, a meme or a tweet by evening, except this year it didn't end there, because in February 2026, a 19-year-old cybersecurity researcher named Nisarga Adhikary found something on CBSE's evaluation portal that was never supposed to be his to find, a way in that let him access the scanned answer sheets of examiners handling Class 12 board exams, and he did what you're supposed to do when you find something like that, he reported it, in writing, to CERT-In, India's own national cybersecurity agency, and he followed up more than once, and for three months, all he got back was silence.
So he did the only thing left to do, he broke in himself, not to take anything, but to force the country to actually look, and what was sitting there in the open, no password, no login screen required, was the academic record of over 2 million students, and when this finally became public, CBSE's first response wasn't to fix it, it was to deny it, on camera, even after the proof was already circulating for anyone to see.
When Adhikary went public on May 22, having waited long enough for silence to become its own answer, he didn't stop at one disclosure, within a week he'd found his way into a second subdomain too, describing what he called super admin access, this time surfacing data tied to university-level evaluations as well, and still, a CBSE regional official told reporters, on the record, that none of this was true, that exams were being conducted offline so there was, in his words, no question of any website being hacked, a statement made after the screenshots were already public knowledge.
It took six more days for CBSE to finally reverse course, admitting the vulnerabilities were real and announcing a cybersecurity team pulled together from across government and the IITs, though by then the board was also claiming its re-evaluation portal was under a barrage of cyberattacks, over 1.5 million hits within two minutes, and a separate 3.8 million-packet assault days later that resembled a denial-of-service attack, and whether you read that as a genuine attack or as cover for a system still leaking even as it insisted it had been fixed, either way it tells you the same thing, that something built to hold 2 million students' futures was nowhere near ready for what its own failure invited.
And then, just as the story seemed to be settling, a second whistleblower showed up, and this one wasn't a hacker at all, he was 17, his name is Sarthak Sidhant, and he'd sat the very same board exam himself, and he walked into a Parliamentary Standing Committee hearing carrying a seven page report of his own, alleging that CBSE had quietly rewritten its own tender rules across several bidding rounds, specifically the clauses meant to cover blacklisting, poor performance, and financial eligibility, in a pattern that kept landing in favour of the same vendor, a company called Coempt Edutech.
Think about what that actually means for a moment, a teenager built the accountability case that the government itself never bothered to build.
Once that report landed, the government finally moved, transferring both the CBSE Chairman and the CBSE Secretary out of their posts, the Chairman reassigned as Additional Secretary in the Ministry of Agriculture and Farmers Welfare, and setting up a one-member inquiry committee under S. Radha Chauhan of the Capacity Building Commission, with a month to report back, and almost immediately, the opposition said what a lot of people were already thinking, Congress called the transfers a mere eyewash and demanded the Education Minister resign instead, Kejriwal simply asked whether this was punishment or protection, and Aaditya Thackeray went further still, saying the minister himself had to go.
But here's the detail that actually undoes the whole story, the one that makes it impossible to answer Kejriwal's question cleanly either way, Coempt Edutech's contract, the very one governing the system that leaked 2 million students' data, does include financial penalties for security failures, but it includes no clause anywhere allowing CBSE to blacklist the company outright, no matter how severe the breach turns out to be, which means a national exam board responsible for the futures of millions of teenagers had already signed away the one consequence that would have actually mattered.
Because none of what happened there is really about CBSE specifically, it's about how government software has been built in this country for a very long time now, and how little that process has changed even as the stakes riding on it have grown enormously. Most government tenders still default to whoever bids the lowest, and that logic was never designed with software in mind, it's the same thinking you'd use to build a bridge, secure the funding, build it once, cut the ribbon, and forget about it for the next fifty years, and a bridge can survive being forgotten, software cannot, it needs constant patching, testing, rebuilding, and every officer signing off on these tenders knows this perfectly well, and picks the cheapest vendor anyway, not out of carelessness, but because the incentives genuinely leave them no better option, choosing the lowest bidder is procedure, unquestionable no matter what breaks later, while choosing a better, costlier vendor is a personal risk that carries no reward if it works out and real exposure if it doesn't, and in a system where promotions run on seniority rather than the daring calls you made along the way, nobody rational takes that risk twice.
So the failure was never really about one careless person, it's the shape of every incentive sitting in that room, and it's been sitting there for decades, built so that the one thing that almost never happens is a real cost landing on whoever actually caused the damage, the vendor absorbs a fine and keeps operating, the officials get reassigned rather than removed, and the one accountability mechanism that does exist now, the Chauhan committee, only came into being after the leak, not as a safeguard built in before it.
This is the same story you have to sit with before you book a Tatkal ticket, because this is the same machine wearing a different face, and you've felt it yourself even if you never connected it to CBSE, IRCTC handles somewhere between 8 and 9 million bookings a day, it blocked 3 crore suspicious IDs in a single year, it posted over ₹1,063.99 crore in quarterly revenue, up 7.2% from the year before, this is not a starved, underfunded system by any stretch, and yet it has crashed during Tatkal hours, on schedule, almost every festival season, for years running, October 2025, again three weeks later, again in April 2026, always the same error message, always the same ten o'clock window, always someone at IRCTC pointing to network stability or external factors rather than the platform itself.
But here's the part that turns this from an inconvenience into something closer to a quiet national scam, because when that server times out at exactly 10am, the ticket doesn't just vanish, it reappears somewhere else, and users have said as much themselves, watching agents secure confirmed Tatkal seats again and again while the platform tells everyone else the server is unreachable, and once you've seen that happen enough times during enough festival seasons, it stops looking like bad luck and starts looking like a system that works fine for whoever has a workaround, and works against everyone who doesn't, which is most of the country trying to get home for a wedding or a funeral or Diwali.
That's the real cost of building software like it's a bridge, it's not just that it breaks, it's that when it breaks in a predictable, repeatable way, someone always finds a way to profit from the gap it leaves behind, an agent, a middleman, a black market cylinder, a leaked answer sheet sold before anyone official even knew it existed, the shape changes but the underlying story is identical, a system with no real consequence for failing quietly creates room for someone else to succeed by exploiting that same failure.
Not a redesign, not a prettier interface, because that misses what's actually broken here, the fix has to start with the same clause that was missing from Coempt Edutech's contract, a legal requirement that any vendor handling citizen data can be blacklisted outright for a serious breach, no exceptions carved in during the tender stage, and alongside that, an independent body, separate from the ministry doing the hiring, whose only job is to stress test these platforms before they go live, not after 2 million students' data is already sitting exposed, and separate from that again, some form of real consequence for the officer who signs off on a contract that fails, not punishment for taking a risk, but accountability for choosing the cheapest option when the cheapest option was already flagged as unfit, because right now, the system rewards exactly the wrong instinct, and until that changes, no amount of better design language fixes what is fundamentally a consequence problem, not a UX problem.
We are not cybersecurity experts, and we don't pretend to have the technical blueprint for how every one of these systems should be rebuilt, but our government departments are supposed to be, or at least supposed to have access to people who are, and if this is treated as just another slow website story, then somewhere down the line, the country is looking at a data integrity crisis on a national scale, because the next Adhikary might not report it to CERT-In first, and the next breach might not be a 19-year-old trying to help.
Sign up for the Daily newsletter to get your biggest stories, handpicked for you each day.
Trending Now! in last 24hrs