A Dubai-based student who identified India exam portal cybersecurity vulnerabilities in two of the country’s high-stakes examination systems says the anti-paper-leak legislation passed by India’s parliament this week does not go far enough on its own.
Rylen Anil, a Grade 12 student at JSS Private School in Dubai, called on the Indian government to mandate regular Vulnerability Assessment and Penetration Testing (VAPT) on all examination portals, particularly before major exam seasons and after significant system updates.
‘Examination portals contain highly sensitive student information, so they must be protected with strong security controls,’ Rylen said. ‘Regular monitoring and faster responses to reported vulnerabilities can greatly reduce the risk of data being accessed by malicious actors.’
What the new bill introduces
India’s Lok Sabha passed the Public Examinations (Prevention of Unfair Means) Amendment Bill, 2026 by a voice vote on 29 July 2026. The bill was introduced on 27 July 2026 by Union Minister of State for Science and Technology Dr Jitendra Singh.
Under the amended law, the minimum penalty for organised paper-leak crime is set at seven years’ imprisonment and a minimum fine of Rs 10 crore, according to The Hindu. The legislation also provides for fast-track courts and Special Task Forces to handle paper-leak cases.
Rylen said the criminal penalties were a step in the right direction, but that legal deterrence needed to be matched by technical safeguards at the portal level.
India exam portal cybersecurity: what Rylen found
Rylen made his findings public in June after reporting them to India’s Computer Emergency Response Team (CERT-In). He is a member of g4mra, a globally ranked Capture The Flag cybersecurity team.
One of the systems involved was the JEE Advanced portal managed by IIT Roorkee. The institute said in a statement that on 2 June 2026, technical interventions carried out to help candidates access admit card data led to a ‘minimal, temporary misconfiguration in a cloud storage component’. IIT Roorkee acknowledged that Rylen identified and reported the issue, after which access was immediately restricted. The institute said no sensitive information, examination outcomes or candidate records had been compromised, and described wider claims of a large-scale breach as ‘misleading and factually incorrect’, according to India Today.
Rylen also received personal thanks from officials at the National Testing Agency (NTA).
‘I am extremely happy that the authorities saw and acknowledged my findings and were able to fix the issues before a malicious actor discovered them,’ he said. ‘It showed me that responsible disclosure can create a real impact and help protect thousands of students.’
Context: the NEET scandal and its aftermath
Rylen’s disclosures came against the backdrop of a major crisis in Indian public examinations. The NEET medical entrance exam, taken by over 2.2 million candidates, was engulfed in a paper-leak scandal in May, with a leaked document containing around 120 matching questions circulating online.
Weeks of student-led protests followed. Activists behind the Cockroach Janta Party movement said more than 20 students died by suicide, with families blaming the exam scandal. Education Minister Dharmendra Pradhan resigned on 25 July; senior politician Pralhad Joshi was appointed as his successor.
‘Hearing about the human cost surrounding examination-related issues is extremely upsetting, especially because these exams can determine a student’s future,’ Rylen said. ‘It makes me understand that cybersecurity is not only about protecting systems and data, but also about protecting real people who depend on those systems.’
Background and next steps
Rylen has been interested in computer systems since Grade 8 and began learning Python at age seven. He currently works as a junior cybersecurity engineer at C3iHub, IIT Kanpur’s technology innovation hub, which was established under the National Mission on Interdisciplinary Cyber-Physical Systems with funding from India’s Department of Science and Technology. He hopes to pursue a full-time career in cybersecurity.
He stressed that any vulnerabilities discovered should be ‘reported responsibly, carefully and without creating unnecessary panic’.
The amended bill now moves to the Rajya Sabha, where it must pass before it can be enacted into law.
