Particle.news

IIT Roorkee Says JEE Advanced Cloud Misconfiguration Was Fixed and No Large-Scale Breach Occurred

The institute says a brief, read-only cloud-storage error flagged on June 2 was patched after responsible disclosure and that exam results and ranks were unaffected.

Overview

  • A technical intervention on June 2 created a temporary misconfiguration in a public cloud storage component linked to the JEE Advanced results and admit-card system.
  • A cybersecurity researcher, Rylen Anil, reported that he could access files and the institute says he responsibly disclosed the issue and deleted verification files.
  • IIT Roorkee restricted access, patched the configuration and says log analysis shows read-only access to less than 0.05% of stored data with no bulk downloads.
  • The Union Ministry of Education has backed the institute’s account and both organisations say no sensitive information was mass-extracted and examination outcomes were not affected.
  • The episode has raised fresh scrutiny of digital exam infrastructure and could prompt tighter testing of cloud setups as students enter the JoSAA counselling process.