2026 JEE Advanced / IIT Roorkee — cloud storage misconfig; ~179k–187k records briefly exposed (June)
Data compromised
Alleged names, DOB, and mobile numbers on result/admit-card artifacts; marks/ranks denied by officials
Technical writeup
In early June 2026, cybersecurity researcher Rylen Anil reported a public cloud storage misconfiguration tied to JEE Advanced 2026 result infrastructure, alleging roughly 179,600 result records and 187,300 admit-card PDFs were briefly readable without authentication—including candidate names, dates of birth, and mobile numbers. NDTV and Indian media reported IIT Roorkee and the Ministry of Education acknowledging a configuration issue during admit-card fixes, stating data was read-only, fixed immediately after the ethical-hacker report, and that officials strongly denied a full breach: no bulk download, no marks/ranks exposure, and less than 0.05% of data accessed. BreachHistory indexes the incident as a limited misconfiguration exposure with disputed severity rather than a confirmed mass exfiltration.
Root cause
Temporary cloud storage misconfiguration during admit-card remediation (per IIT Roorkee statements)