One Researcher, 14 Flaws, Millions of Indians at Risk
A young independent security researcher found gaping holes in Indian government portals, including an admin panel left wide open to the entire internet. The government fixed everything within three weeks.

Key points
- Independent researcher Sushant Bhardwaj discovered 14 vulnerabilities across Indian government IT portals in April 2025, two rated critical severity.
- A Delhi scholarship portal exposed the full bank account numbers of 4,399 people to anyone with an internet connection.
- The Union Public Service Commission, which handled 1.3 million job applications in 2023 alone, left its administrative login panel completely unprotected.
- Nearly 2 million Delhi school students had enrolment and exam records exposed due to missing access controls.
- All 14 vulnerabilities were patched within two to three weeks of Bhardwaj's report, first covered by Dark Reading.
Sushant Bhardwaj is an independent cybersecurity researcher. No government agency, no big security firm. He found 14 security holes in Indian government websites, reported them responsibly, and watched them get fixed. That's how it's supposed to work. It rarely does.
The problems he uncovered were not exotic. Most came down to broken access controls, meaning the websites displayed a "you can't see this" message but never enforced it on the server. Anyone who knew to look could walk straight past the warning.
How did the hackers get in?
No hackers got in, this time. But the doors were wide open.
Bhardwaj found that two Delhi government directories, managed by the city's Directorate of Education, had no real barrier protecting them. Files inside followed predictable naming patterns, so by tweaking the web address he was visiting, he could pull up student enrolment records, parents' names and exam results for close to 2 million students.
A separate Delhi portal handling scholarships, disproportionately used by lower-income families, exposed something far more dangerous: names, guardian details and complete bank account numbers for 4,399 people. All visible to anyone online.
The most serious findings were national. The Union Public Service Commission, or UPSC, recruits India's civil servants. Think of it as the country's central hiring office for government roles. Twelve vulnerabilities in UPSC's portal, and the worst was almost comically bad: the administrative interface, the control panel governing who can log in and what they can do, was sitting open on the public internet with no password required. A criminal could have granted themselves full access and taken over the entire system in minutes.
Bhardwaj also found the portal was vulnerable to automated credential attacks, where software rapidly tries thousands of username-and-password combinations until one works. Additional issues included one-time password flaws, the single-use codes texted to verify identity, and sensitive data appearing in publicly accessible documents.
We covered the access-control accountability problem in our Zero Trust piece on 16 June, and UPSC's open admin panel is exactly the kind of gap that model is supposed to close. It doesn't, if nobody enforces it.
Trey Ford of Bugcrowd told Dark Reading: "The most common public sector failure isn't a clever exploit, it's a simple error like leaving a directory open."
Bhardwaj agrees. "Most of the issues I've encountered were not the result of highly sophisticated attacks but rather configuration weaknesses and inconsistent access controls."
Should you worry?
If you applied to a UPSC position, studied in a Delhi government school, or received a Delhi government scholarship, there's no confirmed evidence that anyone malicious accessed your data before the fixes. If you notice unfamiliar activity on a bank account linked to any government portal, report it to your bank immediately.
The faster-than-expected patch timeline is genuinely good news. What it doesn't resolve is how an admin panel serving 1.3 million applicants was ever reachable without a password. That's not a sophisticated failure. It's a missing lock.



