IIT Roorkee has officially denied reports of a massive data breach involving JEE Advanced students, clarifying that a minor cloud storage misconfiguration was quickly resolved without compromising sensitive information.
Key Points
- IIT Roorkee identified a temporary cloud storage misconfiguration on June 2 that occurred during technical updates for candidate admit card access.
- Ethical hacker Rylen Anil discovered the vulnerability and reported it to the institute, which immediately restricted access to the database.
- Forensic analysis of cloud logs confirmed that no bulk data downloads occurred, with unauthorized access limited to less than 0.05 percent of records.
- The institute emphasized that the affected storage was read-only, preventing any editing or deletion of student information.
- IIT Roorkee stated that examination outcomes and personal data remain secure, dismissing social media claims of a widespread privacy violation.