NRI Pulse Staff Report
Washington, DC, September 24, 2026: A 19-year-old self-taught cybersecurity researcher from India has been recognized by the U.S. Department of Justice after reporting what he described as a critical vulnerability in one of the department’s major law-enforcement systems, prompting authorities to validate and patch the security flaw.
Nisarga Adhikary, who shot to prominence in India earlier this year after exposing vulnerabilities in the Central Board of Secondary Education’s digital evaluation system, was named on the Justice Department’s acknowledgments list for security researchers who responsibly report valid vulnerabilities. The recognition has been widely described in media reports as a place in the DOJ’s cybersecurity “Hall of Fame.”
“I found a critical vulnerability in one of their largest law enforcement systems,” Adhikary told India Today Tech. He said he discovered the vulnerability while browsing the DOJ website and using custom scripts, and reported it to the department through its responsible disclosure process.
According to Adhikary, the Justice Department validated his findings and patched the vulnerability within about a week. He did not receive a monetary reward for the disclosure.
The precise system affected and technical details of the vulnerability have not been made public, an important security precaution given the sensitive nature of federal law-enforcement infrastructure. The DOJ has also not publicly disclosed an independent severity assessment of the vulnerability. The description of it as “critical” comes from Adhikary.
The recognition adds another chapter to a rapid rise in cybersecurity for the teenager, who says he began exploring the field at age 13 and is largely self-taught. He currently works as a Security, Open-Source Intelligence and Threat Intelligence Engineer at C3iHub, the cybersecurity technology innovation hub at the Indian Institute of Technology Kanpur.
Adhikary first drew widespread attention earlier this year after reporting security vulnerabilities in CBSE’s On-Screen Marking system, which is used in the evaluation of board examinations.
He said he initially reported the vulnerabilities to the Indian Computer Emergency Response Team, CERT-In, in February. His disclosures raised concerns about authentication, access controls and the security of digital examination infrastructure.
The episode eventually caught the attention of IIT Kanpur Director Manindra Agrawal, who said he reached out to Adhikary after reading the teenager’s detailed write-up about the vulnerabilities. Adhikary subsequently joined C3iHub as an OSINT and Threat Intelligence Engineer in June.
Adhikary’s work has since expanded beyond Indian systems. He has also said that he discovered and reported a separate vulnerability involving a U.S. Department of Defense system. According to Adhikary, that vulnerability was validated, although remediation was still underway when he spoke to India Today.
The DOJ recognition is part of the federal government’s broader practice of encouraging responsible vulnerability disclosure, under which independent cybersecurity researchers can report weaknesses they encounter in publicly accessible government systems rather than exploiting them.
For Adhikary, the acknowledgment comes only months after he completed Class 12 and moved directly into professional cybersecurity work at IIT Kanpur, an unusual trajectory for a teenager without a conventional college degree.
His latest recognition also underscores the growing role of independent ethical hackers in identifying vulnerabilities before they can be exploited by malicious actors.
At 19, Adhikary has gone from examining the security of an Indian school examination platform to helping alert U.S. federal authorities to vulnerabilities in government systems — all within the span of a few months.

