NEET portal hack: Bihar youth arrested in Gujarat for diverting ₹1,700 refunds
Synopsis
Key Takeaways
The Ahmedabad Cyber Crime Branch has arrested a 19-year-old Bihar resident, Navinkumar Yadav, a BSc graduate from Bhareti, Gaya district, for allegedly hacking into NEET UG-2026 portal accounts and attempting to redirect candidate refund payments to his own bank account. The arrest, made in coordination with the National Testing Agency (NTA), follows the government's announcement of ₹1,700 refunds to students after the cancellation of the previous NEET examination.
How the Hack Was Carried Out
According to police, Yadav allegedly exploited critical weaknesses in the NEET portal's password recovery mechanism, which relied on easily guessable security questions such as favourite colour and favourite sport. Using software-assisted brute-force tools, he reportedly cycled through combinations until he cracked student passwords.
Police alleged that Yadav targeted approximately 350 NEET candidate accounts and successfully breached around 150 of them due to weak password choices. Once inside, he allegedly changed the account passwords and replaced the registered bank account details with his own, so that refund transfers would be redirected to him instead of the rightful candidates.
How the Accused Was Traced
The case came to light after the NTA's Chief Information Security Officer (CISO) flagged suspicious activity. The CISO immediately shared digital footprint data generated through the portal's security logs, enabling investigators to identify the suspect and trace his location. Police said the detection relied on a combination of technical analysis of bank account details and human intelligence inputs, leading to Yadav's arrest in Bihar.
A case has been registered under relevant provisions of the Bharatiya Nyaya Sanhita and the Information Technology Act.
What Officials Said
Joint Commissioner of Police (Crime) Sharad Singhal confirmed at a press conference that more than 150 students had been affected, and that the number could rise as the investigation continues. 'Cyber criminals exploited vulnerabilities in the password recovery system and targeted student accounts,' he said.
Singhal added that relevant bank accounts had been frozen and that affected students would be refunded once the investigation concludes. 'Authorities were working to identify where the money had gone,' he said.
NTA Director Akash Jain acknowledged that initial shortcomings may have existed in the refund system. 'Lessons learned from the investigation have helped strengthen the portal's security features,' he said.
Security Overhaul at NTA
The breach has prompted a significant upgrade to the NEET portal's security architecture. Two-factor authentication, which was previously unavailable on the affected section, is now being implemented by the NTA. According to Jain, OTP-based verification and Aadhaar-linked verification have also been incorporated to prevent further unauthorised access through security question exploitation.
The Cyber Crime Branch has advised students and parents to use strong passwords combining uppercase and lowercase letters, numbers, and special characters, and to avoid simple choices such as names, dates of birth, or mobile numbers. Candidates were also urged to access only the official NTA and NEET websites for examination and refund-related processes.
What Happens Next
The investigation is ongoing, and police have not ruled out additional arrests. Affected students are expected to receive their refunds once the probe is complete and frozen accounts are verified. The NTA's security overhaul, if implemented rigorously, could set a new baseline for portal security across competitive examination bodies in India.