19-Year-Old Indian Cybersecurity Researcher Nisarga Adhikary Named in US Department of Justice Hall of Fame

A 19-year-old Indian cybersecurity researcher, Nisarga Adhikary, has been recognised by the US Department of Justice (DoJ) after he reported in a blog post what he defined as an important security issue in one of the department's major law enforcement systems that he said was a major security vulnerability.

Nisarga Adhikary: Indian Teen Named in US DoJ Hall of Fame | Photo Credit: https://x.com/india_plus_
Nisarga Adhikary: Indian Teen Named in US DoJ Hall of Fame | Photo Credit: https://x.com/india_plus_

Adhikary said he discovered the vulnerability while studying the DoJ's systems and reported it to the department. The vulnerability was validated and patched within about a week, after which his name was added to the department's cybersecurity acknowledgements or Hall of Fame page.

The young researcher shared a screenshot of the DoJ acknowledgement on social media. The department’s page acknowledges researchers who responsibly disclose valid vulnerabilities, highlighting the importance that independent cybersecurity researchers can play in identifying weaknesses before they can potentially be exploited by malicious actors.

Adhikary told India Today he discovered the problem while browsing the department's website and using custom scripts that he developed himself. He was not paid for reporting the vulnerability.

The exact details of the vulnerability have not been publicly disclosed. Adhikary said he could not reveal which specific DoJ system was affected or provide technical information regarding the flaw. Thus, publicly available reports show he said he discovered and responsibly reported a major vulnerability but do not provide enough information to independently assess the technical severity of the flaw beyond the department’s acknowledgement as reported by him.

The DoJ recognition comes months after Adhikary attracted attention in India for speaking out about the Central Board of Secondary Education (CBSE) On-Screen Marking (OSM) system.

In May 2026, Adhikary claimed that he had discovered multiple security vulnerabilities in an OSM portal linked to the CBSE and had reported them to CERT-In. He made allegations about authentication and access control issues. Many reports followed about his claims and the response of the CBSE.

CBSE rejected the notion that its live evaluation system had been compromised. The board said the URL mentioned in social media posts was a testing site with sample data and that the portal used for actual evaluation had a different URL and had not been compromised.

But the CBSE episode brought attention to Adhikary's cybersecurity work. In June, IIT Kanpur confirmed that he had joined its C3iHub as an Open-Source Intelligence (OSINT) and Threat Intelligence Engineer after the controversy surrounding his disclosures.

Adhikary also said that he reported a vulnerability affecting a US Department of Defense or military system. According to India Today, the issue was validated and still under remediation at the time of the report.

The DoJ acknowledgement is another step in the young researcher’s cybersecurity journey. Instead of seeing vulnerability research as unauthorised access, responsible disclosure programmes invite security researchers to report flaws to organisations to investigate and fix them.

For Adhikary, the recognition places his work on an international level. At just 19, his disclosures have already involved cybersecurity systems connected to Indian education infrastructure and US government agencies.

This episode also underscores the increasing role of independent researchers in cybersecurity. Government agencies, technology companies and other organisations increasingly work with researchers to identify vulnerabilities that might otherwise go unaddressed; when such flaws are disclosed and fixed, that process can enhance digital security and give researchers a sense of recognition for their work.

For now, we have little to go on about the DoJ vulnerability because Adhikary has not publicly disclosed the affected system or what the technicality is at hand at all. What is clear from this new reporting is that he says the vulnerability was reported to the department, validated and corrected, and acknowledged on the DoJ's researcher acknowledgements page.