Nisarga Adhikary Gets US DOJ Recognition
Nisarga Adhikary, a 19-year-old Indian cybersecurity researcher, has been recognised by the US Department of Justice for responsibly reporting a security vulnerability in one of its law-enforcement systems.

Adhikary shared the recognition on social media after his name appeared on the department’s cybersecurity acknowledgements page, which lists researchers who responsibly disclose valid vulnerabilities.
Critical US Government Vulnerability Reported
Adhikary said he discovered a critical vulnerability in one of the US Justice Department’s major law-enforcement systems while examining its website and using custom scripts.
He did not disclose technical details about the vulnerability or identify the affected system.
According to Adhikary, he reported the issue to the department, which validated the vulnerability and fixed it within about a week. He was subsequently credited on the department’s Hall of Fame and acknowledgements page.
The researcher also said he was not paid for discovering the vulnerability.
His Cybersecurity Journey Started Young
Adhikary’s interest in cybersecurity began when he was around 13 years old. His work came into the spotlight in India earlier this year after he identified security weaknesses in the Central Board of Secondary Education’s On-Screen Marking portal.
The platform is used by CBSE-affiliated schools to upload and manage examination marks and is an important part of the digital examination process.
Adhikary reported vulnerabilities that raised concerns about access controls and the protection of examination-related information.
CBSE Portal Vulnerabilities Drew Attention
The CBSE incident became widely discussed after claims that scanned answer sheets and examination-related files could potentially be accessed without adequate authentication.
CBSE subsequently said identified vulnerabilities in the service provider’s portal had been contained and that cybersecurity experts had been deployed to strengthen the system.
The incident highlighted the importance of security testing for platforms handling sensitive academic information.
IIT Kanpur Hires The Young Researcher
Following the CBSE episode, Adhikary was appointed as an Open-Source Intelligence and Threat Intelligence Engineer at C3iHub, IIT Kanpur’s cybersecurity and cyber-defence research centre.
The appointment marked a transition from independent security research towards professional cybersecurity and threat intelligence work.
More US Government Vulnerabilities Reported
The US DOJ recognition is not the first interaction Adhikary has had with American government systems.
He has also said that he reported a vulnerability affecting a US Department of Defense or military system. According to him, the issue was validated and remediation was still underway.
He has also received recognition from the US Department of Defense through a vulnerability disclosure platform.
Responsible Disclosure Gets Global Recognition
Adhikary’s recognition demonstrates how responsible vulnerability disclosure can bring attention to security researchers even when they are still at the beginning of their careers.
Rather than exploiting vulnerabilities, researchers following responsible disclosure practices report security weaknesses to affected organisations so they can investigate and fix them.
For a 19-year-old researcher who first gained widespread attention after identifying flaws in India’s examination infrastructure, recognition by a major US government department marks another significant step in his cybersecurity career.
Summary
Nineteen-year-old Indian cybersecurity researcher Nisarga Adhikary has been named on the US Department of Justice’s cybersecurity Hall of Fame and acknowledgements page after reporting a critical vulnerability in a US law-enforcement system. He previously identified security weaknesses in the CBSE examination portal and was later appointed as an OSINT and Threat Intelligence Engineer at IIT Kanpur’s C3iHub.
