CBSE Files Police Complaint Over Cyberattacks on Post-Result Portal

CBSE Files Police Complaint Over Cyberattacks on Post-Result Portal | Quick Digest
The CBSE has filed a police complaint with Delhi Police's IFSO unit regarding sophisticated cyberattacks on its Post-Result Services Portal. Despite coordinated Denial-of-Service (DoS) attempts and millions of malicious packets, CBSE confirmed no data breach occurred, and services were successfully maintained with expert cybersecurity support.

Key Highlights

  • CBSE files police complaint with Delhi Police's IFSO Unit.
  • Cyberattacks targeted the Class 12 post-result verification portal.
  • No data breach or system compromise detected, CBSE confirms.
  • Attacks involved millions of malicious packets, mostly DoS type.
  • Security teams from IITs and government agencies helped mitigate.
  • Portal faced disruptions amid existing answer sheet controversies.
The Central Board of Secondary Education (CBSE) has officially lodged a formal complaint with the Intelligence Fusion & Strategic Operations (IFSO) Unit of the Delhi Police, citing a series of sophisticated and coordinated cyberattacks targeting its Post-Result Services Portal. This critical online platform was launched on June 2, 2026, to facilitate essential services such as the verification and re-evaluation of answer scripts for candidates who had appeared in the Class 12 board examinations. The complaint, filed on June 5, 2026, underscored the severe nature of the attacks, which involved large volumes of malicious traffic originating from various IP addresses both within and outside India. The primary objective of these cyber adversaries appeared to be to destabilize the portal, deny legitimate users access to crucial post-result services, and potentially attempt unauthorized extraction of sensitive information. Such disruptions posed a significant threat, as the portal caters to lakhs of students nationwide, and any impediment to its functioning could adversely impact a large number of stakeholders, causing considerable public inconvenience and creating dissatisfaction against the Board during a crucial admission period. Despite the intensity and coordinated nature of these cyberattacks, CBSE has steadfastly maintained that its systems and databases remained secure and uncompromised, with no data breach or unauthorized access detected. Preliminary investigations conducted by Delhi Police sources reportedly corroborated this assertion, finding no evidence of a data breach within CBSE's systems during the attacks. The cyberattacks commenced shortly after the portal's launch. Officials reported that the portal, which went live at approximately 4:30 AM on June 2, recorded nearly 1.5 million access requests within its first two minutes of operation. Crucially, over 100,000 unauthorized access attempts were detected and blocked in real-time almost immediately after the platform became operational. The most significant incident occurred on June 3, 2026, when the re-evaluation portal was subjected to a large-scale Denial-of-Service (DoS) attack, involving approximately 3.8 million malicious packets. This aggressive assault was an apparent attempt to disrupt the ongoing verification and re-evaluation process. CBSE officials elaborated that the traffic profile during these incidents showed coordinated request surges consistent with DDoS-type attack patterns. However, the robust security architecture deployed on the platform, combined with continuous 24x7 monitoring and rapid response mechanisms, successfully mitigated the threats and ensured the continuity of services. The Board also received crucial support from specialized cybersecurity teams, including those from IIT Kanpur, IIT Madras, the Digital India Corporation, the Indian Cyber Crime Coordination Centre (I4C), and CERT-In, in neutralizing the threats. The decision to file a police complaint with the IFSO Unit of Delhi Police underscores the seriousness with which CBSE views these incidents, seeking a detailed investigation and appropriate legal action against those responsible. Following the complaint, Delhi Police registered an FIR under Section 66 along with Section 43(F) of the Information Technology (IT) Act, initiating a probe into the matter. The launch of the re-evaluation portal itself faced an initial delay. It was originally scheduled to go live on June 1 but was deferred to June 2 following an emergency security hardening exercise. This precautionary measure was undertaken in response to existing concerns related to the On-Screen Marking (OSM) implementation, which had already drawn scrutiny. Prior to activation, the system underwent comprehensive penetration testing, vulnerability assessments, and load testing with dedicated cybersecurity support to address identified vulnerabilities and ensure the platform could withstand high traffic volumes. The cyberattacks occurred amidst a broader backdrop of controversy for CBSE, which included allegations from several Class 12 students regarding mismatches in scanned answer sheets made available by the board. Some students reported that the scanned answer sheets did not appear to be in their handwriting, sparking concerns over potential discrepancies in the OSM system. Despite the cyberattacks and the heavy traffic load, the platform remained stable, capable of supporting more than 8,000 concurrent users. As of June 4, the Board had successfully processed 70,433 applications through its post-result grievance redressal mechanism, comprising 7,314 applications for verification of marks and 63,119 for re-evaluation. The application window for re-evaluation was set to close at midnight on June 6, 2026. This incident highlights the increasing vulnerability of critical digital infrastructure to cyber threats and the proactive measures required to safeguard public services, especially those impacting the educational future of millions of students. The involvement of multiple national cybersecurity agencies in mitigating the attacks underscores the national significance and the coordinated effort to protect India's digital education framework. The continued vigilance and collaboration between technical teams and law enforcement are essential to counter such sophisticated cyber threats.

Frequently Asked Questions

What prompted CBSE to file a police complaint?

CBSE filed a police complaint with the Delhi Police's IFSO Unit due to a series of coordinated and sophisticated cyberattacks on its Post-Result Services Portal, aimed at disrupting services and potentially extracting unauthorized information.

Was there any data breach or compromise of student information?

No, CBSE emphatically denied any data breach or compromise of its systems and student databases. Preliminary police investigations also found no evidence of a data breach.

What kind of cyberattacks did the CBSE portal face?

The portal faced repeated and coordinated cyberattacks, primarily Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attempts, involving millions of malicious packets and unauthorized access attempts.

When did these cyberattacks occur, and on which portal?

The cyberattacks began shortly after the Post-Result Services Portal was launched on June 2, 2026, with a major DoS attack detected on June 3, 2026. The portal is used for Class 12 answer script verification and re-evaluation.

How were the cyberattacks mitigated, and who provided support?

The attacks were successfully mitigated through 24x7 monitoring, robust security architecture, and rapid response mechanisms. Cybersecurity teams from IIT Kanpur, IIT Madras, Digital India Corporation, Indian Cyber Crime Coordination Centre, and CERT-In provided crucial support.

Read Full Story on Quick Digest