Security Breach Suspected on CBSE Re-evaluation Portal
The Central Board of Secondary Education (CBSE) has found itself at the center of a potential cybersecurity incident involving its re-evaluation portal. According to official sources, the payment infrastructure of the portal experienced what is being described as a malicious attack, which reportedly granted unauthorized system access to around 50 students. This security lapse is believed to be the root cause behind the bizarre fee discrepancies that users encountered during the application window.
Erratic Fee Amounts Raise Red Flags
Students attempting to pay for re-evaluation services were met with highly inconsistent figures. In several instances, the displayed fee flipped between a nominal Re 1 and a staggering Rs 67,000 to Rs 68,000. Investigators have traced the anomaly to a glitch within the HDFC Bank payment gateway, which was integrated with the CBSE portal at the time of the incident.
A source familiar with the matter indicated that the system may have been tampered with, either as a prank or with malicious intent. The source confirmed that the fee amounts were altered in approximately 50 student cases, highlighting the targeted nature of the disruption.
Portal Disruptions and Immediate Response
The technical difficulties began surfacing almost immediately after the portal went live. For a certain period, the website struggled to function smoothly, leaving many users unable to complete their transactions. Officials suspect that unauthorized individuals managed to infiltrate the system and attempted to manipulate the payment module before the issue was contained.
Strengthening the Payment Infrastructure
In the wake of the breach, CBSE has taken decisive steps to overhaul its payment architecture. The board has now integrated four major public sector banks into its system to bolster security and reliability. These include:
- State Bank of India (SBI)
- Canara Bank
- Indian Bank
- Bank of Maharashtra
These new payment gateways have been linked to the CBSE portal to provide a more robust and secure transaction environment for students.
Expert Investigation Underway
A multi-disciplinary team of technical experts has been assembled to conduct a thorough forensic review of the incident. Specialists from IIT Madras, IIT Kanpur, and the Digital Infrastructure Corporation of India are currently examining the portal’s source code and payment integration protocols. The objective is to identify vulnerabilities, patch security loopholes, and ensure the system is fully fortified against future attacks.
High-Level Government Intervention
The severity of the situation prompted intervention at the highest levels of government. On May 24, the Union Education Minister held discussions with the Finance Minister to address the crisis. During this meeting, it was decided that public sector banks would play a pivotal role in reinforcing the payment gateway system used by CBSE, ensuring greater oversight and stability.
Migration to Cloud for Better Stability
Beyond the immediate security concerns, the portal was also grappling with capacity and performance issues. To address these challenges, the entire system has been migrated to Amazon Web Services (AWS). This move is intended to equip the platform with the necessary bandwidth and technical resilience to handle high traffic volumes and withstand future technical pressures without compromising performance.
This incident serves as a stark reminder of the vulnerabilities inherent in digital public services. While the board has moved quickly to rectify the situation, the investigation remains ongoing as authorities work to fully understand the scope of the attack and prevent any recurrence. Students are advised to monitor official CBSE communications for further updates regarding the re-evaluation process.
