
### By Newsroom Editorial Desk
*Published October 15, 2022 (Archived in the National Examination Integrity Repository)* | Archival Incident INC-2021-HR-SONEPAT-011
On the night of Monday, October 3, 2022, an inbound commercial flight from Almaty, Kazakhstan, touched down at Indira Gandhi International Airport in New Delhi. Among the passengers walking through the fluorescent-lit corridors toward immigration was a soft-spoken, thirty-something Russian software developer named Mikhail Shargin.
To the casual observer, Shargin looked like countless foreign IT consultants traveling to India’s bustling tech corridors. But as his passport scanned across the Bureau of Immigration counter, an amber alert flashed silently on the officer's screen.
A global Lookout Circular (LOC) had been active against Shargin for nearly eleven months. Within minutes, two plainclothes detectives from the Central Bureau of Investigation (CBI) Anti-Corruption Branch emerged from a side door, escorted Shargin into a secure holding room, and formally placed him under arrest.
For over a year, CBI sleuths and digital forensic specialists had been tracing the digital fingerprints of a ghost. In September 2021, during the fourth and final session of the Joint Entrance Examination (JEE Main 2021), a criminal syndicate had compromised the crown jewel of India's technical admissions apparatus. Over 9.3 lakh candidates had competed for coveted admissions to the National Institutes of Technology (NITs), Indian Institutes of Information Technology (IIITs), and eligibility for the elite JEE Advanced.
The testing platform—the iLeon assessment engine developed by Tata Consultancy Services (TCS) and administered by the National Testing Agency (NTA)—was celebrated as a technological fortress. Built inside hardened operating system kiosks with dual encryption, strict browser sandboxing, and disabled peripheral ports, it was designed to make remote manipulation impossible.
Yet, inside a nondescript private computer laboratory in Sonepat, Haryana, candidates had sat motionless before their screens while invisible solvers answered complex thermodynamics, electromagnetic induction, and integral calculus problems with supernatural speed.
The man who had written the code that cracked the fortress was Mikhail Shargin.
The architectural mastermind of the domestic fraud was not a cloistered cyber-syndicate, but a commercial entity operating in broad daylight: Affinity Education Pvt. Ltd., an overseas education and domestic test-prep consultancy headquartered in Sector 62, Noida.
Spearheaded by its directors—Siddharth Krishna, Vishwambhar Mani Tripathi, and Govind Varshney—Affinity Education had built a lucrative business model capitalizing on the existential desperation of Indian middle-class engineering parents. To crack the JEE Main and secure a Computer Science seat at an NIT like Tiruchirappalli, Surathkal, or Warangal, candidates typically require a percentile rank above 99.2—a feat achieved by fewer than one in a hundred test-takers.
For affluent families whose children were struggling with mock scores, Affinity offered a tempting proposition: a "guaranteed" 99 to 100 percentile, no preparation required.
The price of admission into this alternate reality was between ₹12 lakh and ₹15 lakh per candidate.
To ensure that clients did not renege on payment once high scores were delivered, the directors implemented a predatory financial collateral system. Before the examination, parents were required to hand over the candidate’s original Class 10 and Class 12 passing certificates, user IDs, admit card credentials, and signed, undated post-dated cheques covering the full bribe amount. If a family attempted to dispute the fee after results were published, the consultancy held their academic future hostage.
By August 2021, as the COVID-delayed fourth session of JEE Main approached, Affinity had assembled a roster of dozens of paying clients. To deliver on their impossible promise, they needed a physical testing ground where the rules could be suspended.
The physical breach did not occur in a prestigious metropolitan government college, but in an outsourced private assessment facility: the Innov8 Education Centre located in the industrial district of Sonepat, Haryana, roughly 50 kilometers north of Delhi.
Under the operational model of large-scale CBT examinations, testing vendors frequently lease capacity from private engineering institutes and third-party computer facilities to accommodate hundreds of thousands of test-takers simultaneously. While premier government institutions maintain rigid physical security, outsourced private computer labs often operate with low-paid contract technicians, flexible management, and minimal oversight.
Through intermediaries, Affinity Education compromised the local management and system administrators of Innov8 Centre.
On the days of the Session 4 examination—between August 26 and September 2, 2021—candidates who had paid Affinity Education were deliberately assigned to specific, pre-determined computer nodes within designated lab rooms. While hundreds of innocent students in neighboring cubicles typed furiously under the gaze of CCTV cameras, these select candidates were given explicit instructions: Log in with your roll number, place your hand on the mouse, stare attentively at the screen, and do not touch the keyboard.
Across the room, the candidate’s monitor was alive with activity. The mouse pointer darted with uncanny precision, navigating from Question 1 to Question 75, selecting options, inputting decimal numerical values, and submitting answers with surgical speed.
To understand the audacity of the crime, one must understand the technology that Shargin dismantled.
The TCS iLeon platform is widely considered one of the world's most resilient assessment engines. When a candidate launches the test software, the operating system enters a strict "sandbox" kiosk mode:
Standard commercial hacking tools could not survive thirty seconds inside this environment. To breach it, the syndicate needed custom, bespoke malware engineered by someone who understood low-level operating system kernels, network socket interception, and memory injection.
Through underground darknet forums and international broker networks, Affinity Education contracted Mikhail Shargin.
Shargin developed a proprietary, lightweight malicious payload. The software operated at the Windows driver level, executing beneath the detection threshold of the TCS kiosk software.
The exploit functioned in three calculated stages:
It was an engineering marvel of criminal technology. But like all digital operations, it left an imperceptible trail of breadcrumbs.
Even as the final candidates were finishing their papers on the morning of September 2, 2021, the Central Bureau of Investigation struck.
Acting on covert intelligence gathered by its cyber intelligence wing, the CBI Anti-Corruption-II Branch in New Delhi registered Regular Case RC2212021E0009 under Section 120B (Criminal Conspiracy) and Section 420 (Cheating) of the Indian Penal Code, alongside Section 66 of the Information Technology Act.
In a synchronized operation executed at dawn, over 100 CBI officers conducted simultaneous raids across 19 locations in Delhi, Noida, Gurgaon, Pune, Jamshedpur, Indore, and Bengaluru.
Detectives stormed the corporate offices of Affinity Education in Sector 62, Noida, arresting directors Siddharth Krishna and his associates. Inside the premises, investigators discovered a treasure trove of incriminating physical and digital evidence:
Simultaneously, a CBI team raided the Innov8 Centre in Sonepat, seizing terminal hard drives, router logs, and server memories. Forensic analysts immediately detected anomalous network connections running during active exam windows.
On September 3, 2021, the CBI announced the arrest of the Affinity Education directors. The Ministry of Education and the National Testing Agency issued emergency statements, announcing that the Innov8 Sonepat centre had been permanently blacklisted. When JEE Main 2021 Session 4 results were published on September 15, the NTA withheld the scores of dozens of implicated candidates, subsequently slapping twenty students with three-year nationwide debarment bans.
Yet the primary question remained unanswered: Who had written the code that defeated TCS iLeon?
For twelve months, CBI cyber forensic specialists at the Central Forensic Science Laboratory (CFSL) in New Delhi dissected the disassembled binary code retrieved from the Sonepat hard drives.
The decompiled malware revealed sophisticated coding idioms characteristic of Eastern European underground software development. By analyzing the reverse-engineered server command-and-control logs, foreign IP routing nodes, and financial transaction metadata, the agency identified the foreign architect: Mikhail Shargin.
CBI investigators determined that Shargin had not merely written code for the Sonepat lab; he had allegedly provided remote-access hacking solutions for multiple high-stakes examinations across India, facilitating fraudulent access for an estimated 820 candidates.
Knowing that Shargin operated outside Indian territorial jurisdiction, the CBI approached the Bureau of Immigration to issue an Interpol-coordinated Red Corner Notice and an internal Lookout Circular (LOC).
For months, the circular sat dormant in national border control databases. Then, on October 3, 2022, Shargin boarded an Air Astana flight from Kazakhstan to Delhi, unaware that his digital identity had been completely unmasked. The moment he presented his passport at Terminal 3 immigration, the trap snapped shut.
On October 4, 2022, Mikhail Shargin was produced before the Chief Metropolitan Magistrate at the Special CBI Court in the Rouse Avenue Court Complex, New Delhi.
The courtroom scene was surreal. Flanked by CBI investigators and an official Russian language interpreter, the foreign coder stood in silence as public prosecutors outlined the international dimensions of the crime. The CBI informed the court that Shargin was the master key to a multi-crore international examination hacking network and sought maximum police remand to decrypt foreign cloud servers, analyze encrypted Telegram chats, and identify other testing agencies that had been compromised.
During custodial hearings, prosecutors noted that Shargin remained largely uncooperative, invoking language barriers and refusing to surrender decryption keys for his secured personal devices. Nevertheless, forensic experts successfully extracted critical logs confirming his administrative control over the proxy software during the September 2021 JEE sessions.
The Rouse Avenue Court granted multiple remand extensions, affirming the grave national security implications of foreign cyber mercenaries penetrating India’s critical educational evaluation infrastructure.
The Mikhail Shargin case forever shattered the myth that Computer-Based Testing is an inherently tamper-proof panacea.
It revealed that the commodification of elite entrance examinations in India had reached such astronomical financial proportions—where a single seat at an NIT or IIT is valued at tens of lakhs of rupees—that domestic syndicates possessed the capital to hire world-class international cyber mercenaries to dismantle state security systems.
In response to the Sonepat breach, the Ministry of Education and the NTA were forced to execute sweeping, permanent reforms across India's digital testing network:
| Date & Time | Authority / Entities Involved | What Happened & Case Developments | Verified Source Link |
|---|---|---|---|
| 2021-08-20 | Affinity Education Pvt. Ltd. | Coaching directors Siddharth Krishna, Vishwambhar Mani Tripathi, and Govind Varshney assemble a network of prospective engineering candidates, collecting post-dated cheques of ₹12–15 lakh and original academic marksheets for guaranteed top percentiles in JEE Main Session 4. | The Hindu Investigation |
| 2021-08-26 to 2021-09-01 | Innov8 Centre Sonepat & CBI Operatives | In the 4th session of JEE Main, compromised computer terminals at Innov8 Education Centre in Sonepat, Haryana, are hijacked using custom malware that bypasses the TCS iLeon secure browser, allowing remote solvers in Delhi-NCR safehouses to complete test papers in real time. | NDTV News Bureau |
| 2021-09-02 (Dawn) | Central Bureau of Investigation (CBI) | CBI registers Regular Case RC2212021E0009 and conducts simultaneous dawn raids across 19 locations in Delhi-NCR, Pune, Jamshedpur, Indore, and Bengaluru; seizes 30 laptops, 20 personal computers, exam logins, and dozens of post-dated cheques. | CBI Official Press Release |
| 2021-09-03 | CBI Anti-Corruption Branch | CBI formally arrests Affinity Education directors Siddharth Krishna and employees, remanding them to police custody; interrogations reveal the involvement of an international foreign hacker who wrote the exploit code. | India Today Crime Desk |
| 2021-09-05 | National Testing Agency (NTA) | NTA issues an official advisory confirming full cooperation with the CBI; blacklists the Innov8 centre in Sonepat and begins digital anomaly audits on response sheets exhibiting unnatural timing spikes. | Hindustan Times Education |
| 2021-09-15 | National Testing Agency (NTA) | NTA declares JEE Main 2021 results; scores of 20 implicated candidates are withheld, and subsequent formal orders debar them from appearing in JEE exams for a period of three years. | Livemint National Report |
| 2021-11-12 | CBI Cyber Crimes Division | CBI digital forensic analysis traces the proprietary remote-execution malware that breached TCS iLeon back to digital infrastructure in Russia; Bureau of Immigration issues a global Lookout Circular (LOC) against Russian software developer Mikhail Shargin. | The Hindu National Desk |
| 2022-10-03 | Bureau of Immigration & CBI | Russian national Mikhail Shargin is intercepted at Indira Gandhi International Airport in New Delhi upon arrival from Almaty, Kazakhstan, following the active LOC, and handed over to CBI sleuths. | Times of India Front Page |
| 2022-10-04 | Rouse Avenue District Courts, New Delhi | Chief Metropolitan Magistrate at Rouse Avenue Courts remands Mikhail Shargin to CBI custody; CBI tells the court that Shargin tampered with TCS iLeon software to facilitate remote solving for 820+ candidates across India. | NDTV Legal Coverage |
| 2022-10-10 | Special CBI Court, Rouse Avenue | Rouse Avenue Court extends Shargin's custody as forensic experts decrypt encrypted foreign hard drives, cloud backups, and cryptocurrency transactions linked to coaching networks across India. | The Indian Express Crime Bureau |
| 2023–2024 | Ministry of Education & NTA | Ministry of Education enforces comprehensive security overhaul for all computer-based examinations: mandatory air-gapped physical networks, two-step biometric checks, hardware port disabling, and continuous keystroke velocity monitoring. | Ministry of Education Annual Report |
Publication: The Hindu
Date: September 2, 2021
Publication: NDTV
Date: October 4, 2022
Publication: The Hindu
Date: October 4, 2022
Publication: The Indian Express
Date: October 10, 2022
Publication: Hindustan Times
Date: September 4, 2021
Publication: Livemint
Date: September 15, 2021
Document: FIR No. RC2212021E0009 and Press Bulletins on Russian National Arrest
Direct URL: https://cbi.gov.in
Forum: Court of Special Judge (CBI), Rouse Avenue Court Complex, New Delhi
Direct URL: https://delhidistrictcourts.nic.in
Comments
0Want to participate in the discussion?
No comments yet. Start the discussion above.