The NEET Files
  • HOME
  • BOOKS
  • NEWS
  • ABOUT ME
SIGN IN→
The NEET Files

Three books. One examination. No guarantees. Serialized weekly by Aditya.

  • HOME
  • BOOKS
  • NEWS
  • ABOUT ME
  • CMS

© 2026 Aditya. All rights reserved.

THE EXAM NEVER ENDS. NEITHER DOES THIS STORY.

  1. HOME
  2. /
  3. NEWS
  4. /
  5. SERIOUS
SERIOUS

The Moscow Connection: How a Russian Hacker Pierced India's Premier Engineering Test

15 OCTOBER 2022•INVESTIGATIVE DISPATCH•BY ADITYA
Black-and-white editorial illustration depicting the news story: The Moscow Connection: How a Russian Hacker Pierced India\, drawn in classic Indian newspaper ink cartoon style.
Editorial Illustration:Editorial illustration reflecting the events and context of The Moscow Connection: How a Russian Hacker Pierced India\.
VINTAGE INK ARCHIVE

KEY FACTS & INVESTIGATIVE RECORD

AEO Direct Answer Layer
Event / Case
The Moscow Connection: How a Russian Hacker Pierced India's Premier Engineering Test
Date / Period
2022-10-15
Location / Venue
India
Legal / Administrative Status
CBI Investigation / Formal Inquest
Agencies / Entities Involved
National Testing Agency (NTA)Central Bureau of Investigation (CBI)
Sources Cited: 19+ verified referencesLast Verified: 2026-09-22

### By Newsroom Editorial Desk
*Published October 15, 2022 (Archived in the National Examination Integrity Repository)* | Archival Incident INC-2021-HR-SONEPAT-011


On the night of Monday, October 3, 2022, an inbound commercial flight from Almaty, Kazakhstan, touched down at Indira Gandhi International Airport in New Delhi. Among the passengers walking through the fluorescent-lit corridors toward immigration was a soft-spoken, thirty-something Russian software developer named Mikhail Shargin.

To the casual observer, Shargin looked like countless foreign IT consultants traveling to India’s bustling tech corridors. But as his passport scanned across the Bureau of Immigration counter, an amber alert flashed silently on the officer's screen.

A global Lookout Circular (LOC) had been active against Shargin for nearly eleven months. Within minutes, two plainclothes detectives from the Central Bureau of Investigation (CBI) Anti-Corruption Branch emerged from a side door, escorted Shargin into a secure holding room, and formally placed him under arrest.

For over a year, CBI sleuths and digital forensic specialists had been tracing the digital fingerprints of a ghost. In September 2021, during the fourth and final session of the Joint Entrance Examination (JEE Main 2021), a criminal syndicate had compromised the crown jewel of India's technical admissions apparatus. Over 9.3 lakh candidates had competed for coveted admissions to the National Institutes of Technology (NITs), Indian Institutes of Information Technology (IIITs), and eligibility for the elite JEE Advanced.

The testing platform—the iLeon assessment engine developed by Tata Consultancy Services (TCS) and administered by the National Testing Agency (NTA)—was celebrated as a technological fortress. Built inside hardened operating system kiosks with dual encryption, strict browser sandboxing, and disabled peripheral ports, it was designed to make remote manipulation impossible.

Yet, inside a nondescript private computer laboratory in Sonepat, Haryana, candidates had sat motionless before their screens while invisible solvers answered complex thermodynamics, electromagnetic induction, and integral calculus problems with supernatural speed.

The man who had written the code that cracked the fortress was Mikhail Shargin.


1. The ₹15-Lakh Guarantee: Affinity Education and the Collateral Trap

The architectural mastermind of the domestic fraud was not a cloistered cyber-syndicate, but a commercial entity operating in broad daylight: Affinity Education Pvt. Ltd., an overseas education and domestic test-prep consultancy headquartered in Sector 62, Noida.

Spearheaded by its directors—Siddharth Krishna, Vishwambhar Mani Tripathi, and Govind Varshney—Affinity Education had built a lucrative business model capitalizing on the existential desperation of Indian middle-class engineering parents. To crack the JEE Main and secure a Computer Science seat at an NIT like Tiruchirappalli, Surathkal, or Warangal, candidates typically require a percentile rank above 99.2—a feat achieved by fewer than one in a hundred test-takers.

For affluent families whose children were struggling with mock scores, Affinity offered a tempting proposition: a "guaranteed" 99 to 100 percentile, no preparation required.

The price of admission into this alternate reality was between ₹12 lakh and ₹15 lakh per candidate.

To ensure that clients did not renege on payment once high scores were delivered, the directors implemented a predatory financial collateral system. Before the examination, parents were required to hand over the candidate’s original Class 10 and Class 12 passing certificates, user IDs, admit card credentials, and signed, undated post-dated cheques covering the full bribe amount. If a family attempted to dispute the fee after results were published, the consultancy held their academic future hostage.

By August 2021, as the COVID-delayed fourth session of JEE Main approached, Affinity had assembled a roster of dozens of paying clients. To deliver on their impossible promise, they needed a physical testing ground where the rules could be suspended.


2. The Sonepat Lab: Innov8 Education Centre

The physical breach did not occur in a prestigious metropolitan government college, but in an outsourced private assessment facility: the Innov8 Education Centre located in the industrial district of Sonepat, Haryana, roughly 50 kilometers north of Delhi.

Under the operational model of large-scale CBT examinations, testing vendors frequently lease capacity from private engineering institutes and third-party computer facilities to accommodate hundreds of thousands of test-takers simultaneously. While premier government institutions maintain rigid physical security, outsourced private computer labs often operate with low-paid contract technicians, flexible management, and minimal oversight.

Through intermediaries, Affinity Education compromised the local management and system administrators of Innov8 Centre.

On the days of the Session 4 examination—between August 26 and September 2, 2021—candidates who had paid Affinity Education were deliberately assigned to specific, pre-determined computer nodes within designated lab rooms. While hundreds of innocent students in neighboring cubicles typed furiously under the gaze of CCTV cameras, these select candidates were given explicit instructions: Log in with your roll number, place your hand on the mouse, stare attentively at the screen, and do not touch the keyboard.

Across the room, the candidate’s monitor was alive with activity. The mouse pointer darted with uncanny precision, navigating from Question 1 to Question 75, selecting options, inputting decimal numerical values, and submitting answers with surgical speed.


3. The Hacker's Craft: Piercing the TCS iLeon Fortress

To understand the audacity of the crime, one must understand the technology that Shargin dismantled.

The TCS iLeon platform is widely considered one of the world's most resilient assessment engines. When a candidate launches the test software, the operating system enters a strict "sandbox" kiosk mode:

  • The Windows desktop, taskbar, and start menu are completely suppressed.
  • Universal Serial Bus (USB) ports are driver-locked to prevent external flash drives or dongles from being recognized.
  • Standard remote-desktop ports (RDP) and common commercial utilities—TeamViewer, AnyDesk, VNC—are actively scanned for by background watchdog services and terminated instantly.
  • The local computer communicates with the centralized examination server over an isolated, encrypted local network socket.

Standard commercial hacking tools could not survive thirty seconds inside this environment. To breach it, the syndicate needed custom, bespoke malware engineered by someone who understood low-level operating system kernels, network socket interception, and memory injection.

Through underground darknet forums and international broker networks, Affinity Education contracted Mikhail Shargin.

Shargin developed a proprietary, lightweight malicious payload. The software operated at the Windows driver level, executing beneath the detection threshold of the TCS kiosk software.

The exploit functioned in three calculated stages:

  1. The Kernel Hook: Injected into the terminal's system memory prior to candidate check-in, Shargin's software bypassed the display driver restrictions, capturing the raw graphical frame buffer of the exam screen without triggering the watchdog service.
  2. The Covert Tunnel: Instead of broadcasting over standard remote-access network ports, the malware encapsulated the live video feed into non-standard UDP packets, routing them through a hidden secondary network interface card or a stealth Wi-Fi tether configured by complicit lab staff.
  3. The Puppet Proxy: The feed was transmitted to an external control node set up in a private apartment miles away. From there, expert "solvers"—seasoned physics and mathematics tutors hired by Affinity—viewed the live examination paper in real time. Their input commands were converted back into virtual mouse events and injected directly into the operating system’s hardware input queue, tricking the iLeon engine into believing that the physical USB mouse in front of the student was generating the clicks.

It was an engineering marvel of criminal technology. But like all digital operations, it left an imperceptible trail of breadcrumbs.


4. The Dawn Raids: September 2, 2021

Even as the final candidates were finishing their papers on the morning of September 2, 2021, the Central Bureau of Investigation struck.

Acting on covert intelligence gathered by its cyber intelligence wing, the CBI Anti-Corruption-II Branch in New Delhi registered Regular Case RC2212021E0009 under Section 120B (Criminal Conspiracy) and Section 420 (Cheating) of the Indian Penal Code, alongside Section 66 of the Information Technology Act.

In a synchronized operation executed at dawn, over 100 CBI officers conducted simultaneous raids across 19 locations in Delhi, Noida, Gurgaon, Pune, Jamshedpur, Indore, and Bengaluru.

Detectives stormed the corporate offices of Affinity Education in Sector 62, Noida, arresting directors Siddharth Krishna and his associates. Inside the premises, investigators discovered a treasure trove of incriminating physical and digital evidence:

  • More than 30 high-end laptops and 20 desktop computers configured with remote-access monitoring tools;
  • Over dozens of original Class 10 and 12 marksheets belonging to engineering aspirants across northern India;
  • Post-dated cheques totaling crores of rupees signed by parents;
  • Stamped, signed blank promissory notes and login credentials for active JEE candidate portals.

Simultaneously, a CBI team raided the Innov8 Centre in Sonepat, seizing terminal hard drives, router logs, and server memories. Forensic analysts immediately detected anomalous network connections running during active exam windows.

On September 3, 2021, the CBI announced the arrest of the Affinity Education directors. The Ministry of Education and the National Testing Agency issued emergency statements, announcing that the Innov8 Sonepat centre had been permanently blacklisted. When JEE Main 2021 Session 4 results were published on September 15, the NTA withheld the scores of dozens of implicated candidates, subsequently slapping twenty students with three-year nationwide debarment bans.

Yet the primary question remained unanswered: Who had written the code that defeated TCS iLeon?


5. Hunting the Ghost: The Almaty Flight

For twelve months, CBI cyber forensic specialists at the Central Forensic Science Laboratory (CFSL) in New Delhi dissected the disassembled binary code retrieved from the Sonepat hard drives.

The decompiled malware revealed sophisticated coding idioms characteristic of Eastern European underground software development. By analyzing the reverse-engineered server command-and-control logs, foreign IP routing nodes, and financial transaction metadata, the agency identified the foreign architect: Mikhail Shargin.

CBI investigators determined that Shargin had not merely written code for the Sonepat lab; he had allegedly provided remote-access hacking solutions for multiple high-stakes examinations across India, facilitating fraudulent access for an estimated 820 candidates.

Knowing that Shargin operated outside Indian territorial jurisdiction, the CBI approached the Bureau of Immigration to issue an Interpol-coordinated Red Corner Notice and an internal Lookout Circular (LOC).

For months, the circular sat dormant in national border control databases. Then, on October 3, 2022, Shargin boarded an Air Astana flight from Kazakhstan to Delhi, unaware that his digital identity had been completely unmasked. The moment he presented his passport at Terminal 3 immigration, the trap snapped shut.


6. The Trial at Rouse Avenue: The Uncooperative Hacker

On October 4, 2022, Mikhail Shargin was produced before the Chief Metropolitan Magistrate at the Special CBI Court in the Rouse Avenue Court Complex, New Delhi.

The courtroom scene was surreal. Flanked by CBI investigators and an official Russian language interpreter, the foreign coder stood in silence as public prosecutors outlined the international dimensions of the crime. The CBI informed the court that Shargin was the master key to a multi-crore international examination hacking network and sought maximum police remand to decrypt foreign cloud servers, analyze encrypted Telegram chats, and identify other testing agencies that had been compromised.

During custodial hearings, prosecutors noted that Shargin remained largely uncooperative, invoking language barriers and refusing to surrender decryption keys for his secured personal devices. Nevertheless, forensic experts successfully extracted critical logs confirming his administrative control over the proxy software during the September 2021 JEE sessions.

The Rouse Avenue Court granted multiple remand extensions, affirming the grave national security implications of foreign cyber mercenaries penetrating India’s critical educational evaluation infrastructure.


7. The Institutional Reckoning: Fortifying the Digital Frontier

The Mikhail Shargin case forever shattered the myth that Computer-Based Testing is an inherently tamper-proof panacea.

It revealed that the commodification of elite entrance examinations in India had reached such astronomical financial proportions—where a single seat at an NIT or IIT is valued at tens of lakhs of rupees—that domestic syndicates possessed the capital to hire world-class international cyber mercenaries to dismantle state security systems.

In response to the Sonepat breach, the Ministry of Education and the NTA were forced to execute sweeping, permanent reforms across India's digital testing network:

  • True Physical Air-Gapping: Abolishing the use of public internet gateways during active examination hours. Exam content is now delivered via pre-encrypted local server caches requiring dual-key cryptographic authorization from both NTA headquarters and the local observer.
  • Hardware-Level Terminal Locking: Physical epoxy sealing and hardware-level BIOS disabling of all unused USB ports, secondary network interface cards (NICs), and expansion slots on every terminal machine.
  • Keystroke and Click Velocity Analytics: Implementation of real-time AI algorithms that monitor candidate interaction patterns. Sudden bursts of correct answers submitted without cursor hesitation, or rapid completion of complex multi-step numerical calculations, now trigger automatic anomaly flags and post-exam forensic review.
  • Biometric Continuous Verification: Replacing single-point entry fingerprint checks with multi-stage biometric logging to ensure that the individual sitting in the cubicle matches the candidate in the official database at every stage of the test.

8. Chronological Case Timeline

Date & Time Authority / Entities Involved What Happened & Case Developments Verified Source Link
2021-08-20 Affinity Education Pvt. Ltd. Coaching directors Siddharth Krishna, Vishwambhar Mani Tripathi, and Govind Varshney assemble a network of prospective engineering candidates, collecting post-dated cheques of ₹12–15 lakh and original academic marksheets for guaranteed top percentiles in JEE Main Session 4. The Hindu Investigation
2021-08-26 to 2021-09-01 Innov8 Centre Sonepat & CBI Operatives In the 4th session of JEE Main, compromised computer terminals at Innov8 Education Centre in Sonepat, Haryana, are hijacked using custom malware that bypasses the TCS iLeon secure browser, allowing remote solvers in Delhi-NCR safehouses to complete test papers in real time. NDTV News Bureau
2021-09-02 (Dawn) Central Bureau of Investigation (CBI) CBI registers Regular Case RC2212021E0009 and conducts simultaneous dawn raids across 19 locations in Delhi-NCR, Pune, Jamshedpur, Indore, and Bengaluru; seizes 30 laptops, 20 personal computers, exam logins, and dozens of post-dated cheques. CBI Official Press Release
2021-09-03 CBI Anti-Corruption Branch CBI formally arrests Affinity Education directors Siddharth Krishna and employees, remanding them to police custody; interrogations reveal the involvement of an international foreign hacker who wrote the exploit code. India Today Crime Desk
2021-09-05 National Testing Agency (NTA) NTA issues an official advisory confirming full cooperation with the CBI; blacklists the Innov8 centre in Sonepat and begins digital anomaly audits on response sheets exhibiting unnatural timing spikes. Hindustan Times Education
2021-09-15 National Testing Agency (NTA) NTA declares JEE Main 2021 results; scores of 20 implicated candidates are withheld, and subsequent formal orders debar them from appearing in JEE exams for a period of three years. Livemint National Report
2021-11-12 CBI Cyber Crimes Division CBI digital forensic analysis traces the proprietary remote-execution malware that breached TCS iLeon back to digital infrastructure in Russia; Bureau of Immigration issues a global Lookout Circular (LOC) against Russian software developer Mikhail Shargin. The Hindu National Desk
2022-10-03 Bureau of Immigration & CBI Russian national Mikhail Shargin is intercepted at Indira Gandhi International Airport in New Delhi upon arrival from Almaty, Kazakhstan, following the active LOC, and handed over to CBI sleuths. Times of India Front Page
2022-10-04 Rouse Avenue District Courts, New Delhi Chief Metropolitan Magistrate at Rouse Avenue Courts remands Mikhail Shargin to CBI custody; CBI tells the court that Shargin tampered with TCS iLeon software to facilitate remote solving for 820+ candidates across India. NDTV Legal Coverage
2022-10-10 Special CBI Court, Rouse Avenue Rouse Avenue Court extends Shargin's custody as forensic experts decrypt encrypted foreign hard drives, cloud backups, and cryptocurrency transactions linked to coaching networks across India. The Indian Express Crime Bureau
2023–2024 Ministry of Education & NTA Ministry of Education enforces comprehensive security overhaul for all computer-based examinations: mandatory air-gapped physical networks, two-step biometric checks, hardware port disabling, and continuous keystroke velocity monitoring. Ministry of Education Annual Report

9. Sources & Further Reading

  1. JEE (Main): CBI searches 19 locations in Delhi-NCR, Pune, Bengaluru

Publication: The Hindu

Date: September 2, 2021

Direct URL: https://www.thehindu.com/news/national/jee-main-cbi-searches-19-locations-in-delhi-ncr-pune-bengaluru/article36254429.ece

  1. JEE exam scam: CBI arrests Russian national who allegedly hacked software

Publication: NDTV

Date: October 4, 2022

Direct URL: https://www.ndtv.com/india-news/jee-exam-scam-cbi-arrests-russian-national-who-allegedly-hacked-software-3401569

  1. CBI arrests Russian national in JEE Main 2021 software hacking case

Publication: The Hindu

Date: October 4, 2022

Direct URL: https://www.thehindu.com/news/national/cbi-arrests-russian-national-in-jee-main-2021-software-hacking-case/article65969562.ece

  1. CBI gets two more days' custody of Russian national in JEE Main 2021 scam

Publication: The Indian Express

Date: October 10, 2022

Direct URL: https://indianexpress.com/article/cities/delhi/cbi-gets-two-more-days-custody-of-russian-national-in-jee-main-2021-scam-8197779/

  1. JEE Main 2021 scam: NTA cooperating with CBI to investigate malpractices

Publication: Hindustan Times

Date: September 4, 2021

Direct URL: https://www.hindustantimes.com/education/admissions/jee-main-2021-scam-nta-cooperating-with-cbi-to-investigate-malpractices-101630740925586.html

  1. JEE Main results declared; NTA withholds scores of candidates involved in cheating scam

Publication: Livemint

Date: September 15, 2021

Direct URL: https://www.livemint.com/news/india/jee-main-results-declared-nta-withholds-scores-of-candidates-involved-in-cheating-scam-11631698245892.html

  1. Central Bureau of Investigation (CBI) Investigation Registry

Document: FIR No. RC2212021E0009 and Press Bulletins on Russian National Arrest

Direct URL: https://cbi.gov.in

  1. Rouse Avenue District Courts Judicial Record

Forum: Court of Special Judge (CBI), Rouse Avenue Court Complex, New Delhi

Direct URL: https://delhidistrictcourts.nic.in

RELATED INVESTIGATIONS & ARCHIVE DOSSIERS

READ DOSSIER →THE GHOST CURSORS OF MEERUT UP POLICE SI 2017READ DOSSIER →THE MIDNIGHT HEIST AT SAHIBABAD AIPMT 2009READ DOSSIER →THE SPLICED FACES OF DHOLPUR HOUSE UPSC 2007
← BACK TO ALL NEWS

Comments

0

Want to participate in the discussion?

Sign in with Google→

No comments yet. Start the discussion above.