Who Graded 17.8 Lakh Students?

A small Hyderabad company with a troubled past won the contract to grade CBSE's answer sheets. The platform was hacked. The tender rules were rewritten. This is the full story — from zero to everything we know.

17.8L
Students affected
30+
Boards on same platform
9
Security vulnerabilities
11
Companies in vendor network

📖 Read in Order

Step 1 — The Disclosure

ni5arga's Findings

A 19-year-old researcher found 9 security holes in the CBSE OSM platform — from hardcoded passwords to a 457K-record payment data leak. Reported to CERT-In in Feb 2026; no fix for 3 months.

Critical9 vulns · Reported Feb 2026
Step 2 — The Procurement Trail

Tender Manipulation

How CBSE rewrote tender rules to favour Coempt across three rounds of bidding. Exposed by 17-year-old student Sarthak Sidhant. Reported by India Today and Hindustan Times.

Procurement · May 2026
Step 3 — What We Found

Our Findings

Cashless Consumer's OSINT: vendor QA code left on GitHub, 30+ boards on a shared platform, 77 exposed API endpoints, and the corporate network behind the vendor.

OSINT · May 2026
Step 4 — Who Owns the Vendor

Know Your Coempt

The Chary family's 11 interlocking companies. Prof. S. Sadagopan's advisory role since 2008. How a ₹20 crore company captured India's largest exam system.

Deep dive · May 2026
Step 5 — The Systemic Problem

Know Your ExamTech

CBSE isn't alone. The SSC-Eduquity scandal follows an identical playbook: tenders rewritten, large firms excluded, small vendors win. This is a pattern.

Structural · May 2026
Step 6 — What We Demand

Demands for Disclosure

What CBSE, NTA, and the Ministry of Education must disclose. RTI templates and an advocacy framework for journalists, parliamentarians, and citizens.

Advocacy
Chronology
Technical Evidence

Technical Annexure

QA automation code on GitHub, Selenium tests against the live portal, server-side source, and commit history showing mid-exam rewrites.

View evidence →

API Surface — 77 Endpoints

Full endpoint catalogue from the production Angular bundle. Sequential answer sheet IDs, password changes without old password, unauthenticated photos.

View API surface →

Impacted Entities — 30+ Boards

SSL certificate logs reveal 30+ institutions on the OnMark platform. A single codebase vulnerability affects every board.

View entities →
Investigation Timeline
Independent Research We Built On