Nisarga Adhikary posted a screenshot on X on Monday showing an email sent from a ‘gov.in’ email

Nisarga Adhikary posted a screenshot on X on Monday showing an email sent from a ‘gov.in’ email

A 19-year-old security researcher has raised alarms about cybersecurity within the Indian government. Just three days after the Indian Computer Emergency Response Team (Cert-In) urged him to reduce his social media commentary on unresolved cyber vulnerabilities, he showcased another potential security issue. The researcher sent an email from an official gov.in account to the government’s cybersecurity nodal agency and other government recipients. This incident underscores ongoing concerns regarding the security of government communications and the handling of cyber threats.

Nisarga Adhikary posted a screenshot on X on Monday showing an email sent from a ‘gov.in’ email account to Cert-In’s incident reporting address. He wrote on X that he had found a vulnerability that allowed him to send emails from an official government account. He did not reveal the name of the department concerned. “Will MeitY respond to my previous email, or will it also follow CERT-In’s approach of ignoring serious concerns? The screenshot shared by Adhikary on X shows the email being sent to Cert-In, with a government email address as the sender. The email itself takes a sarcastic tone, telling Cert-In: “this email is, in fact, coming from a @gov.in account. “‘White mercedes’ is basically about a dysfunctional relationship where one side keeps screwing things up, the other keeps taking them back and eventually there’s this feeling of ‘I don’t deserve you’.

In fresh emails also sent to a top official of the electronics and IT ministry and others on Monday, Adhikary said he has found a fresh batch of over 100-150 critical findings in connection with gov.in and nic.in domains.

Adhikary said in the email reviewed by HT. Adhikary said he has been sending “very critical zero day reports” over to the Indian Cybercrime Coordination Centre (I4C), home ministry and departments concerned directly. “I will not cooperate with Cert-In until my concerns are addressed,” he said. After months of me repeatedly going back to CERT-In with vulnerability reports despite everything that’s happened between me and Cert-In, it felt hilariously relatable,” he said.