Breach report
CUET-UG 2026 candidate records offered for sale online; source of leak unknown

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
MediaNama found about 15.57 lakh CUET-UG 2026 records among 41 exam and coaching databases on sale. Candidates confirmed samples. NTA says it shares data only through secure channels.
What happened
MediaNama reported on 8 July 2026 that three ordinary-looking shopping websites were selling 41 databases from 2026 exams and coaching institutes. One listing claimed 15,56,840 CUET-UG 2026 candidate records for ₹6,999. Other listings named CUET-PG, CMAT, SNAP, XAT, NMAT, MAT, state entrance tests and a coaching chain's rosters. Medical Dialogues, citing a News18 report, said sellers offered names, mobile numbers, email addresses, parents' names, application numbers and dates of birth, including free sample files.
Confirmed vs. claimed
Confirmed: the data is on sale. MediaNama called more than ten people from a sample and six confirmed their details matched.
Unknown: where the data came from. MediaNama suggested a shared upstream source such as a coaching chain, vendor or ed-tech platform, but no origin has been established. There is no evidence that the National Testing Agency's (NTA) own systems were breached. NTA said it gives top priority to candidate privacy and shares exam data with universities only through DigiLocker and authorised APIs. MeitY reportedly said it would look into the matter.
Who is affected
Students who registered for CUET-UG 2026 and the other listed exams, and their parents. The tracker's 1.6M figure is the seller's count, rounded; it has not been independently verified.
What to do
- Expect admission, scholarship and "seat confirmation" calls that quote your application number. Do not pay any fee except on the official university or NTA site.
- Never share OTPs or install screen-sharing apps at a caller's request.
- Report fraudulent calls and messages on Chakshu in the Sanchar Saathi portal.
- If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
- More steps: what to do after a data breach notice.
Sources
More breaches in India
- Dodo Payments — 17 Aug 2026
- Bank of Baroda — 28 Jul 2026
- Reliance Infrastructure (Kudankulam project data) — 16 Jul 2026
- UMANG (MeitY government services app) — 14 Jul 2026
- IDRBT (.bank.in domain registry) — 29 Jun 2026