19-Year-Old Indian Cybersecurity Researcher Nisarga Adhikary Recognised by US DOJ After Reporting Critical Vulnerability
NEW DELHI: 19-year-old Indian cybersecurity researcher Nisarga Adhikary has been recognised on the US Department of Justice (DOJ) cybersecurity acknowledgements page after reporting a vulnerability that he described as critical in one of the department’s major law-enforcement systems.
Adhikary credited by US Department of Justice
Adhikary shared the development on X on September 22, posting a screenshot of the DOJ’s cybersecurity acknowledgements page. The page recognises researchers who have responsibly disclosed valid vulnerabilities to the department.
Speaking to India Today Tech, Adhikary said, “I found a critical vulnerability in one of their largest law enforcement systems.” He did not disclose the name of the affected system or provide technical details about the vulnerability.
Vulnerability reported and patched
According to Adhikary, he reported the issue roughly a week before the recognition. He said the DOJ validated the finding, patched the vulnerability within a week and subsequently credited him on its Hall of Fame and acknowledgements page.
Explaining how he discovered the issue, Adhikary said, “I found this myself when browsing their site and by using some custom scripts.” He also clarified that he did not receive any payment for reporting the vulnerability.
DOJ has a vulnerability disclosure programme
The DOJ has an official Vulnerability Disclosure Policy that allows security researchers to conduct good-faith research on publicly accessible DOJ websites and services and report security vulnerabilities.
The policy requires researchers to limit testing to what is necessary to confirm a vulnerability. It also prohibits activities such as data exfiltration, privilege escalation, lateral movement and disruption of DOJ services.
Other US government systems
Adhikary’s cybersecurity work has also extended to other US government systems. He told India Today Tech that he had reported a vulnerability in a US Department of Defense or military system. According to him, the vulnerability was validated and remediation is still underway.
Earlier work in India
Earlier this year, Adhikary gained attention in India after reporting security vulnerabilities in the Central Board of Secondary Education’s On-Screen Marking portal. He was also appointed as an Open-Source Intelligence and Threat Intelligence Engineer at C3iHub, IIT Kanpur, in June 2026.
The DOJ acknowledgement adds another milestone to Adhikary’s cybersecurity research work. However, the department has not publicly disclosed technical details of the vulnerability he reported or identified the specific law-enforcement system involved.
