Exam integrity

How the NEET paper leaks happened, and how technology can prevent the next one

NEET-UG 2026 was cancelled for 2.27 million candidates after a leak. What went wrong in 2024 and 2026, why the printed paper is the attack surface, and what digital delivery changes.

Team XAM8 min read

Short answer

India's recent exam leaks were not failures of question-setting. They were failures of physical custody: a single printed paper exists days before the exam, passes through dozens of hands, and is identical for every candidate, so one compromised copy becomes a national breach. Technology cannot fix insider risk on its own. What digital-first delivery does is remove the pre-exam artefact, give every candidate a different paper, and leave an audit trail that paper never had.

What happened in NEET-UG 2026?

In May 2026 the National Testing Agency cancelled the entire NEET-UG examination for 2.27 million candidates after a leaked “guess paper” was found to overlap with as many as 140 of the 180 questions on the live paper. The CBI investigation that followed produced arrests that included NTA insiders. It is the largest single exam cancellation in Indian history.

The scale matters because of what a cancellation costs. A NEET candidate does not simply retake a test: an academic year, a coaching cycle, and in many cases a family's savings are attached to a single sitting. Cancelling one exam imposes that cost on everyone who sat it honestly. In a cohort of 2.27 million, that is very nearly all of them.

Was 2026 the first time? What did the Supreme Court say in 2024?

No. NEET-UG 2024 had already been through a full integrity crisis. Around 24 lakh candidates registered and roughly 23.3 lakh appeared. The Supreme Court, hearing the petitions that followed, described the leak as an “undisputed fact”, but declined to order a mass re-test, holding that the leak was not shown to be systemic enough to invalidate the whole exam. The only re-examination ordered covered 1,563 candidates who had been given compensatory grace marks. A CBI probe ran in parallel.

Two weeks earlier, the UGC-NET June 2024 exam had been cancelled within 24 hours of being held, affecting 9.08 lakh candidates, and referred to the CBI. Within a single month of 2024, two national exams covering more than three million candidates were compromised.

How big is the problem across Indian exams?

Big enough that it is better described as a range than a single number. Credible tallies point to roughly 50 to 90+ documented exam-integrity incidents across 8 to 15+ states over the past seven or eight years, affecting an estimated 1.4 to 1.7 crore aspirants. The more uncomfortable statistic is on the enforcement side: of 148 documented exam-fraud cases since 2015, only one has ended in a conviction.

ExamYearCandidates affectedOutcome
NEET-UG20262.27 million (22.7 lakh)Entire exam cancelled; CBI arrests including NTA insiders
NEET-UG2024~24 lakh registered · ~23.3 lakh appearedLeak called an "undisputed fact" by the Supreme Court; re-exam ordered for only 1,563 grace-marks candidates
UGC-NETJune 20249.08 lakhCancelled within 24 hours of being held; referred to the CBI
All documented casessince 2015~1.4–1.7 crore aspirants (estimate)148 documented exam-fraud cases · 1 conviction
Sources: Wikipedia (2026 NEET controversy, citing Indian Express and CBI filings), CNBC (Aug 2026), Supreme Court Observer, LiveLaw, Careers360, Tribune India, The Wire (2026).

Didn't the 2024 anti-cheating law fix this?

It did not. The Public Examinations (Prevention of Unfair Means) Act, 2024 came into force on 21 June 2024, carrying penalties of up to 10 years' imprisonment and fines of up to ₹1 crore for organised paper-leak offences. It is, on paper, one of the more severe anti-cheating statutes anywhere.

The NEET-UG 2026 cancellation happened almost two years after that law took effect. Deterrence assumes a credible probability of being caught and convicted; with one conviction in 148 documented cases, the expected cost of participating in a leak stayed low no matter what the statute said. Legislation raised the ceiling on punishment without changing the odds. That leaves the design of the exam itself as the lever nobody has pulled.

Why is the printed paper the attack surface?

Because a printed question paper is a physical object that exists, complete and unencrypted, before the exam begins. Four properties make it uniquely fragile:

  • It exists early. The content is finalised, printed and shipped days or weeks ahead of the exam. Every hour in that window is an hour in which the answer key has real market value.
  • It has many custodians. Setters, printers, transporters, storage points and centre staff all touch it. The security of the exam is the security of its weakest custodian, and each one is a person, not a control.
  • It is identical for everyone. One compromised copy leaks the exam for the entire cohort. There is no partial failure mode: a breach anywhere is a breach everywhere.
  • It leaves no forensic trail. A photographed paper circulating on a messaging app carries no record of who opened it, when, or from where. Investigations start after the damage and work backwards through testimony.

Note what is not on that list: the difficulty of the questions, the ability of invigilators, or the honesty of most candidates. The failure is in logistics, and logistics is exactly the part of an exam that digital delivery removes.

What does digital-first delivery change?

It changes the shape of the target. Instead of one artefact that must stay secret in the physical world, you have encrypted content released at exam time, drawn per candidate from a larger pool, with every action logged.

Attack surfacePrinted paperDigital-first delivery
Content before the examExists in printed form for days or weeksEncrypted at rest; decrypted only at the scheduled start
Blast radius of one leakEntire cohort; everyone sees the same paperOne candidate’s form; item pools and shuffling mean no two papers match
Custody chainPrinters, transport, storage, centre staffNo physical chain; access is role-based and logged
Identity of the test-takerPhoto ID checked visually at the deskID capture, face match and continuous presence checks during the session
InvigilationOne invigilator watching a roomPer-candidate signals: focus loss, second faces, audio, device changes
Evidence after the factTestimony and seizuresTimestamped event log and session recording per candidate
Detecting an anomalyManual, often weeks laterStatistical outlier detection on response patterns and timings, immediately
Comparison of where each delivery model can fail. Digital-first delivery does not eliminate risk; it moves it from physical custody to access control and monitoring, where it can be measured.

The single most underrated item in that table is the second row. Randomised item selection converts a catastrophic, all-or-nothing failure into a bounded one. If a candidate obtains their own paper early, it is worth exactly one candidate's advantage, and the outlier detection that follows makes even that hard to use quietly.

What about answers that are hard to fake in the first place?

Randomisation protects the question. Question format protects the answer. A four-option multiple-choice item can be answered by anyone holding the key, including someone sitting beside the candidate. A spoken or recorded response cannot: it carries the voice, the reasoning and the hesitation of whoever produced it, which makes both impersonation and key-passing considerably harder. Applied and scenario questions with working shown do the same job in text.

What should an institution running exams do now?

  1. Stop shipping the answer key ahead of the exam. If the content exists in final form before the start time, that window is your real vulnerability. Shorten it to zero.
  2. Build item banks, not papers. Assemble each candidate's form at run time from a pool several times larger than the paper.
  3. Verify identity continuously, not once at the door. ID capture plus periodic presence checks through the session.
  4. Log everything, and keep the log. Timestamped events per candidate are the evidence base a paper exam never generates.
  5. Mix in formats that resist key-passing: audio, video and worked responses alongside objective items.
  6. Put a human in front of every flag. Automated signals triage attention; they should never issue a verdict on their own.

None of this is speculative technology. It is standard practice in remote assessment, and it is what we built XAM by Ankor, an assessment platform, to do: author, deliver, AI-proctor, auto-grade and report on exams in one engine, including audio and video answers as a native question type. We mention it once, here, because the argument above stands with or without us. The paper is the attack surface either way.

Sources

XAM by Ankor

Run the assessments that break Google Forms.

One engine for delivering, grading and reporting on assessments: audio and video answers, proctoring, auto-evaluation and branded reports. Start free, no card.

Keep reading