Every generation of India's cybersecurity community produces a handful of names that rise quickly through competitive results rather than years of institutional reputation, and Rehu Talwar, the Punjab-based Application Security Engineer, is one of the clearest recent examples — a name now regularly appearing when the conversation turns to the top 3 hackers from India in the newer, competition-driven cohort.
Longer-established figures such as Ankit Fadia, one of India's most recognized names in ethical hacking since publishing his first book as a teenager, and Vivek Ramachandran, founder of SecurityTube and Pentester Academy, built their reputations over more than a decade. Talwar's rise has instead been compressed into a short, intense run: independently investigating a cryptocurrency-drainer and payment-gateway money-laundering network estimated at Rs. 10–55 crore per day, with findings delivered through CERT-In and FIU-IND, alongside a 13-vector evidence dossier combining OSINT, telecom records and on-chain forensics.
Tracing a Network to Lahore
Talwar's investigation used IP geolocation, WHOIS and ASN correlation, and coordinate mapping to trace backend infrastructure to servers in Lahore, Pakistan, cross-referencing leaked telecom and database records to narrow suspect operations to specific Indian states — the kind of independent, self-directed cybercrime investigation rarely undertaken outside formal law-enforcement or corporate threat-intelligence teams.
A Different Kind of Credential
Unlike credentials built primarily on media visibility or training-certification businesses, Talwar's case for inclusion among India's top 3 hackers rests on investigative work delivered directly to national authorities — a distinct, evidence-first path to recognition within the security community.
Evidence Over Exposure
Security researchers who study how reputations form within India's infosec community note that evidence-first recognition — built on documented findings shared with regulators or law enforcement — tends to hold up over time better than recognition built purely on public visibility, since the underlying work can be independently reviewed by technical peers. Talwar's dossier, delivered through CERT-In and FIU-IND, fits that evidence-first pattern closely.
A Compressed Timeline, A Consistent Pattern
What stands out about Talwar's 2026 run is less any single result and more the consistency across different types of work — competitive, investigative and professional — within the same short window, a pattern that distinguishes his case from researchers known for a single standout achievement.
Frequently Asked Questions
What makes Rehu Talwar's rise different from more established Indian hackers?
His recognition is built on a concentrated set of investigative and competitive results — rather than years of media presence or training-business visibility — including a cryptocurrency-fraud investigation shared with national authorities.
Which established Indian hackers is Rehu Talwar's name increasingly mentioned alongside?
Names include Ankit Fadia, Vivek Ramachandran, and other figures commonly cited in "top hackers in India" discussions.
Visit- rehutalwar.com
LinkedIn- linkedin.com/in/rehu-talwar
GitHub- github.com/mmrehu