In my last piece I wrote about parents who go looking for a shortcut, and about the ecosystem that has grown up to sell them one. There is a fair objection to that piece: most parents never make that call. What about them?
It is the better question, and the answer is worse. Because a family does not have to attempt anything dishonest to be worked over by this system. There is a second economy operating alongside the first, and its raw material is the honest applicant. In that trade she is not a student. She is a lead. She has a price, she is sold by the sheet, and she will never find out.
What follows is a plain description of practices I have seen or had reported to me over years in academic administration. I have deliberately kept every example structural. Naming institutions would let every unnamed one off the hook, and the point here is that none of this is exotic. Anyone who has run an admission office will recognise all of it.
1. The list gets out before she gets a reply
The first thing that is sold is not a seat. It is her name, her marks, her phone number and her father’s phone number. This happens through three channels, and they differ mainly in price.
The register at the gate. Every visitor to a campus signs in — name, phone, purpose of visit, which course the child is asking about. That open book sitting on the security desk is, in commercial terms, a daily feed of qualified prospects. It is photographed on a phone and sold, in some places on a standing daily arrangement. The guard or receptionist who does it is very often the lowest-paid person on the premises, entrusted, without anyone quite deciding to entrust him, with the most commercially valuable asset the institution generates that day.
The applicant database. Everything a student submits to apply — the complete, verified, self-declared profile — sits in one system. The weak point is almost never the admission staff. It is the person with database access: often a contract engineer, frequently employed through a vendor, whose annual salary is less than the market value of a single export. Nobody logs bulk exports. Nobody reviews who holds them. The file reaches competitors in the region within days, and the institution never learns it happened.
The entrance examination data. This is the most valuable of the three, and the most serious. A state or national entrance test produces something no private party can assemble: a complete, scored, ranked list of every serious candidate in the country, with contact details attached. Where that data has been accessible to people willing to sell it, it has been sold — to agencies, who package and resell it to institutions as a subscription product. An examination conducted under public authority becomes a commercial catalogue.
Notice what is missing from all three. There is no breach notification. No student is ever told that her data left the building. There is no complainant, because the victim does not know she is one, and there is consequently almost never a case.
2. She is intercepted before she reaches the gate
Once the list exists, the second market opens: diverting a candidate who had already decided where she wanted to go.
It begins on the phone. An agent calls, speaking as though from the institution — confirming her application, discussing her marks, sounding entirely official — and steers the conversation towards somewhere else that has paid for the referral. The family has no way to verify who is calling. The number is not the institution’s, but they have no reason to check a call that already knows their child’s rank.
It continues at the campus itself, where agents operate both outside the gate and, in many places, inside it. They are helpful, they are informed, they carry brochures, and to a family arriving in an unfamiliar city they are indistinguishable from staff.
Then there is the version that troubles me most, because it leaves no trace at all. A family travels overnight. They reach the counter. They are told the course is full, or the admissions have closed, or the department has shifted to another campus. None of it is true. They believe it — why would they not? — and they leave. On paper, nothing has happened. There is no record of a visit, no rejection to appeal, no decision anyone made. A student was removed from the process by a sentence spoken across a desk.
At the far end of this sits the arrangement that reaches into the records themselves — an understanding with someone on the admission team to adjust a list, delay an entry, or advance a file. It usually starts with junior or temporary staff, who are cheapest to reach and easiest to disown. It does not always stay there.
3. The test nobody watches
Where an institution conducts its own entrance test, and where a particular course is in high demand, the score itself becomes negotiable.
It is worth being precise about why this is possible. A national examination, whatever its failings, operates under scrutiny — observers, custody protocols, video, independent evaluation, published statistics, and a press that will report a leak. An institution-level test frequently has none of that. The paper is set internally, administered internally, evaluated internally, and published as a rank list with nothing underneath it that anyone outside can examine. There is no distribution of scores, no evaluator audit, no external observer. The result is simply announced, and the institution is the only body in a position to know whether it is true.
We have, in other words, placed the most contested decisions in the least observed process.
4. Four institutions, one name
The last practice is the quietest, and often not illegal at all.
Where a group runs several institutions under closely similar names, a family can go through the entire admission process believing they have joined the campus they researched — the one with the reputation, the faculty, the placement record, the photographs — and discover afterwards that they have joined a different institution with a similar name, in a different location, with different approvals and a different accreditation.
Very often nothing in the prospectus is false. The literature is shared, the branding is shared, the achievements of the strongest campus are described in group terms, and the specific legal identity of the institution the student is actually joining is present somewhere in the fine print. The ambiguity is not created by a lie. It is created by a design decision not to clear it up, and then maintained because clearing it up would cost admissions.
What the pattern tells us
Set the four side by side and something becomes visible that no individual complaint would reveal.
First, the malpractice tracks the student’s journey step by step. She submits her details and they are sold. She is contacted and she is diverted. She arrives and she is turned away. She sits the test and it is bent. She enrols and she is misled about what she has enrolled in. Every honest step she takes has a corresponding market waiting for it. This is not a series of separate scams. It is one supply chain with several handoffs.
Second, almost none of it requires the family to be dishonest. This is what separates it from what I described in the previous piece. There is no bribe here, no shortcut sought, no favour asked. The victim’s only mistake was to participate in the process in good faith.
Third, and this is the part institutions must sit with: every weak point is a person we have chosen not to pay, not to train, and not to supervise. The security guard with the register. The receptionist at the enquiry desk. The contract engineer with database credentials. The temporary clerk in the admission cell. We route the most valuable and most sensitive material an institution handles through the hands of the people we have given the least reason to protect it, and then we are surprised. That is not primarily a moral failure. It is a design failure, and it is ours.
Fourth, nearly all of it is invisible by construction. No record is created. No complainant exists. In several cases no clear offence has been committed. A system that can only respond to complaints will never see any of this, because the people harmed do not know they were harmed.
What can actually be done
I am wary of grand prescriptions. But most of this is defeated by ordinary administrative measures that any serious institution can adopt without waiting for anybody’s permission.
Treat the visitor register as regulated data. No open book at the gate. Digital entry, access-controlled, retained no longer than needed, with nobody able to view the day’s full list except a named officer.
Log every bulk export from the applicant database. Every export, by whom, of how many records, reviewed monthly by someone outside the IT function. Vendor and contract staff should not hold unlogged export rights on student data, and in most institutions today they do.
Seed the database. This one is cheap, legal and remarkably effective. Insert a small number of decoy applicant records carrying phone numbers the institution controls. If a decoy receives a call from an agency or a competitor, you have learnt three things at once: that your data is leaking, roughly when it leaked, and — from which seeded batch was hit — where it leaked from. Institutions that do this find out in weeks what they would otherwise never learn at all.
Make the enquiry counter leave a trace. Every walk-in enquiry gets a logged entry and a printed acknowledgement handed to the family, with a reference number, the date, and the course they asked about. It costs almost nothing, and it makes “the seat is gone” into a statement someone can be asked about later. Practices that leave no record survive precisely because they leave no record.
Open up institution-level entrance tests. External observers, question paper custody protocols, evaluation separated from the department that owns the course, and publication of the full score distribution rather than a bare rank list. If the process is sound, none of this costs anything but effort.
And require every offer letter to identify exactly what is being offered — the specific legal name of the institution, its own approvals and its own accreditation, and the postal address of the campus where teaching will take place. Not the group’s. The institution’s. No family should discover in week two which college they joined.
For those who write the rules, one addition seems to me overdue: candidate data generated by a public entrance examination should carry the protections we would demand for any other sensitive personal data, with named custodians, audit trails, and an obligation to tell a candidate when her information has been compromised. At present a student’s academic profile is one of the most freely traded datasets in the country, and she is the only person in the transaction with no say in it.
The student nobody protected
Picture the girl this all happens to. She fills in her form honestly. Her details are sold before anyone reads the form. She is called by someone who sounds official and steered somewhere she had not chosen. She travels overnight to the campus she wanted and is told at the counter that the seat is gone. She takes an institutional test whose result she cannot question. She joins a college believing it is the one in the photographs.
At no point did she or her parents attempt a single dishonest thing. And at no point did the system extend her the slightest protection.
My previous piece was about the people who go looking for a shortcut. This one is about the people who never did. The second group is far larger, and we owe them considerably more than we have given them.
This post follows on from Unfair Means in Education: The Ecosystem We Have Built.