Skip to main content

Cyber Crimes in India

Learning Objectives

By the end of this topic, you should be able to:

  • Explain the scheme of the Information Technology Act, 2000 and its relationship with the IPC/Bharatiya Nyaya Sanhita, 2023.
  • Distinguish the civil liability provisions (Sections 43, 43A) from the criminal offences (Sections 65-67B) of the IT Act.
  • Identify the correct section for common cyber offences: hacking, identity theft, cheating by personation, voyeurism, cyber terrorism, and online obscenity.
  • Analyse Shreya Singhal v. Union of India (2015) and its impact on free speech online.
  • Describe intermediary "safe harbour" under Section 69A/79 and the blocking regime.
  • Apply jurisdictional and evidentiary rules (Section 65B, Indian Evidence Act / Section 63, BSA) to cybercrime fact patterns.

Quick Answer

Cyber crimes are offences committed using, or targeting, computers, networks, or digital data — hacking, identity theft, online fraud, cyberstalking, publication of obscene content, and cyber terrorism. In India they are governed primarily by the Information Technology Act, 2000 (substantially amended in 2008), supplemented by the general criminal law (IPC, now the Bharatiya Nyaya Sanhita, 2023). The IT Act creates a two-layer scheme: civil compensation for unauthorised access and data negligence (Sections 43, 43A) and criminal offences (Sections 65-67B, 66F). The subject matters because almost every modern offence — fraud, defamation, harassment, terrorism — now has a digital dimension, and because Shreya Singhal (2015) made cyber law a central battleground for free speech.

Overview

When the IT Act was enacted in 2000, its main purpose was to give legal recognition to electronic records and digital signatures for e-commerce. Cybercrime provisions were almost an afterthought. The 2008 Amendment — passed after the 26/11 Mumbai attacks — transformed the Act into India's principal cybercrime statute, adding identity theft, cheating by personation, voyeurism, cyber terrorism, and child sexual abuse material offences.

Two structural ideas organise this topic. First, computer as target vs. computer as tool: hacking attacks the computer itself; online cheating merely uses it as an instrument. Second, overlap with general criminal law: the IT Act does not displace the IPC/BNS — a phishing fraud can be charged under both Section 66D of the IT Act and Section 318 BNS (cheating). Section 81 of the IT Act gives it overriding effect where the two conflict, and courts have held that where the IT Act is a complete code on a subject (e.g., electronic obscenity), it prevails over general provisions (Sharat Babu Digumarti v. Govt. of NCT of Delhi, 2017).

Core Concepts

1. Unauthorised Access and Hacking (Sections 43 and 66)

Definition. Section 43 imposes civil liability (compensation by way of damages) on anyone who, without permission of the owner, accesses a computer, downloads data, introduces a virus, damages a system, or denies access. Section 66 makes the same acts a criminal offence when done dishonestly or fraudulently — punishable with imprisonment up to 3 years or fine up to ₹5 lakh, or both.

Explanation. The 2008 Amendment deliberately split wrongs by mental state: mere unauthorised access (however negligent) attracts compensation under Section 43, adjudicated by an Adjudicating Officer for claims up to ₹5 crore; the same act plus dishonest or fraudulent intent (borrowing the IPC definitions of "dishonestly" and "fraudulently") becomes the crime under Section 66. This is why the word "hacking", which appeared in the old Section 66, was dropped — the new structure is act (S.43) + mens rea (S.66).

Example. An employee curious about salaries opens the HR database without permission — Section 43 compensation. If he copies the data to sell to a rival, the dishonest intention converts it into a Section 66 offence.

Real-World Example. In Poona Auto Ancillaries Pvt. Ltd. v. Punjab National Bank (2013), Maharashtra's IT Adjudicator awarded compensation where phishing losses occurred, holding the bank partly responsible for weak security — an illustration of Section 43/43A civil adjudication in action. Section 43A separately makes a body corporate handling sensitive personal data liable to pay compensation for negligence in maintaining "reasonable security practices".

Why It Matters. Exam questions love the 43/66 distinction — one is civil, one criminal, and the dividing line is mens rea. In practice, victims often pursue the faster adjudication route for compensation alongside criminal complaints.

Common Misunderstanding. Students often write that "Section 66 punishes hacking with unauthorised access simpliciter". Wrong — access without dishonest/fraudulent intent is only a civil wrong under Section 43.

2. Identity Theft and Cheating by Personation (Sections 66C and 66D)

Definition. Section 66C punishes fraudulent or dishonest use of another person's electronic signature, password, or any other unique identification feature — imprisonment up to 3 years and fine up to ₹1 lakh. Section 66D punishes cheating by personation using a computer resource or communication device — same punishment.

Explanation. These are the workhorse provisions of Indian cybercrime enforcement. Section 66C targets the misappropriation of identity credentials (passwords, OTPs, biometric data, digital signatures); Section 66D targets the deception — pretending to be someone or something you are not, online, to cheat a victim. A typical phishing scam involves both: stealing credentials (66C) and impersonating a bank (66D), usually charged along with cheating under Section 318 BNS (formerly Section 420 IPC).

Example. A fraudster calls posing as a bank officer, obtains an OTP, and drains an account. Using the OTP is 66C; the impersonation-based deception is 66D.

Real-World Example. The "digital arrest" scams of 2024, where fraudsters posed as CBI or customs officers on video calls and extorted money from victims, were prosecuted under Sections 66C/66D IT Act read with cheating and extortion provisions of the BNS. During the UPI boom, 66C/66D became the most invoked cyber provisions in India.

Why It Matters. Financial cyber fraud is the most common cybercrime reported on the National Cyber Crime Reporting Portal (cybercrime.gov.in, helpline 1930). Any practising lawyer will encounter these sections.

Common Misunderstanding. Section 66D does not require that the impersonated person exists — pretending to be a fictitious officer or a non-existent company still qualifies, because the essence is cheating by personation, not injury to the person impersonated.

3. Privacy Offences: Voyeurism and Obscenity (Sections 66E, 67, 67A, 67B)

Definition. Section 66E punishes intentionally capturing, publishing, or transmitting the image of a private area of a person without consent, violating privacy (up to 3 years or ₹2 lakh fine). Section 67 punishes publishing or transmitting obscene material electronically; Section 67A covers sexually explicit material; Section 67B covers child sexual abuse material (CSAM), including browsing and downloading.

Explanation. Section 67 adopts the classic obscenity test (lascivious, appealing to prurient interest, tending to deprave and corrupt) — the electronic counterpart of Section 294 BNS (old S.292 IPC). The gradation matters: 67 (obscene) → 67A (sexually explicit — higher punishment, first conviction up to 5 years) → 67B (children — strictest, even collection and browsing punished). Section 66E overlaps with voyeurism under Section 77 BNS (old S.354C IPC), but 66E is gender-neutral while the BNS provision protects women specifically.

Example. Secretly filming someone in a changing room and sharing the clip: Section 66E (privacy) plus Section 67/67A (transmission of obscene/explicit content) plus BNS voyeurism if the victim is a woman.

Real-World Example. In Avnish Bajaj v. State (the Bazee.com case, 2005), the CEO of an e-commerce platform was arraigned when an obscene MMS clip was listed for sale on the site — the controversy fed directly into the 2008 amendments on intermediary liability. Later, in Sharat Babu Digumarti (2017), the Supreme Court held that for electronic obscenity, the IT Act excludes prosecution under the IPC obscenity provision — special law prevails.

Why It Matters. Non-consensual intimate imagery ("revenge porn") is among the fastest-growing complaints by women; these sections, with POCSO for minors, are the prosecutorial toolkit.

Common Misunderstanding. Students confuse 66E (privacy violation by capturing/transmitting private-area images) with 67 (obscenity generally). A leaked private image may not be legally "obscene", yet still squarely violates 66E.

4. Cyber Terrorism (Section 66F)

Definition. Section 66F punishes cyber terrorism — acts done with intent to threaten the unity, integrity, security, or sovereignty of India or to strike terror, by denying access to computer resources, unauthorised access, or introducing contaminants, causing (or likely to cause) death, injury, damage to property, or disruption of essential supplies and services; also knowingly accessing restricted data with reason to believe it may harm the sovereignty of India. Punishment extends to imprisonment for life.

Explanation. Introduced in 2008 post-26/11, this is the gravest IT Act offence. Its structure mirrors terrorism law: a specified intent (threatening national security/striking terror) plus a specified means (attacks on computer resources or protected systems) plus consequences (actual or likely harm). "Protected systems" declared under Section 70 — power grids, banking backbones, defence networks — receive special protection, with the National Critical Information Infrastructure Protection Centre (NCIIPC) as the nodal agency.

Example. A coordinated attack that shuts down a city's electricity grid to create panic would be cyber terrorism; the same technical act done by a bored student to show off, without terrorist intent, would fall under Sections 43/66 instead.

Real-World Example. The 2022 ransomware attack on AIIMS Delhi, which crippled hospital servers for weeks, was investigated as cyber terrorism under Section 66F given the targeting of critical health infrastructure.

Why It Matters. It shows how mens rea scales punishment in cyber law: identical technical conduct ranges from civil compensation to life imprisonment depending on intent and target.

Common Misunderstanding. Not every large-scale hack is "cyber terrorism". Without the intent to threaten India's security or strike terror, even massive data breaches remain within Sections 43/66/72A.

5. Free Speech Online and Intermediary Liability (Sections 66A struck down, 69A, 79)

Definition. Section 66A criminalised sending "grossly offensive" or "menacing" messages online — struck down as unconstitutional in Shreya Singhal v. Union of India (2015). Section 69A empowers the Central Government to block public access to online content on grounds tracking Article 19(2). Section 79 grants intermediaries (ISPs, platforms) "safe harbour" from liability for third-party content, conditional on due diligence and takedown upon actual knowledge.

Explanation. Shreya Singhal is the constitutional heart of Indian cyber law. The Supreme Court held Section 66A vague and overbroad — terms like "grossly offensive" and "annoyance" chilled protected speech and were not saved by Article 19(2). The same judgment (i) upheld Section 69A blocking with its procedural safeguards, and (ii) read down Section 79: intermediaries lose safe harbour only on failing to remove content after a court order or government notification, not on mere private complaints. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 now prescribe detailed due-diligence, grievance officers, and traceability obligations for significant social media intermediaries.

Example. A defamatory post appears on a platform. The platform is not automatically liable; it must act when it receives actual knowledge through a court/government order — failing which it loses Section 79 protection.

Real-World Example. Section 66A arrests of two young women in Palghar (2012) for a Facebook post questioning Mumbai's shutdown after a politician's death triggered the Shreya Singhal challenge. Despite the 2015 striking down, prosecutions under 66A persisted, prompting the Supreme Court in PUCL v. Union of India (2021-22 directions) to order all pending 66A cases closed.

Why It Matters. This cluster defines the constitutional limits of criminalising online speech and the allocation of responsibility between users, platforms, and the State — a favourite essay and viva topic.

Common Misunderstanding. "Section 66A was struck down, so offensive messages online are now legal." No — targeted conduct remains punishable under specific provisions: defamation (S.356 BNS), criminal intimidation (S.351 BNS), stalking (S.78 BNS), obscenity (S.67 IT Act). What fell was the vague catch-all, not accountability for online speech offences.

Visual Learning

Choosing the Right IT Act Provision

Evolution of Indian Cyber Law

Key Terms

TermDefinitionContext
Computer resourceComputer, computer system, network, data, database — S.2(1)(k) IT ActGateway definition for most offences
Section 43Civil liability for unauthorised access, damage, viruses, denial of accessCompensation via Adjudicating Officer
Section 43ABody corporate's liability for negligent handling of sensitive personal data"Reasonable security practices"; now read with DPDP Act, 2023
Section 66Criminal counterpart of S.43 acts done dishonestly/fraudulentlyUp to 3 years; replaced old "hacking" offence
Section 66CIdentity theft — misuse of password/e-signature/unique IDPhishing, OTP fraud
Section 66DCheating by personation using computer resourceFake profiles, "digital arrest" scams
Section 66ECapturing/publishing private-area images without consentOverlaps voyeurism, S.77 BNS
Section 66FCyber terrorismUp to life imprisonment; post-26/11 addition
Sections 67/67A/67BElectronic obscenity / sexually explicit material / CSAMGraded severity; 67B punishes even browsing
Section 69AGovernment power to block online contentUpheld in Shreya Singhal
Section 79Intermediary safe harbourConditional on due diligence; 2021 Rules
Section 65B Evidence Act / S.63 BSACertificate for admissibility of electronic recordsAnvar v. Basheer (2014); Arjun Panditrao (2020)
Protected systemCritical infrastructure notified under S.70NCIIPC nodal agency

Common Mistakes

  1. Misconception: "Section 66 punishes any unauthorised access to a computer." Why it's wrong: Unauthorised access alone is only a civil wrong under Section 43. Section 66 criminalises Section 43 acts only when done dishonestly or fraudulently. Correct: Ask two questions — was there a Section 43 act, and was there dishonest/fraudulent intent? Both must be yes for criminal liability under Section 66.

  2. Misconception: "After Shreya Singhal, no one can be prosecuted for online messages." Why it's wrong: The judgment struck down only the vague Section 66A. Specific, narrowly drawn offences survive: online defamation, criminal intimidation, stalking (BNS), obscenity (S.67), and blocking under S.69A was expressly upheld. Correct: Online speech is punishable where it fits a defined offence within Article 19(2) grounds; only the catch-all criminalisation of "offensive" speech is gone.

  3. Misconception: "Platforms are automatically liable for everything users post." Why it's wrong: Section 79 gives intermediaries safe harbour if they observe due diligence and act on takedown obligations; Shreya Singhal read "actual knowledge" to mean a court order or government notification, not private complaints. Correct: Intermediary liability is conditional — it arises on failure to comply with the 2021 Rules or to remove content after authorised notice.

Comparison and Connections

PointSection 43 (IT Act)Section 66 (IT Act)Section 66F (IT Act)
NatureCivil wrongCriminal offenceAggravated criminal offence
Mental elementNone requiredDishonest/fraudulent intentIntent to threaten India's security / strike terror
ConsequenceCompensation (Adjudicating Officer)Up to 3 years and/or ₹5 lakhUp to life imprisonment
Frequently confused pairDistinction
S.66C vs S.66D66C = misusing identity credentials; 66D = deceiving someone by impersonation
S.66E vs S.6766E = privacy violation (private-area images); 67 = obscenity test (prurient content)
IT Act vs BNS offencesIT Act is the special law for computer-focused wrongs; BNS supplies general offences (cheating, defamation, stalking); special law prevails on overlap (Sharat Babu Digumarti)

This topic connects to White Collar Crimes (online financial fraud), Crimes Against Women and Children (cyberstalking, POCSO and S.67B), and Procedural Aspects (electronic evidence and Section 65B/63 BSA certificates).

Practice Questions

Recall

  1. List the acts covered by Section 43 of the IT Act and state its remedy. Answer guidance: Unauthorised access, downloading/copying data, introducing viruses/contaminants, causing damage, disruption, denial of access, tampering, charging services to another's account, destroying/diminishing value of information, stealing source code — remedy is compensation through the Adjudicating Officer (claims up to ₹5 crore).

  2. Which sections of the IT Act deal with identity theft, cheating by personation, voyeurism, and cyber terrorism? Answer guidance: 66C, 66D, 66E, 66F respectively — note punishments: 3 years each for 66C-66E; up to life for 66F.

Understanding

  1. Why did the Supreme Court strike down Section 66A but uphold Section 69A in the same judgment? Answer guidance: 66A was vague and overbroad ("offensive", "annoyance"), covering speech far beyond Article 19(2) grounds and chilling expression; 69A is narrowly tied to 19(2) grounds, requires recorded reasons, and has procedural safeguards under the Blocking Rules, 2009.

  2. Explain the "act plus mens rea" architecture linking Sections 43 and 66. Answer guidance: Same physical acts; S.43 imposes strict civil liability, S.66 adds "dishonestly or fraudulently" (IPC/BNS meanings) to trigger criminality — illustrating proportionality between culpability and consequence.

Application

  1. R creates a fake matrimonial profile using another woman's photographs, chats with victims, and collects "travel money" from three of them. Identify the offences. Answer guidance: S.66D (cheating by personation via computer resource), S.66C (using another's identifying features/photographs as identity), S.318 BNS (cheating), possibly S.336 BNS (forgery of electronic record) and S.67 if content is obscene. Explain why both special and general law apply.

  2. A disgruntled ex-employee logs into his former employer's cloud dashboard using credentials that were never deactivated and deletes client files. He says "the password still worked, so access was authorised". Advise the company. Answer guidance: Authorisation ended with employment; access was "without permission of the owner" — S.43 acts (access, deletion, diminishing value) done dishonestly → S.66 offence; company may also claim compensation under S.43 and pursue S.72 breach-of-confidentiality angles if applicable.

Analysis

  1. "Indian cybercrime law punishes intent, not technology." Evaluate with reference to Sections 43, 66, and 66F. Answer guidance: Show the escalation ladder: identical technical conduct → civil liability (no intent), 3 years (dishonest intent), life imprisonment (terrorist intent against critical infrastructure). Discuss whether consequence-based grading (harm caused) should supplement intent-based grading.

  2. Compare intermediary liability before and after Shreya Singhal and the 2021 Rules. Has the balance shifted back toward platform responsibility? Answer guidance: Pre-2008: exposure (Bazee.com); 2008 S.79: conditional immunity; 2015: "actual knowledge" narrowed to court/government orders; 2021 Rules: proactive duties, grievance redressal, traceability for significant intermediaries — argue whether these dilute the Shreya Singhal protection and raise fresh Article 19/21 questions.

FAQ

Q1. Are cyber crimes bailable in India? It varies by section. Offences punishable up to 3 years under the IT Act (Sections 66, 66C, 66D, 66E) are cognizable and bailable per Section 77B; graver offences like Section 66F (cyber terrorism) and repeat convictions under 67A/67B are non-bailable. Always check the punishment and Section 77B.

Q2. Where do I report a cybercrime? On the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline (especially for financial fraud — early reporting enables freezing of fraudulent transactions), or at any police station/cyber cell. Jurisdiction is flexible because Section 1(2) read with Section 75 gives the IT Act extra-territorial reach where the computer resource is in India.

Q3. Can a WhatsApp message or screenshot be used as evidence? Yes, as electronic records — but secondary electronic evidence needs a certificate under Section 65B(4) Evidence Act (now Section 63 of the Bharatiya Sakshya Adhiniyam, 2023), as mandated in Anvar P.V. v. P.K. Basheer (2014) and clarified in Arjun Panditrao Khotkar (2020).

Q4. Is Section 66A still applied even though it was struck down? It should not be. Because FIRs continued to cite the dead provision, the Supreme Court in the PUCL proceedings (2022) directed states to withdraw all pending Section 66A prosecutions and instructed police not to register cases under it.

Q5. How does the BNS, 2023 interact with the IT Act for cyber offences? The BNS carries general offences that often apply online — cheating (S.318), defamation (S.356), stalking including cyberstalking (S.78), voyeurism (S.77), organised crime including cyber-crimes as part of organised syndicates (S.111). The IT Act remains the special law for computer-specific offences; on direct overlap (e.g., electronic obscenity) the special law prevails.

Quick Revision

  • IT Act 2000, overhauled by the 2008 Amendment (post-26/11); applies extra-territorially (Secs 1(2), 75).
  • S.43 = civil (unauthorised access, viruses, damage — compensation); S.66 = criminal (same acts + dishonest/fraudulent intent, ≤3 yrs).
  • S.43A: body corporate negligence over sensitive personal data → compensation.
  • S.66C identity theft; S.66D cheating by personation online — the phishing/OTP-fraud duo (≤3 yrs each).
  • S.66E private-area images without consent; S.67 obscene, S.67A sexually explicit, S.67B child sexual abuse material (strictest — even browsing).
  • S.66F cyber terrorism — intent against sovereignty/terror + attack on computer resources → up to life.
  • S.66A struck down in Shreya Singhal (2015) — vague, overbroad, chilling effect; S.69A blocking upheld; S.79 safe harbour read down to require court/government notice.
  • Intermediary duties now detailed in the IT Rules, 2021.
  • Electronic evidence needs a S.65B/S.63 BSA certificate (Anvar, Arjun Panditrao).
  • Special law prevails over general law for electronic content (Sharat Babu Digumarti, 2017).
  • Report financial cyber fraud fast: cybercrime.gov.in / helpline 1930.

Prerequisites

Next Topics