India has over 900 million internet users, and with that scale comes an equally vast landscape of digital threats. From a student’s social media account being hacked to large-scale financial fraud targeting banks, cyber crimes are no longer rare events – they are daily realities. The Information Technology Act, 2000 (IT Act) is India’s primary legal framework to tackle these threats. It defines what constitutes a cyber crime, who is liable, and what penalties follow. Understanding these provisions is essential for any law student – and increasingly, for anyone operating in the digital economy.
Table of Contents
- What counts as a cyber crime under Indian law?
- Key offences under the IT Act, 2000
- Section 43 – Unauthorised access and damage to computer systems
- Section 65 – Tampering with computer source documents
- Section 66 – Computer-related offences (hacking)
- Section 66B to 66F – The 2008 additions
- Offences related to online content
- Section 67 – Publishing obscene material electronically
- Sections 67A and 67B – Sexually explicit and child abuse material
- Protection of critical infrastructure – Section 70
- Breach of confidentiality and misrepresentation
- Section 71 – Misrepresentation to certifying authorities
- Section 72 – Breach of confidentiality
- Extra-territorial reach of the Act
- Enforcement and investigation machinery
- Limitations of the Act and evolving cyber law landscape
What counts as a cyber crime under Indian law?
Interestingly, the IT Act never actually defines “cyber crime” as a term. The Indian law gives no fixed definition to the term ‘cybercrime’, and even the Indian Penal Code (IPC) avoids the phrase. Instead, the Act lists specific acts, declares them offences, and prescribes punishments. In a broad sense, any illegal act committed using a computer, network, or digital device – whether targeting data, systems, or individuals – falls within the ambit of cyber crime. The IT Act’s Chapter XI (Sections 65 to 74) contains the core criminal provisions, and the 2008 Amendment significantly expanded this list to address emerging threats.
Key offences under the IT Act, 2000
Section 43 – Unauthorised access and damage to computer systems
This is the foundational civil provision that forms the basis for many criminal charges. Under Section 43, whoever, without permission of the person in charge of a computer system, accesses it, downloads data, introduces a virus, or causes denial of access is liable to pay compensation up to ₹1 crore. While Section 43 deals with civil liability (compensation), it feeds directly into Section 66, which criminalises the same acts when done dishonestly or fraudulently.
Section 65 – Tampering with computer source documents
Any person who intentionally tampers with, conceals, destroys, or alters any computer source document is liable to imprisonment up to three years, or a fine up to ₹2 lakh, or both. This section goes beyond copyright protection – it directly safeguards the integrity of software code. A well-known case illustrating this is Syed Asifuddin v. State of Andhra Pradesh, where Tata Indicom employees were arrested for manipulating electronic serial numbers of mobile handsets. The court confirmed that tampering with source code invokes Section 65 of the Information Technology Act.
Section 66 – Computer-related offences (hacking)
Section 66 is among the most frequently invoked provisions. If an individual engages in any action outlined in Section 43 with dishonest or fraudulent intent, the punishment may include imprisonment for up to three years, a fine of up to ₹5 lakh, or both. In practical terms, this is how hacking is prosecuted in India. In the case of Kumar v. Whiteley, the accused gained unauthorised access to the Joint Academic Network (JANET), deleted and added files, and changed passwords to lock out legitimate users – a textbook hacking case prosecuted under this section.
Section 66B to 66F – The 2008 additions
The 2008 Amendment Act dramatically expanded the offences covered under Section 66 by introducing Sections 66B through 66F. These address a range of crimes that had no explicit legal cover before:
Section 66B – Receiving stolen computer resources: Dishonestly receiving or retaining a stolen computer resource or communication device attracts imprisonment up to three years or a fine up to ₹1 lakh.
Section 66C – Identity theft: Misusing someone else’s electronic signature, password, or any unique identification feature carries up to three years imprisonment and a fine up to ₹1 lakh. This directly addresses the growing problem of credential theft, SIM-swapping, and account takeovers.
Section 66D – Cheating by personation: This covers online impersonation used to cheat – a provision directly applicable to phishing scams. When a fraudster creates a fake banking website or impersonates a government official online to extract money, Section 66D applies alongside IPC provisions for cheating.
Section 66E – Violation of privacy: Capturing, publishing, or transmitting images of a person’s private parts without consent is an offence punishable with imprisonment up to three years or a fine up to ₹2 lakh. This was a significant acknowledgement of digital voyeurism as a criminal act.
Section 66F – Cyber terrorism: This is the most severe provision in the Act. Any person who uses cyber means to threaten the unity, integrity, security, or sovereignty of India can be punished with life imprisonment. This includes acts like attacking critical infrastructure systems – power grids, banking networks, or defence databases – through electronic means.
Offences related to online content
Section 67 – Publishing obscene material electronically
Publishing or transmitting lascivious material in electronic form is punishable on first conviction with up to three years imprisonment and a fine up to ₹5 lakh, and on subsequent conviction with up to five years and a fine up to ₹10 lakh. India’s first conviction under this section came in a case from Tamil Nadu where the accused was found guilty of harassing a woman by sending obscene emails – he was sentenced to two years of rigorous imprisonment.
Sections 67A and 67B – Sexually explicit and child abuse material
Section 67A covers publishing sexually explicit material in electronic form, with imprisonment up to five years and a fine up to ₹10 lakh for the first offence. Section 67B addresses child sexual abuse material (CSAM) online, with punishment of up to seven years imprisonment and a fine up to ₹10 lakh. These provisions reflect the Act’s recognition that digital platforms can be weaponised for exploitation, and the law treats such offences with particular severity.
Protection of critical infrastructure – Section 70
Under Section 70, the government may declare any computer resource that affects Critical Information Infrastructure as a “protected system.” Any person who secures unauthorised access to such a system faces imprisonment of up to ten years along with a fine. This section covers systems like nuclear facilities, power grids, financial infrastructure, and telecommunications networks. It signals that an attack on these systems is not just a computer offence – it is treated almost at par with threats to national security.
Breach of confidentiality and misrepresentation
Section 71 – Misrepresentation to certifying authorities
Whoever makes misrepresentation or suppresses material facts to obtain a digital signature certificate or licence faces imprisonment up to two years or a fine up to ₹1 lakh. This targets fraud in the digital credentialing system itself.
Section 72 – Breach of confidentiality
Any person who, having gained access to electronic records, information, or documents under the powers of the Act, discloses such information without consent is liable to imprisonment up to two years or a fine up to ₹1 lakh. This is particularly significant for government officials, adjudicating officers, and intermediaries who handle personal data in the course of their duties.
Extra-territorial reach of the Act
Section 75 gives the IT Act an extra-territorial dimension – it applies to offences committed outside India by any person, irrespective of nationality, if the act involves a computer, computer system, or network located in India. This is critical in the digital world where criminals often operate from foreign jurisdictions to target Indian systems. A 2022 Delhi cyber crime case illustrated this when a gang running phishing scams was charged under Section 66D along with multiple IPC provisions for fraudulently obtaining banking credentials.
Enforcement and investigation machinery
The Act does not just define offences – it also sets up the machinery for enforcement. Investigations into IT Act offences must be conducted by a police officer of at least the rank of Deputy Superintendent of Police (Section 78). The government also established CERT-In (Indian Computer Emergency Response Team) as a nodal agency for cybersecurity incident response. Additionally, an Adjudicating Officer can hear civil claims (up to ₹5 crore in damages), while criminal matters go to regular courts. The Cyber Appellate Tribunal was set up to handle appeals from adjudicating officers’ orders, though it has since been merged with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Limitations of the Act and evolving cyber law landscape
Despite its wide reach, the IT Act has significant gaps. The Act does not provide any remedy for breach and leak of personal data, nor does it specify accountability if a government organisation causes a data breach. Critics have also pointed out that penalties for many offences are relatively light given the scale of harm a cyber attack can cause. The landmark Shreya Singhal v. Union of India (2015) judgment struck down Section 66A – which penalised “offensive online messages” – as unconstitutional for violating the right to free speech under Article 19. This showed that cyber law must balance security interests with civil liberties. India has since enacted the Digital Personal Data Protection Act, 2022 to address data privacy gaps, marking an evolution of the legal framework beyond the IT Act’s original scope.
What do you think? As digital transactions and online services become central to daily life in India, do you think the penalties prescribed under the IT Act are proportionate to the actual harm caused by offences like identity theft or data breaches? And given that Section 66A was struck down for threatening free speech, where should the law draw the line between regulating harmful online content and protecting citizens’ fundamental rights?
References
- https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
- https://www.lawctopus.com/academike/offences-act-2000/
- https://archive.pib.gov.in/release02/lyr2002/rfeb2002/01022002/r010220022.html
- https://taxguru.in/corporate-law/offences-penalties-information-technology-act-2000.html
- https://www.networkintelligence.ai/blogs/it-act-2000-penalties-offences-with-case-studies/
- https://cleartax.in/s/it-act-2000
- https://testbook.com/ugc-net-commerce/cyber-crimes-penalties
- https://csic.org.in/cyber-crime-act/
- https://www.legalservicesindia.com/article/439/Offences-&-Penalties-under-the-IT-Act,-2000.html
- https://iclg.com/practice-areas/cybersecurity-laws-and-regulations/india
- https://blog.ipleaders.in/information-technology-act-2000/
- https://en.wikipedia.org/wiki/Information_Technology_Act,_2000
Leave a Reply