Quick Answer: Cyber crime in India is primarily governed by the Information Technology Act 2000, supplemented by cyber-related provisions in the Bharatiya Nyaya Sanhita (BNS) and the evidentiary rules of the Bharatiya Sakshya Adhiniyam (BSA). Complaints can be filed online through the National Cyber Crime Reporting Portal, and financial fraud victims should immediately call the 1930 helpline.
What are Cyber Crimes Under Indian Law?
Cyber crime refers to any illegal activity carried out using a computer, mobile device, or network as either the target or the tool of the offence. This includes activities ranging from hacking into a bank's server to sending a single fraudulent message that tricks someone into sharing their OTP. Axepron Legal's Legal Practice page gives a broader overview of this area of law.
Definition and Overview
Indian law does not define "cyber crime" as a single standalone offence in one section. Instead, it is a broad umbrella term covering a wide range of activities defined across the Information Technology Act 2000, the Bharatiya Nyaya Sanhita (BNS) 2023, and, where financial instruments are involved, banking and payment regulations issued by the Reserve Bank of India. What unites these offences is that a computer, computer network, or communication device is either the object of the crime or the medium through which it is committed.
Categories of Cyber Crime
Cyber offences in India are generally grouped into three broad categories. The first is crimes against individuals, such as identity theft, cyberstalking, online defamation, and the circulation of intimate images without consent. The second is crimes against property, which includes hacking, ransomware attacks, theft of trade secrets, and unauthorized access to computer systems for financial gain. The third is crimes against the state or society at large, covering cyberterrorism, large-scale data breaches affecting critical infrastructure, and the spread of content that threatens public order. Each category is investigated differently and often falls under the jurisdiction of specialized cyber cells rather than regular police stations.
Governing Law / Legal Framework
The Information Technology Act 2000 remains the primary legislation for cyber offences such as hacking, data theft, and identity fraud. It was amended in 2008 to widen its scope after high-profile data breach and cyberterrorism cases exposed gaps in the original law. Since 2023, the Bharatiya Nyaya Sanhita has also stepped in to cover cyber-enabled crimes like online cheating, fraud, and harassment, working alongside the IT Act's technology-specific provisions rather than replacing them.
Key Sections of the IT Act
Section 43 deals with civil liability for unauthorized access, damage, or data theft from a computer system, allowing the victim to claim compensation. Section 66 makes such acts a criminal offence when done dishonestly or fraudulently. Section 66C specifically punishes identity theft, including the fraudulent use of another person's password, digital signature, or unique identification feature. Section 66D covers cheating by impersonation using a computer resource, which is the section most commonly invoked in online scam cases. Section 66E addresses violation of privacy through capturing or publishing images of a person's private area without consent, and Section 67 penalizes the publishing or transmitting of obscene material in electronic form.
Role of the Bharatiya Sakshya Adhiniyam
Electronic evidence such as emails, chat logs, call data records, and screenshots is admissible in court under the Bharatiya Sakshya Adhiniyam, provided it is certified in the prescribed manner, typically through a certificate under the section governing electronic records. This makes proper preservation and certification of digital evidence central to the success of most cyber crime prosecutions, and investigators are trained to follow a chain-of-custody process to ensure such evidence is not challenged later on grounds of tampering.
Jurisdiction and Cross-Border Issues
Cyber crimes rarely respect state or national borders, which creates practical challenges for investigation and prosecution. Section 75 of the IT Act gives it extra-territorial application, allowing Indian authorities to act against offences committed outside India if they involve a computer resource located within the country. In practice, however, cooperation with foreign service providers and law enforcement agencies can slow down investigations considerably, especially where servers are hosted abroad.
| Offence | Governing Law | Nature |
| Hacking / Unauthorized Access | IT Act, Section 43 & 66 | Cognizable |
| Online Financial Fraud | IT Act Section 66D + BNS cheating provisions | Cognizable |
| Cyberstalking / Online Harassment | BNS provisions | Cognizable |
| Identity Theft | IT Act, Section 66C | Cognizable |
| Publishing Obscene Material | IT Act, Section 67 / 67A | Cognizable |
Common Offences and How to Report Them
The most frequently reported cyber crimes in India include UPI and net banking fraud, social media account takeover and impersonation, sextortion scams, phishing emails and messages that mimic banks or government departments, fake job or investment offers, and OTP-based frauds where a caller poses as a bank official.
Financial Fraud Cases
In cases involving UPI apps, net banking, or credit and debit cards, time is critical. Banks and payment apps can often reverse or block a transaction if it is reported within a short window, which is why the 1930 helpline exists as a fast-track mechanism separate from the general online complaint portal. Delayed reporting significantly reduces the chances of recovering lost funds.
Harassment, Stalking, and Obscene Content
Cases involving harassment of women and children, morphed images, or non-consensual sharing of intimate content can be reported anonymously through a dedicated category on the cybercrime.gov.in portal, and such complaints are typically escalated with priority given the sensitivity involved.
Step-by-Step Reporting Process
First, preserve all evidence immediately, including screenshots, transaction IDs, phone numbers, and email headers, before anything can be deleted or altered by the fraudster. Second, call the 1930 helpline right away if the matter involves financial loss, since the operator can initiate an immediate hold request with the bank or payment gateway. Third, register a detailed complaint on the National Cyber Crime Reporting Portal, selecting the correct category so it is routed to the right cyber cell. Fourth, if required, visit the nearest police station or cyber cell in person to file a formal First Information Report, particularly for cases involving significant financial loss or repeated harassment. Finally, retain the complaint acknowledgment number, as it is needed to track the status of the investigation and for any follow-up correspondence with your bank.
Interplay with the Digital Personal Data Protection Act
Beyond the IT Act, the Digital Personal Data Protection Act 2023 adds another layer of accountability by requiring organizations that collect personal data to implement reasonable security safeguards and report data breaches to the Data Protection Board. A company that suffers a data breach due to negligence can now face financial penalties under this Act in addition to any criminal liability its employees or the attackers may face under the IT Act, making corporate cyber security compliance more important than ever.
Penalties and Punishments
Punishments under cyber crime law vary significantly depending on the offence and its severity. Unauthorized access or hacking under Section 66 of the IT Act can attract imprisonment of up to three years, a fine of up to five lakh rupees, or both. Identity theft under Section 66C carries a similar term of imprisonment along with a fine. Cheating by impersonation under Section 66D, the provision most often used in online scam prosecutions, can lead to imprisonment of up to three years and a fine of up to one lakh rupees. Offences involving publication of obscene material carry higher penalties, especially on repeat conviction, and cases involving children attract significantly more stringent punishment under both the IT Act and dedicated child protection legislation. Courts also have the power to order compensation to victims separately from any criminal penalty imposed on the accused.
Preventive Measures and Cyber Hygiene
Prevention remains far more effective than post-incident recovery, especially in financial fraud cases where recovering lost money can be difficult once it has moved through multiple accounts. Basic precautions include never sharing OTPs, PINs, or passwords with anyone claiming to be from a bank or government department, since legitimate institutions never ask for these details over a call or message. Enabling two-factor authentication on email, banking, and social media accounts adds a critical extra layer of protection even if a password is compromised.
Practical Safety Habits
Avoid clicking on links in unsolicited messages, verify unfamiliar payment requests directly through official apps rather than the link provided, keep software and antivirus tools updated, and regularly review bank and card statements for unfamiliar transactions. Businesses in particular should train employees to recognize phishing attempts, since a significant share of corporate data breaches begin with a single employee clicking a malicious link.
Indian courts and cyber cells have increasingly dealt with cases involving deepfake technology, fraudulent investment schemes advertised through social media influencers, and organized scam call centers operating across state lines. These trends have pushed law enforcement to set up dedicated cyber forensic labs in most states, and several High Courts have issued directions requiring social media platforms to take down non-consensual intimate content within strict timelines once notified, reflecting a broader shift toward faster victim-centric remedies alongside criminal prosecution.