India has over 900 million internet users, and that number grows every year. But with greater digital access comes greater digital risk. Cybercrime – crime committed using computers or networks – is rising sharply across the country. What makes India’s situation particularly complex is that there is no single, dedicated cybercrime legislation that covers the full spectrum of digital offenses. Instead, prosecutors must stitch together provisions from two key legal frameworks: the Information Technology Act, 2000 (IT Act) and the Indian Penal Code, 1860 (IPC), now partly updated by the Bharatiya Nyaya Sanhita, 2023 (BNS). Understanding how these laws classify and punish cybercrimes is essential for anyone navigating India’s digital landscape.
Table of Contents
- What is cybercrime?
- Conventional crimes committed through computers
- Cyber defamation
- Cyber fraud
- Digital forgery and cyberstalking
- Cyber pornography
- Network and email-based crimes
- Hacking and unauthorized access
- Email spamming and email spoofing
- Data alteration and destruction crimes
- Computer vandalism and virus transmission
- Data diddling and salami attacks
- Phishing
- Violation of intellectual property rights
- Software piracy
- Cybersquatting
- Landmark cybercrime cases in India
- SMC Pneumatics (India) Pvt. Ltd. vs. Jogesh Kwatra (2001)
- State of Tamil Nadu vs. Suhas Katti (2004)
- NASSCOM vs. Ajay Sood & Others (2005)
- The legal framework: IT Act and IPC working together
What is cybercrime?
The term “cybercrime” is not defined under any statute in India. In its broadest sense, it refers to any activity done with criminal intent in cyberspace – where a computer can be both the tool used to commit the crime and the target of it. Cybercrimes can range from traditional offenses like fraud and defamation that have shifted online, to entirely new categories of crime that did not exist before the internet era. They are generally grouped into four major types.
Conventional crimes committed through computers
These are traditional crimes that have simply migrated to digital platforms. The computer is the instrument; the crime itself is familiar.
Cyber defamation
When someone publishes false, damaging statements about another person using email, websites, or social media, it constitutes cyber defamation. Section 499 of the IPC governs defamation broadly, and it applies equally to digital publications. The IT Act additionally holds intermediaries – social media platforms, for instance – accountable if they fail to remove defamatory content after being formally notified.
Cyber fraud
Cyber fraud involves deceiving someone online for financial gain – fake lottery emails, fraudulent investment schemes, phishing pages that mimic legitimate banks. Section 420 of the IPC (now Section 318 of the BNS) deals with cheating and dishonestly inducing delivery of property, and carries up to seven years imprisonment. It applies directly to criminals who create fake websites or run digital scams.
Digital forgery and cyberstalking
Creating or using fraudulent electronic documents – like a forged digital ID or a fake email address – falls under Section 336 of the BNS (previously Section 463 of the IPC), which addresses forgery of documents and digital records. Cyberstalking – monitoring or repeatedly contacting someone through digital means against their will – is covered under Section 354D of the IPC, which was inserted by the Criminal Law (Amendment) Act, 2013. It carries up to three years imprisonment for a first offense, and five years for repeat offenders.
Cyber pornography
Publishing or transmitting obscene material electronically is a criminal offense under Section 67 of the IT Act, with up to three years imprisonment and a โน5 lakh fine for first-time offenders. Child pornography specifically invites even steeper penalties – up to five years imprisonment for a first conviction under Section 67B.
Network and email-based crimes
This category targets the technology itself – the networks, servers, and communication systems that form the backbone of the internet.
Hacking and unauthorized access
Hacking means gaining entry to a computer system or network without permission. It is directly addressed under Sections 43 and 66 of the IT Act, which punish unauthorized access, data theft, destruction of data, and denial of access to legitimate users – with penalties of up to three years imprisonment or a โน5 lakh fine or both. In one illustrative case, a person named N.G. Arun Kumar gained unauthorized access to a BSNL broadband connection, modifying user account databases. He was ultimately sentenced to one year of rigorous imprisonment under Section 420 IPC and Section 66 of the IT Act.
Email spamming and email spoofing
Email spamming involves flooding inboxes with unsolicited bulk mail – at scale, this can overwhelm and crash email servers. Email spoofing is the act of forging the sender’s address so that an email appears to originate from a trusted or legitimate source. Both offenses can be prosecuted under the IT Act, particularly under sections that address unauthorized use of computer resources and fraudulent impersonation. Spoofing, when used to deceive recipients into disclosing information, can also attract charges under IPC sections on cheating and identity fraud.
Data alteration and destruction crimes
These crimes go a step further – rather than just accessing a system, the perpetrator damages, alters, or corrupts data or the system itself.
Computer vandalism and virus transmission
Deliberately damaging a computer system – whether by physically interfering with it or by introducing malicious code – is a punishable offense. Section 43(a) of the IT Act penalises any person who, without the owner’s permission, accesses or secures access to a computer system or network. Transmitting a virus, worm, or any other malware is specifically covered under Section 43 and Section 66 of the IT Act. In 2022, the Delhi Cyber Crime Cell arrested a gang charged under Section 66D of the IT Act and Sections 419, 420, and 468 of the IPC for deploying phishing tools to steal banking credentials.
Data diddling and salami attacks
Data diddling refers to the unauthorized alteration of data before or during input into a computer system – for example, changing figures in a financial database just before they are processed. Salami attacks involve making tiny, almost undetectable changes across multiple transactions – shaving fractions of a rupee from thousands of accounts so that the total theft is substantial but each individual deduction goes unnoticed. Both fall under Section 65 of the IT Act, which addresses the tampering with computer source documents, as well as relevant IPC provisions on mischief and fraud.
Phishing
Phishing is one of the most common cybercrimes today. It involves impersonating a trusted entity – a bank, a government agency, or a company – to trick users into revealing sensitive information like passwords or banking details. Under Section 66D of the IT Act, phishing is treated as cheating by personation using a computer resource, and carries imprisonment of up to three years or a fine of up to โน1 lakh or both. India has also been reported to be among the top three countries globally for phishing attacks, making this one of the most pressing areas of cyber law enforcement.
Violation of intellectual property rights
The internet has made copying and distributing content effortless – and that has made IP theft a massive problem.
Software piracy
Distributing pirated software – cracked programs, unlicensed copies sold online – is a violation of copyright law. While the IT Act does not have a standalone provision for software piracy, the Copyright Act, 1957 applies fully in the digital domain. Distributing pirated software without authorization can result in civil and criminal penalties under that Act.
Cybersquatting
Cybersquatting is the practice of registering a domain name that incorporates someone else’s trademark or brand name – with the intent to sell it back at a profit or redirect traffic away from the legitimate owner. For example, registering “relianceindustries.net” when you have no connection to Reliance Industries is cybersquatting. While India does not have a standalone anti-cybersquatting law, traditional intellectual property laws – including the Trade Marks Act, 1999 – apply. Courts have used the doctrine of “passing off” to grant relief in such cases.
Landmark cybercrime cases in India
Laws matter, but so does their application. India’s courts have heard several pivotal cyber cases that established how the IT Act and IPC work together in practice.
SMC Pneumatics (India) Pvt. Ltd. vs. Jogesh Kwatra (2001)
This was India’s first case of cyber defamation. Jogesh Kwatra, an employee of SMC Pneumatics, began sending defamatory, vulgar, and abusive emails about the company and its Managing Director to subsidiaries worldwide. The plaintiff filed for a permanent injunction. The Delhi High Court granted an ex-parte injunction restraining the defendant from sending derogatory emails – and further barred him from publishing any defamatory content about the plaintiffs, whether in the physical world or in cyberspace. The case was historic because it was the first time an Indian court assumed jurisdiction over a matter of cyber defamation.
State of Tamil Nadu vs. Suhas Katti (2004)
This is the first case in India where a conviction was handed down for posting obscene messages on the internet under Section 67 of the IT Act, 2000. The accused, Suhas Katti, posted obscene and defamatory messages about a divorced woman in a Yahoo message group, misrepresenting her as soliciting sex. He was arrested in Mumbai shortly after the FIR was filed in February 2004 and convicted within seven months – a remarkably swift outcome that demonstrated the efficiency of the Chennai Cyber Crime Cell. He was sentenced to rigorous imprisonment for two years and fined โน4,000 under Section 67 of the IT Act, with additional sentences running concurrently under Sections 469 and 509 of the IPC. The case also validated the use of electronic evidence under Section 65B of the Indian Evidence Act for the first time in a trial court.
NASSCOM vs. Ajay Sood & Others (2005)
This case brought the concept of phishing formally into Indian law. The defendants ran a placement agency and, in order to collect personal data for recruitment purposes, sent emails to third parties masquerading as NASSCOM – India’s premier software industry body. In a landmark judgment delivered in March 2005, the Delhi High Court declared phishing on the internet to be an illegal act, entailing an injunction and recovery of damages. Since there was no specific legislation penalizing phishing at the time, the court defined it under Indian law as a misrepresentation in the course of trade that causes confusion about the origin of an email – and treated it as an act of passing off and tarnishment of the plaintiff’s image. The Delhi High Court’s definition of phishing and its categorization as a fraudulent act served as an important precedent in the domain of internet fraud. The court also ordered that the hard disks seized from the defendants’ premises be handed over to the plaintiff as evidence of the fraudulent emails sent.
The legal framework: IT Act and IPC working together
India’s approach to cybercrime is built on a dual-framework model. Section 81 of the IT Act states that its provisions shall have effect notwithstanding anything inconsistent contained in any other law – meaning the IT Act takes precedence as a special law. However, where the IT Act does not cover a specific offense, IPC and BNS provisions fill the gap. This overlap means a single cybercrime can lead to simultaneous charges under multiple sections of both laws. The replacement of the IPC by the Bharatiya Nyaya Sanhita in July 2024 has updated the numbering of many sections but has not fundamentally altered how cyber offenses are prosecuted. Experts continue to call for a dedicated, comprehensive digital law – and the government’s proposed Digital India Act is intended to eventually replace the IT Act with legislation better suited to today’s threat landscape.
What do you think? As India’s cyber laws were largely written in 2000 and amended only in 2008, do they genuinely reflect the sophistication of modern cybercrimes like deepfakes or AI-assisted fraud? And with crimes like cybersquatting still lacking dedicated legislation, is the dual IT Act-IPC framework enough to deliver justice to victims?
References
- https://law.asia/india-cybersecurity-legislation-reform/
- https://probono-india.in/blog-detail.php?id=218
- https://blog.ipleaders.in/cyber-crime-laws-in-india/
- https://www.lexology.com/library/detail.aspx?g=d599eba2-e69a-4121-95b4-ff84e49730c6
- https://iclg.com/practice-areas/cybersecurity-laws-and-regulations/india
- https://www.prashantmali.com/content/cyber-law-cases
- https://en.wikipedia.org/wiki/Suhas_Katti_v._Tamil_Nadu
- https://lawbhoomi.com/state-of-tamil-nadu-vs-suhas-katti/
- https://indiankanoon.org/doc/1804384/
- https://lawfullegal.in/nasscom-vs-ajay-sood-ors-delhi-hc-2005-case-analysis/
- https://www.mondaq.com/india/it-and-internet/891738/cyber-crimes-under-the-ipc-and-it-act—an-uneasy-co-existence
Leave a Reply