India’s growing dependence on digital technology has created new opportunities for cybercriminals, ranging from identity theft and online impersonation to unauthorised access, privacy violations and the circulation of unlawful content. The Information Technology Act, 2000 (IT Act) remains one of India’s principal laws dealing specifically with offences involving computer resources and electronic communication.
The Act provides a legal framework for recognising electronic transactions while also establishing offences, penalties, investigative powers and mechanisms for addressing misuse of digital technologies.
Key Cyber Offences Under the IT Act
Several provisions of the IT Act directly address common forms of cybercrime.
Section 66 deals with computer-related offences involving dishonest or fraudulent acts covered by Section 43. Depending on the circumstances, unauthorised access, downloading or extraction of data, introduction of malicious code and damage to computer systems may attract criminal liability.
Section 66C addresses identity theft, including fraudulent or dishonest use of another person’s electronic signature, password or other unique identification feature. Section 66D covers cheating by personation using a computer resource, making it particularly relevant to online impersonation and digital fraud.
Section 66E addresses violations of privacy involving the capture, publication or transmission of images of a person’s private areas without consent in circumstances violating privacy. The Act also contains provisions concerning cyber terrorism, obscene or sexually explicit electronic material and material depicting children in sexually explicit acts.
It is important to note that Section 66A is no longer an enforceable offence. The Supreme Court struck it down in Shreya Singhal v. Union of India in 2015, and the provision is listed as omitted in the current statutory framework.
Enforcement and Investigation
Cybercrime enforcement in India involves both central institutions and State and Union Territory law-enforcement agencies. While the Central Government provides coordination, infrastructure and capacity-building support, police and public order remain State subjects, and State/UT law-enforcement agencies are primarily responsible for prevention, investigation and prosecution of cybercrime.
The Indian Cybercrime Coordination Centre (I4C), functioning under the Ministry of Home Affairs, serves as a national coordination mechanism for tackling cybercrime. Its initiatives include cybercrime reporting systems, financial-fraud response mechanisms, data analytics and coordination between law-enforcement agencies and financial institutions.
Reporting Cybercrime
Victims can report cyber offences through the National Cybercrime Reporting Portal (NCRP). For financial cyber fraud, the national helpline 1930 provides an additional channel for immediate reporting.
The importance of prompt reporting has increased with the development of mechanisms such as the Cyber Fraud Mitigation Centre (CFMC), which brings together banks, financial intermediaries, payment aggregators, telecom service providers and law-enforcement representatives to facilitate rapid action against financial fraud.
Beyond the IT Act
Cybercrime enforcement cannot be viewed solely through the IT Act. Depending on the conduct involved, offences may also attract provisions of India’s general criminal law and other sector-specific legislation.
For example, an online financial scam may involve both provisions dealing with computer resources and offences relating to cheating or criminal conspiracy. Similarly, cyber harassment, stalking, threats or circulation of unlawful content may require consideration of multiple applicable laws.
Conclusion
The IT Act continues to provide an important statutory foundation for addressing cyber offences in India. Its provisions cover a broad range of conduct, including computer-related offences, identity theft, online impersonation, privacy violations, cyber terrorism and unlawful electronic content.
At the same time, effective enforcement depends on coordination between victims, police authorities, I4C, financial institutions, technology platforms and other stakeholders.
As cybercrime continues to evolve, awareness of the applicable offences and prompt reporting remain critical. For individuals and businesses, understanding the IT Act is therefore not merely a matter of legal compliance—it is an important part of protecting digital assets, personal information and online identity.
