Introduction
Your bank account, your photos, your identity, your reputation β almost everything that matters now lives partly online, and that is exactly where a new class of criminals operates. Phishing links, UPI scams, identity theft, deepfakes, "digital arrest" frauds, and online harassment are no longer rare; India loses tens of thousands of crores to cyber fraud every year. The law has been catching up fast. Knowing which laws protect you, what counts as a cyber crime, and how to report one is now basic digital self-defence.
What You'll Learn
This blog explains India's cyber-crime legal framework β the Information Technology Act, the new Bharatiya Nyaya Sanhita that replaced the IPC in 2024, and the data-protection regime β the main offences and their punishments, how to report a cyber crime, the landmark judgments, and the mistakes that let criminals escape.
What Are Cyber Crimes?
A cyber crime is any unlawful act committed using a computer, network, or digital device β either as the tool (hacking, phishing, online fraud) or the target (data theft, system damage). The term is not defined in a single statute; it is understood as a cluster of offences spread across the IT Act, 2000, the Bharatiya Nyaya Sanhita, 2023, and supporting rules. Cyber crimes range from financial fraud and identity theft to cyberstalking, sextortion, obscene content, and attacks on critical infrastructure.
Why It Matters
Cyber crime is "the crime of the 21st century" β silent, borderless, and scalable. A single fraudster can target thousands of victims across states in minutes. For an ordinary person, the danger is intensely personal: drained bank accounts, a stolen identity used to take loans, intimate images weaponised, or a reputation destroyed by a deepfake. Understanding the law tells you what is illegal, what evidence to preserve, and β crucially β how fast you must act to have any chance of recovery or prosecution.
Key Definitions
- Hacking / unauthorized access: Entering a computer system without permission.
- Phishing: Tricking someone into revealing credentials via fake emails, SMS, or websites.
- Identity theft: Stealing and misusing someone's personal/credential data.
- Cheating by personation: Impersonating another to deceive and defraud (e.g., fake bank-officer calls).
- Deepfake: AI-generated synthetic audio/video impersonating a real person.
- CERT-In: India's Computer Emergency Response Team, the national agency for cyber-incident response.
Relevant Legal Provisions
1. The Information Technology Act, 2000 β the principal cyber law. Key sections: - Section 43 β civil liability (penalty up to βΉ1 crore) for damaging a computer, introducing viruses, or unauthorized access. - Section 66 β hacking and computer-related offences (up to 3 years and/or fine). - Section 66C β identity theft (up to 3 years and βΉ1 lakh fine). - Section 66D β cheating by personation using a computer resource (up to 3 years and βΉ1 lakh fine). - Section 66E β violation of privacy by capturing/publishing private images (up to 3 years and/or βΉ2 lakh fine). - Section 66F β cyber terrorism (up to life imprisonment). - Sections 67, 67A, 67B β publishing/transmitting obscene, sexually explicit, or child sexual abuse material. - Section 70 β offences against protected systems / critical information infrastructure (up to 10 years).
(Note: Section 66A, which criminalised "offensive" online messages, was struck down as unconstitutional in Shreya Singhal v. Union of India, 2015.)
2. The Bharatiya Nyaya Sanhita (BNS), 2023 β replaced the Indian Penal Code with effect from 1 July 2024. It does not address hacking directly but supplies the general crimes that overlay cyber offences: cheating (Section 318, formerly IPC 420), cheating by personation (Section 319, formerly IPC 419), theft (Section 303), extortion (Section 308), criminal intimidation, and defamation (Section 356). In practice, the IT Act and BNS are invoked together.
3. The Digital Personal Data Protection (DPDP) Act, 2023 β governs how organisations must protect personal data; its Rules were notified in November 2025. IT Rules, 2021 (Intermediary Guidelines) require platforms to remove unlawful content and report incidents to CERT-In; in October 2025, these were amended to address deepfakes and synthetically generated information (including labelling requirements).
Step-by-Step Procedure (Reporting a Cyber Crime)
- Act immediately β speed is everything, especially for financial fraud.
- For financial fraud, call the national helpline 1930 (24Γ7) and report on the National Cyber Crime Reporting Portal (cybercrime.gov.in) β ideally within the first hour. This can freeze the fraudster's account before the money moves on.
- Inform your bank to block the card/account and lodge a written dispute.
- Preserve evidence β screenshots, transaction IDs, URLs, email headers, call logs, and any chat with the fraudster. Do not delete anything.
- File the NCRP complaint with full details and save the complaint ID.
- Escalate to an FIR at your local police station or cyber cell if needed (mandatory for larger frauds; see below).
- Track the complaint on the portal and follow up persistently with both police and bank.
Eligibility / Applicability
Anyone β individual or organisation β who is a victim of a cyber offence can report it. Cyber crime has pan-India jurisdiction: under the principle behind Section 154 CrPC/BNSS, a complaint can be registered with any cyber cell regardless of where the crime occurred (a "Zero FIR"). The NCRP allows anonymous reporting specifically for offences against women and children.
Benefits (of the legal framework)
- A single national reporting portal (NCRP) and 24Γ7 helpline (1930).
- Rapid account-freezing through the Citizen Financial Cyber Fraud Reporting and Management System, which links 85+ banks and intermediaries.
- Pan-India jurisdiction β you can report anywhere.
- Strong statutory penalties and the ability to invoke the IT Act and BNS together.
- Special protections for women and children, including anonymous complaints.
Limitations or Exceptions
Enforcement remains the weak link. Cyber criminals exploit cross-border and cross-state jurisdiction, anonymity tools, and the dark web. Recovery is time-sensitive β chances drop sharply after the first 24 hours. Investigations can be slow, digital evidence faces admissibility hurdles, and there is a shortage of trained investigators. The law is also continually playing catch-up with new threats like AI voice-cloning and deepfakes.
Practical Example or Case Study
In Shreya Singhal v. Union of India (2015), the Supreme Court struck down Section 66A of the IT Act for vaguely criminalising online speech β a landmark for digital free expression. On the emerging front, the Delhi High Court in Sadhguru Jagadish Vasudev v. Igor Isakov (2025) granted a sweeping "dynamic+" injunction protecting a person's name, image, and voice from AI-deepfake misuse, ordering rapid takedowns β recognising that static legal tools are inadequate for AI-scale harm. A common real-world scenario is the "digital arrest" scam: fraudsters posing as police or agencies video-call a victim, claim they are under investigation, and extract money through fear. Such conduct attracts cheating by personation (IT Act 66D + BNS 319) and other offences β and the single most important response is to disconnect, verify independently, and call 1930.
Common Mistakes
- Delaying the report β every hour reduces the chance of freezing the money.
- Deleting messages or screenshots that are vital evidence.
- Engaging with the fraudster or paying "to resolve" a fake case.
- Reporting only to the police OR only to the bank β do both.
- Sharing OTP/PIN/CVV under pressure (no genuine official ever asks for these).
- Assuming nothing can be done β even after the window closes, reporting helps and may yield partial recovery.
Frequently Asked Questions
Where do I report a cyber crime? At cybercrime.gov.in or by calling 1930 (for financial fraud), and at your local cyber cell/police station for an FIR.
Was Section 66A really removed? Yes β it was struck down as unconstitutional in 2015. Cases cannot be registered under it.
Can I report from a different city or state? Yes. Cyber crime has pan-India jurisdiction; you can file a Zero FIR anywhere.
Are deepfakes illegal? Misusing someone's likeness can attract IT Act, BNS, and DPDP provisions; the IT Rules were amended in 2025 to specifically address synthetic media.
Conclusion
Cyber crime law in India now rests on three pillars β the IT Act for digital-specific offences, the BNS for the underlying crimes, and the DPDP regime for data protection β backed by a real-time reporting machine in 1930 and the NCRP. But the law can only help those who act fast and preserve evidence. In the digital age, informed vigilance is your first line of defence, and prompt reporting is your best shot at justice and recovery.
Disclaimer
This blog is for general awareness and is not legal advice. Cyber-crime law, IT Rules, and the DPDP regime evolve quickly. If you are a victim, report immediately via 1930/cybercrime.gov.in and consult a cyber-crime lawyer for serious cases. Online fraud and cyber-enabled crime are sensitive issues β if you or someone you know is targeted or distressed, reach out to the official helplines and trusted support.
Related Articles
- Online Fraud Remedies: What to Do When You're Scammed
- Consumer Protection Act, 2019: Your Rights When a Product Lets You Down
- Rights of Women in India: A Practical Legal Guide
- The Right to Information Act, 2005: How Citizens Can Question Power