Cyber Crimes: Offences and Penalties for E-Frauds and illegitimate Digital Arrest

Cyber crimes refer to unlawful acts committed using computers, computer networks, or the internet as either the target or the tool of the offence. In India, such offences are primarily governed by the Information Technology Act, 2000 (amended in 2008), which provides the legal framework for addressing crimes like hacking, data theft, identity theft, cyber terrorism, phishing, and online defamation. Provisions such as Section 43 (penalty for damage to computer systems), Section 66 (computer-related offences), Section 66C (identity theft), and Section 66E (violation of privacy) form the backbone of cyber offence regulation. Globally, frameworks like the Budapest Convention on Cybercrime guide international cooperation. As digital transactions and data dependency grow, cyber law has become critical to protecting individuals, businesses, and national security from evolving technological threats.

Types of Cyber Crimes and E-Frauds:

1. Hacking

Hacking refers to unauthorised access to a computer system, network, server, or electronic device. A hacker may gain access by exploiting security weaknesses, stolen passwords, or other vulnerabilities. The purpose may include stealing information, changing data, disrupting services, or causing financial loss. Hacking can affect individuals, businesses, banks, and government organisations. Under the Information Technology Act, 2000, unauthorised access and damage to computer resources may attract legal consequences, particularly under Sections 43 and 66. Strong passwords, security updates, firewalls, and access controls can help prevent unauthorised access.

2. Phishing

Phishing is a cyber crime in which criminals use fake emails, messages, websites, or links to deceive people into revealing confidential information. The information targeted may include passwords, banking details, card information, or login credentials. Phishing messages often appear to come from legitimate organisations such as banks, government departments, or online services. The stolen information may then be misused for identity theft or financial fraud. Victims should avoid clicking suspicious links and should verify the sender before sharing information. Depending on the circumstances, phishing activities may attract provisions of the Information Technology Act, 2000 and other applicable criminal laws.

3. Identity Theft

Identity theft occurs when a person unlawfully obtains and uses another person’s personal or identification information for an unauthorised purpose. Criminals may misuse names, passwords, digital credentials, bank details, or other information to commit fraud or impersonate the victim. In India, Section 66C of the Information Technology Act, 2000 specifically deals with identity theft involving fraudulent or dishonest use of another person’s electronic signature, password, or other unique identification feature. Identity theft can cause financial loss, reputational damage, and legal complications for victims. Individuals should protect their passwords and avoid sharing confidential information through unverified sources.

4. Cyber Stalking

Cyber stalking involves repeatedly using electronic communication or online platforms to monitor, threaten, harass, or intimidate another person. It may include sending unwanted messages, repeatedly contacting a victim, monitoring online activities, or spreading harmful information. Cyber stalking can cause fear, emotional distress, and damage to privacy. The conduct may attract provisions of the Information Technology Act, 2000, as well as other applicable laws depending on the specific acts committed. Victims should preserve messages, screenshots, account details, and other evidence and report serious cases to the appropriate authorities or cyber crime portal.

5. Cyber Fraud

Cyber fraud refers to fraudulent activities carried out through computers, mobile devices, websites, online banking, or digital communication. Criminals may deceive victims into transferring money, revealing banking credentials, or making unauthorised payments. Common examples include online payment fraud, fake investment schemes, banking fraud, and fraudulent websites. Cyber fraud can result in substantial financial loss. Depending on the nature of the offence, provisions of the Information Technology Act, 2000, the Indian Penal Code or Bharatiya Nyaya Sanhita, 2023, and other applicable laws may apply. Users should verify online transactions and immediately report suspicious financial activity.

6. Cyber Defamation

Cyber defamation occurs when a person publishes or circulates false and defamatory statements about another person through the internet or electronic communication. It may involve social media posts, websites, emails, online videos, or other digital platforms. Such statements may harm the reputation, goodwill, or social standing of the affected person. Cyber defamation may attract provisions relating to defamation under the Bharatiya Nyaya Sanhita, 2023, depending on the circumstances. The electronic nature of the publication does not automatically remove legal responsibility. Victims should preserve the relevant online material as evidence and may seek appropriate legal remedies.

7. Cyber Bullying

Cyber bullying means using digital platforms to harass, threaten, insult, embarrass, or humiliate another person. It can occur through social media, messaging applications, online gaming platforms, emails, or other electronic communication. Common forms include spreading rumours, sharing embarrassing content, sending threatening messages, and creating fake accounts to target someone. Cyber bullying can seriously affect a person’s privacy, reputation, and mental well being. Depending on the conduct, various provisions of Indian laws may apply. Victims should block offenders where appropriate, preserve evidence, report abusive content to the platform, and approach the authorities when the conduct involves threats or other offences.

8. Cyber Terrorism

Cyber terrorism involves the use of computer resources or communication technology for activities intended to threaten the security, sovereignty, or integrity of India or to cause serious disruption. Attacks may target critical infrastructure, government systems, communication networks, or other important computer resources. Section 66F of the Information Technology Act, 2000 specifically deals with cyber terrorism. The offence carries severe punishment because attacks on critical systems can affect national security and public safety. Cyber terrorism is therefore considered one of the most serious forms of cyber crime and requires strong cybersecurity measures and coordinated action by law enforcement agencies.

9. Data Theft

Data theft refers to the unauthorised copying, downloading, transferring, or obtaining of electronic information. The stolen information may include business records, customer details, financial information, confidential documents, or personal data. Criminals may obtain data through hacking, malware, phishing, insider misuse, or weak security controls. Under Section 43 of the Information Technology Act, 2000, unauthorised downloading, copying, or extraction of data from a computer resource may attract liability. Where the conduct is done dishonestly or fraudulently, Section 66 may also become relevant. Data theft can cause financial loss, privacy violations, and serious business consequences.

10. Malware Attacks

Malware means malicious software designed to damage, disrupt, monitor, or gain unauthorised access to computer systems or data. Common forms include viruses, worms, trojans, spyware, and ransomware. Malware may enter a system through malicious attachments, infected websites, unsafe downloads, or compromised software. Once installed, it may steal information, damage files, monitor activities, or prevent users from accessing their data. Malware attacks can affect individuals, businesses, and government organisations. Unauthorised damage to or interference with computer resources may attract provisions of Sections 43 and 66 of the Information Technology Act, 2000, depending on the circumstances.

Common Methods of Digital Fraud and Online Financial Fraud:

1. Phishing

Phishing is one of the most common methods of digital fraud. Fraudsters send fake emails, SMS, messages, or website links that appear to come from trusted organisations such as banks, government departments, or online services. The victim is encouraged to click a link and provide confidential information such as usernames, passwords, OTPs, or banking details. The stolen information may then be used for unauthorised transactions or identity theft. Phishing may attract provisions of the Information Technology Act, 2000 and other applicable laws. Users should carefully check website addresses, avoid suspicious links, and never share confidential banking information through unverified messages. Banks and genuine organisations generally do not ask customers to disclose their PINs, passwords, or OTPs.

2. Vishing

Vishing, or voice phishing, is a form of fraud conducted through telephone calls or voice communication. Fraudsters often impersonate bank officials, customer care representatives, government officers, or other trusted persons. They may create urgency by claiming that an account will be blocked or that verification is required. The victim may then be persuaded to reveal OTP, PIN, password, card details, or other confidential information. The information may subsequently be used to conduct unauthorised transactions. Depending on the circumstances, such activities may attract provisions of the Information Technology Act, 2000 and other applicable criminal laws. People should independently verify the caller’s identity and should never disclose confidential banking credentials during unsolicited calls.

3. Smishing

Smishing is a type of phishing carried out through SMS or instant messaging applications. Fraudsters send messages containing malicious links or false information about bank accounts, parcels, refunds, electricity bills, KYC verification, or financial rewards. When the victim clicks the link, they may be directed to a fake website or asked to install malicious software. The fraudster may then obtain personal or financial information. Smishing can result in identity theft, account compromise, or financial loss. Depending on the facts, provisions of the Information Technology Act, 2000 and other applicable laws may apply. Users should avoid clicking unknown links and should verify messages through the organisation’s official communication channels.

4. UPI Fraud

UPI fraud involves deceptive use of Unified Payments Interface (UPI) to obtain money from victims. Fraudsters may send fake payment requests, impersonate buyers or sellers, or falsely claim that a person must enter a UPI PIN to receive money. In reality, entering a UPI PIN generally authorises a payment from the user’s account. Criminals may also use fraudulent QR codes or fake customer support numbers. Depending on the circumstances, provisions of the Information Technology Act, 2000 and other applicable criminal laws may apply. Users should carefully verify payment requests, avoid sharing UPI credentials, and immediately report unauthorised transactions to their bank and appropriate authorities.

5. Credit and Debit Card Fraud

Credit and debit card fraud occurs when criminals obtain and misuse card information to make unauthorised purchases or transactions. Fraudsters may collect card details through phishing websites, fake calls, malicious applications, or compromised payment systems. They may request the card number, CVV, PIN, or OTP by pretending to be legitimate representatives. The stolen information can then be used for fraudulent transactions. Depending on the circumstances, such conduct may attract provisions of the Information Technology Act, 2000 and other applicable laws. Cardholders should regularly monitor their account statements, enable transaction alerts, avoid sharing confidential card information, and immediately inform their bank about any unauthorised transaction.

6. Identity Theft

Identity theft is a method of digital fraud in which criminals obtain and misuse another person’s personal or electronic identification information. They may use stolen passwords, electronic signatures, account credentials, or other identifying information to impersonate the victim. Under Section 66C of the Information Technology Act, 2000, fraudulent or dishonest use of another person’s electronic signature, password, or other unique identification feature is punishable. Identity theft may lead to financial loss, unauthorised transactions, and reputational damage. Individuals should protect their personal information, use strong passwords, enable appropriate security measures, and avoid sharing sensitive information with unknown persons or unverified websites.

7. Online Shopping Fraud

Online shopping fraud occurs when criminals use fake websites, social media accounts, or online marketplaces to deceive customers. They may advertise products at unusually low prices, collect advance payments, and then fail to deliver the product. In other cases, victims may receive counterfeit, damaged, or completely different goods. Fraudsters may also misuse customer information collected during the transaction. Depending on the circumstances, the Consumer Protection Act, 2019, Information Technology Act, 2000, and other applicable laws may be relevant. Consumers should verify the seller’s identity, website authenticity, reviews, return policy, and payment details before completing an online purchase.

8. Investment Fraud

Online investment fraud involves false investment opportunities promoted through websites, social media, messaging applications, or online advertisements. Fraudsters may promise guaranteed returns, quick profits, or unusually high returns with little or no risk. After obtaining money, they may create additional demands for taxes, withdrawal charges, or processing fees. Eventually, the victim may be unable to recover the money. Depending on the circumstances, such conduct may attract provisions of the Bharatiya Nyaya Sanhita, 2023, Information Technology Act, 2000, and securities laws where applicable. Investors should verify the identity and regulatory status of the platform or intermediary before transferring money.

9. Malware and Ransomware

Malware is malicious software designed to damage systems, steal information, or obtain unauthorised access. Ransomware is a type of malware that may encrypt or restrict access to files and demand payment from the victim. Malware can enter a device through malicious links, email attachments, unsafe downloads, or compromised websites. It can cause financial loss, data loss, and disruption of business operations. Unauthorised access, copying, or damage to computer resources may attract provisions of Sections 43 and 66 of the Information Technology Act, 2000, depending on the circumstances. Users should maintain updated software, use security tools, take regular backups, and avoid suspicious downloads.

10. Business Email Compromise

Business Email Compromise (BEC) is an online financial fraud in which criminals impersonate a company executive, employee, supplier, or business partner. Fraudsters may use compromised or fake email accounts to instruct employees to transfer money to a fraudulent bank account. They may also alter invoices or provide false payment instructions. Because the communication appears to come from a trusted source, employees may unknowingly authorise large financial transactions. Such fraud may involve offences under the Bharatiya Nyaya Sanhita, 2023, Information Technology Act, 2000, and other applicable laws. Businesses should independently verify unusual payment requests, especially requests involving changes in bank account details or urgent transfers.

Offences for E-Frauds and illegitimate Digital Arrest:

1. E-Fraud

E-fraud refers to fraudulent activities committed through computers, mobile phones, internet services, or digital payment systems with the intention of obtaining money or other benefits dishonestly. Common examples include phishing, identity theft, UPI fraud, online banking fraud, card fraud, and fake investment schemes. Depending on the facts, such offences may attract provisions of the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023. Section 66C of the IT Act deals with identity theft, while Section 66D deals with cheating by personation using a computer resource or communication device. Victims should preserve digital evidence and report financial fraud immediately.

2. illegitimate Digital Arrest

Digital arrest is a fraudulent practice in which criminals falsely claim to be police officers, government officials, judges, or other authorities and threaten a person with arrest through a video call or other digital communication. Genuine Indian law enforcement authorities do not conduct arrests or legal proceedings through video calls or demand money to avoid arrest. Fraudsters may use fake documents, uniforms, and official-looking communications to create fear and pressure victims into transferring money. Such conduct may involve cheating, personation, extortion, and identity-related offences under the Bharatiya Nyaya Sanhita, 2023 and, where applicable, the Information Technology Act, 2000.

Penalties for E-Frauds and illegitimate Digital Arrest:

1. Penalties for E-Frauds

Penalties for e-frauds depend on the nature of the offence and the applicable law. Under Section 66D of the Information Technology Act, 2000, cheating by personation using a computer resource or communication device is punishable with imprisonment up to three years and fine up to ₹1 lakh. Section 66C provides punishment for identity theft, including imprisonment up to three years and fine up to ₹1 lakh. Additional punishment may apply under the Bharatiya Nyaya Sanhita, 2023, depending on the specific fraudulent act. Courts consider the nature of the offence, financial loss, intention, and other circumstances while determining liability.

2. Penalties for Illegitimate Digital Arrest

An illegitimate digital arrest is a fraudulent scheme and not a legally recognised form of arrest. Persons using fake identities or authority to threaten victims and obtain money may face criminal liability for cheating, personation, extortion, and related offences. Under Section 319 of the Bharatiya Nyaya Sanhita, 2023, cheating by personation may attract imprisonment up to five years, or fine, or both, subject to the statutory requirements. Where computers or communication devices are used for cheating by personation, Section 66D of the Information Technology Act, 2000 may also apply. Additional offences and penalties can arise depending on the conduct.

Liability and Punishment for Cyber Fraud under Applicable Laws:

1. Liability Under the Information Technology Act, 2000

Cyber fraud may create civil and criminal liability under the Information Technology Act, 2000. Section 43 provides liability for unauthorised access, downloading, copying, or damage to computer resources. Where such acts are committed dishonestly or fraudulently, Section 66 may apply and prescribe criminal punishment. Section 66C deals with identity theft, while Section 66D deals with cheating by personation using a computer resource or communication device. Under Section 66C and Section 66D, the offender may face imprisonment up to three years and fine up to ₹1 lakh. The exact liability depends on the facts and evidence.

2. Liability Under Bharatiya Nyaya Sanhita, 2023

Cyber fraud may also attract liability under the Bharatiya Nyaya Sanhita, 2023 (BNS), depending on the nature of the fraudulent conduct. Fraudulent activities involving cheating, dishonest inducement, personation, forgery, or extortion may attract criminal punishment under the relevant provisions. For example, Section 318 of the BNS deals with cheating, while Section 319 deals with cheating by personation. The punishment depends upon the specific offence and circumstances. Where a cyber fraud involves both digital technology and traditional criminal conduct, provisions of the IT Act, 2000 and BNS may apply together, subject to the applicable legal provisions.

3. Liability for Identity Theft

Identity theft is a specific cyber offence under Section 66C of the Information Technology Act, 2000. It occurs when a person fraudulently or dishonestly uses another person’s electronic signature, password, or other unique identification feature. The offender may be punished with imprisonment up to three years and fine up to ₹1 lakh. Identity theft may also lead to additional liability if the stolen identity is subsequently used for cheating, financial fraud, impersonation, or unauthorised transactions. Therefore, the offender may face punishment under the IT Act as well as other applicable criminal laws, depending on the nature of the complete fraudulent activity.

4. Liability for Cheating by Personation

Section 66D of the Information Technology Act, 2000 specifically addresses cheating by personation using a computer resource or communication device. This provision may apply to fraudsters who impersonate bank officials, police officers, government officials, customer care representatives, or other persons through digital means to deceive victims. The punishment under Section 66D is imprisonment up to three years and fine up to ₹1 lakh. Additional punishment may arise under the Bharatiya Nyaya Sanhita, 2023, where the conduct also constitutes cheating or personation under its provisions. Liability depends upon the evidence establishing the fraudulent intention and the acts committed.

5. Liability for Unauthorised Access and Data Theft

Unauthorised access to computer systems and data theft may attract liability under Section 43 of the Information Technology Act, 2000. The provision covers activities such as unauthorised access, downloading, copying, extracting, or damaging data and computer resources. Where the same acts are performed dishonestly or fraudulently, Section 66 may also apply and make the conduct criminal. The offender may therefore face imprisonment and fine, depending on the offence established. Where the stolen data is subsequently used for identity theft, cheating, or financial fraud, additional provisions of the IT Act and BNS may also become applicable.

One thought on “Cyber Crimes: Offences and Penalties for E-Frauds and illegitimate Digital Arrest

Leave a Reply

error: Content is protected !!