Cyber Crime Law in India: Current Legal Framework, Reporting and Remedies

Cybercrime in India is not governed by one single offence or statute. A modern cyber-fraud, identity-theft, impersonation, account-takeover, obscene-content, data or online-cheating case may involve the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023 (BNS), the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) and the Bharatiya Sakshya Adhiniyam, 2023 (BSA).

For financial cyber fraud, speed is especially important. The Government of India’s National Cyber Crime Reporting Portal identifies 1930 as the 24×7 helpline for immediate reporting of cyber financial fraud and provides online reporting through the National Cyber Crime Reporting Portal.

This guide explains the current legal framework, common cyber offences, online cheating and impersonation, where to report cyber fraud, evidence preservation, territorial jurisdiction, bank-account freezing issues and practical steps for victims and accused persons.

What Laws Apply to Cyber Crime in India?

Depending on the facts, a cybercrime case may involve several statutes at the same time:

  • Information Technology Act, 2000: computer-related offences, identity theft, computer-resource impersonation, privacy violations, cyber terrorism and specified unlawful electronic content.
  • Bharatiya Nyaya Sanhita, 2023: cheating, cheating by personation, criminal breach of trust, extortion, forgery and other substantive offences committed through digital means.
  • Bharatiya Nagarik Suraksha Sanhita, 2023: FIR/investigation, search and seizure, jurisdiction, arrest, bail, police report and trial procedure.
  • Bharatiya Sakshya Adhiniyam, 2023: proof and admissibility of electronic/digital records.
  • Other sectoral laws: banking, payment, securities, child protection, data protection or specialised regulatory statutes may apply depending on the transaction and victim.

Important Cyber Offences Under the Information Technology Act

The Information Technology Act remains a central statute for computer and electronic offences. Important provisions include:

  • Section 65: tampering with computer source documents.
  • Section 66: computer-related offences.
  • Section 66B: dishonestly receiving stolen computer resource or communication device.
  • Section 66C: punishment for identity theft.
  • Section 66D: cheating by personation by using a computer resource.
  • Section 66E: violation of privacy.
  • Section 66F: cyber terrorism.
  • Sections 67, 67A and 67B: specified obscene, sexually explicit and child sexual content transmitted or published electronically.

The current official statute can be checked on India Code — Information Technology Act, 2000.

Identity Theft Under Section 66C IT Act

Identity theft can involve dishonest or fraudulent use of another person’s electronic signature, password or other unique identification feature. In practical cybercrime investigations, alleged identity misuse may involve credentials, login details, payment identifiers, SIM-linked accounts or other digital identity material depending on the facts.

Preserve the account logs, login alerts, device information, OTP records, recovery emails and platform communications that show when and how the identity was allegedly misused.

Online Impersonation and Section 66D IT Act

Section 66D specifically addresses cheating by personation using a communication device or computer resource. Common fact patterns may include:

  • fraudsters pretending to be bank officers;
  • fake customer-care representatives;
  • impersonation of police, courier, customs or government officials;
  • fake matrimonial or dating identities;
  • business-email impersonation;
  • social-media account impersonation;
  • investment or trading scams using false identities;
  • fraudulent job or recruitment profiles.

Depending on the facts, BNS cheating/personation provisions may also be invoked.

BNS Sections 318 and 319 in Cyber Fraud Cases

Section 318 BNS is the current general cheating provision. It becomes relevant where deception fraudulently or dishonestly induces delivery or retention of property or causes the legally defined harm. Section 319 BNS deals with cheating by personation.

Cyber fraud frequently involves both the digital means of deception and the underlying financial/property offence. The IT Act and BNS must therefore be mapped to the exact allegation rather than treating “cybercrime” as one generic offence.

For the cheating framework in detail, see our Section 318 BNS cheating guide.

Common Types of Cybercrime

1. UPI and Online Payment Fraud

Fraud may involve fake collect requests, malicious links, remote-access applications, impersonation, OTP theft, QR-code deception or compromised credentials. Preserve transaction IDs/UTR numbers, account details, phone numbers and all communications.

2. Investment and Trading Fraud

Victims may be induced to transfer funds to fake trading platforms, investment groups or accounts controlled by fraud networks. Screenshots alone are rarely enough; preserve payment trails, app/website URLs, chats, account statements and representations promising returns.

3. Business Email Compromise

A fraudster may impersonate a vendor, employee or senior officer and change bank-account details or payment instructions. Preserve original email headers, not merely printed emails.

4. Account Takeover and Identity Theft

Email, social-media, messaging or financial accounts may be compromised through stolen credentials, SIM-related fraud or malicious links. Immediately secure the account, preserve security alerts and inform the relevant platform.

5. Cyber Blackmail and Sextortion

Threats to publish private images, manipulated content or intimate communications may involve extortion and IT Act/BNS offences depending on the facts. Do not destroy the threatening communications; preserve account identifiers, URLs and payment demands.

6. Dating and Matrimonial Scams

False identity, fabricated emergencies and requests for money are common patterns. These cases may involve impersonation, cheating and extortion depending on the conduct.

7. Social-Media Impersonation and Fake Profiles

Record the complete profile URL, username, creation/context details, screenshots and platform complaint reference before the profile is taken down.

How to Report Cyber Financial Fraud: 1930 and NCRP

For cyber financial fraud, the National Cyber Crime Reporting Portal advises immediate reporting through 1930, the national helpline, and through the National Cyber Crime Reporting Portal.

The official portal is available at cybercrime.gov.in.

The Government portal’s complainant checklist asks victims of financial fraud to keep information such as:

  • incident date and time;
  • incident details;
  • bank/wallet/merchant name;
  • transaction ID or UTR;
  • date of transaction;
  • fraud amount;
  • relevant evidence;
  • suspect mobile number/email/bank account/URL where available.

Speed can matter because financial-fraud response mechanisms may attempt to identify and interrupt the movement of funds.

Should You Also Approach the Police or Cyber Cell?

The appropriate route depends on the offence and urgency. Online reporting does not eliminate the need for police investigation where a cognizable offence is alleged. Preserve the NCRP acknowledgement/complaint number and any communication from the investigating agency.

If the complaint involves threats, sexual offences, stalking, immediate physical danger or other urgent criminal conduct, do not treat a portal filing as the only necessary step.

Where Can an Electronic Cheating Case Be Tried?

Section 202 BNSS contains a specific territorial-jurisdiction rule for offences including cheating committed through electronic communications, letters or telecommunication messages. Such an offence may be inquired into or tried where the relevant electronic communication/message was sent or received.

For cheating that dishonestly induces delivery of property, jurisdiction may also arise where the property was delivered by the person deceived or received by the accused.

This rule can be important in remote UPI, email, marketplace and online-investment fraud where victim, accused, bank accounts and servers may be in different places.

Electronic Evidence in Cybercrime Cases

Cybercrime cases are evidence-intensive. Relevant evidence may include:

  • transaction records;
  • UTR/reference numbers;
  • bank statements;
  • device records;
  • IP/login records where lawfully obtained;
  • emails with headers;
  • WhatsApp/Telegram chats;
  • call logs and recordings;
  • social-media URLs;
  • website/app URLs;
  • screenshots plus underlying source data;
  • CCTV at cash-withdrawal or account-opening locations;
  • KYC/account-opening material;
  • platform responses and grievance records.

Under the current evidence law, the BSA expressly recognises electronic and digital records. Section 63 contains important admissibility and certificate requirements for specified computer output.

See our Bharatiya Sakshya Adhiniyam evidence guide.

Bank Account Frozen or Put on Lien After Cybercrime Complaint

Cyber-fraud investigations often affect not only the original recipient account but also downstream accounts through which disputed funds moved. A person or business may discover that an account is frozen, debit-restricted or marked with a lien after a cybercrime complaint.

Do not assume that an account freeze automatically proves guilt. Obtain the bank communication, complaint/FIR details where available, investigating officer information, amount under dispute and transaction chain. The legal response may differ where the account holder is the alleged fraudster, a money mule, a downstream recipient, merchant, business counterparty or an innocent third party.

For this issue specifically, see our guide on bank accounts frozen due to UPI/cyber transactions.

Cybercrime Against Businesses

Companies should treat cybercrime response as both an investigation and evidence-preservation exercise. Immediate steps may include:

  • preserve affected devices and logs;
  • reset compromised credentials using a controlled process;
  • notify banks/payment processors where funds are at risk;
  • preserve email headers and server logs;
  • identify affected accounts and systems;
  • maintain an incident chronology;
  • restrict unnecessary access without destroying evidence;
  • coordinate legal, IT/security and management response;
  • review data-protection/contractual notification obligations where relevant.

Defence in a Cybercrime Case

An accused or account holder should focus on attribution and evidence. Questions may include:

  • Who controlled the device/account at the relevant time?
  • Is identity established or merely inferred from a phone number or bank account?
  • Was the account itself compromised?
  • What transaction did the accused actually receive?
  • Was the payment a legitimate commercial transaction?
  • Is there evidence of deception or dishonest intention?
  • Are chats or screenshots complete and authentic?
  • Is the IP/device evidence properly linked to the person?
  • Was money transferred onward innocently or as part of a fraud network?
  • Does territorial jurisdiction exist?

Where the allegation is essentially financial deception, the ingredients of Section 318 BNS must still be proved. Where arrest or custody is threatened, see the Bail Law in India guide.

Cybercrime FIR and Charge Sheet

After investigation, the police report should be examined offence-by-offence. A cybercrime charge sheet may rely heavily on bank records, device extraction, platform responses, KYC, CDR/technical evidence and witness statements. Defence review should test both statutory ingredients and the evidentiary chain.

See our current guide on charge sheets under BNSS.

What to Do Immediately After Cyber Financial Fraud

  1. Call 1930 promptly for cyber financial fraud.
  2. Register the complaint through the National Cyber Crime Reporting Portal.
  3. Inform your bank/payment provider immediately.
  4. Preserve UTR/transaction IDs and bank statements.
  5. Preserve chats, email headers, phone numbers, URLs and screenshots.
  6. Do not continue paying a fraudster who claims more money is needed to release earlier funds.
  7. Change compromised passwords and secure linked accounts.
  8. Keep the NCRP acknowledgement and all complaint references.
  9. Where required, approach the competent police/cyber cell and obtain case details.

Frequently Asked Questions

What number should I call for cyber financial fraud in India?

The National Cyber Crime Reporting Portal identifies 1930 as the helpline for immediate reporting of cyber financial fraud.

Where can cybercrime be reported online?

The Government of India operates the National Cyber Crime Reporting Portal at cybercrime.gov.in.

Which law applies to online identity theft?

Depending on the facts, Section 66C IT Act can apply to identity theft. Online impersonation may also engage Section 66D IT Act and BNS personation/cheating provisions.

Can BNS cheating apply to online fraud?

Yes, where the statutory ingredients of cheating are established. BNSS Section 202 also contains a jurisdiction rule for cheating through electronic communications.

Are screenshots enough in a cybercrime case?

Screenshots may be relevant, but authenticity, completeness and admissibility matter. Preserve the underlying digital record and comply with the BSA electronic-evidence framework where applicable.

Does a bank freeze mean the account holder is guilty?

No. A freeze or lien is an investigative/transaction-control measure and does not by itself establish criminal guilt. The account holder’s role and transaction evidence must be examined.

Primary Legal and Government Sources

Disclaimer

This article is for legal education and general information only. It is not solicitation or case-specific legal advice. Cybercrime cases vary significantly depending on the offence, platform, transaction chain, evidence, investigating agency and jurisdiction.

Leave a Comment

Your email address will not be published. Required fields are marked *