Information Technology Act, 2000
Cybercrime Meaning and Classification: Types of Cyber Offences Explained
The IT Act never defines cybercrime; the term covers every offence in which a computer, network or digital device is the target, the instrument or the store of evidence. The offence sections have been studied provision by provision in Topics 56 to 62; what the examiner also expects is the criminological vocabulary, what phishing, ransomware or a SIM swap actually are, and where each species sits in the statute book. This note supplies that layer: the classifications, the technical families, the fraud ecosystem, the offences against persons and society, and one map from conduct to provision.
1. Meaning and Classification
- Meaning. A crime committed by means of, or directed at, computers, computer systems, networks or data: the conventional working definition, since neither the IT Act nor the BNS defines the term. The IT Act supplies the specifically electronic offences; the BNS supplies the general offences committed through electronic means.
- Classification by target. The standard taxonomy runs by victim: crimes against individuals (identity theft, stalking, image-based abuse, personal frauds), against property (data theft, ransomware, damage to systems), against businesses (breaches, business email compromise, espionage), against government (attacks on protected systems, espionage), and against society at large (obscenity, child sexual abuse material, cyber terrorism, mass frauds)
Figure 1: The five target classes
Figure 2: The computer's three roles
- Computer as target. The system itself is attacked: hacking, malware, denial of service, defacement, the s.43 with s.66 territory.
- Computer as instrument. The system is the weapon for a conventional wrong: fraud, impersonation, stalking, extortion, where IT Act and BNS provisions run together.
- Computer as repository of evidence. In any crime at all, the device may simply hold the proof, engaging the electronic evidence and forensics framework rather than a cyber offence (Topics 9, 24)
2. Intrusion, Malware and Attacks
- Hacking and cracking. Unauthorised access to or manipulation of a computer resource; usage distinguishes the cracker, who breaks in with criminal intent, from the wider hacking vocabulary that includes security research. The law does not use either word since 2008: the conduct is s.43(a) access without permission, criminal under s.66 when dishonest or fraudulent (Topics 53, 58)
- Data breach and database theft. Unauthorised extraction or copying of data, s.43(b) downloading and copying, s.66 when dishonest, with s.72A for service provider disclosures, and the DPDP Act's civil regime for the personal data dimension.
- Website defacement. Altering a site's content, classically diminishing information value under s.43(i) with s.66, and s.66F where a government site is struck on terror scale.
- Denial of service and DDoS. Flooding a service until legitimate users are locked out, s.43(f) denial of access with s.66; distributed attacks marshal a botnet to the same end, and s.66F where critical infrastructure is targeted.
- Injection and interception attacks. SQL injection smuggles database commands through input fields; cross-site scripting plants script in pages served to other users; a man-in-the-middle attack interposes between two communicating parties to read or alter traffic; brute force and password attacks grind through credential guesses. All are modes of s.43 access, damage or disruption, criminalised through s.66.
Figure 3: The malware family
- The malware family. Virus (attaches to files, spreads on execution), worm (self-replicates across networks), trojan horse (malice disguised as useful software), spyware and keyloggers (covert surveillance of activity and keystrokes), botnet (a herd of compromised machines under remote command), logic bomb (dormant code triggered by an event), cryptojacking (stolen computing power mining cryptocurrency). Introducing any computer contaminant is s.43(c) conduct, criminal under s.66.
- Ransomware. Malware that encrypts the victim's data and demands payment for the key, today's dominant enterprise threat: s.43 with s.66 for the intrusion and damage, extortion under the BNS for the demand, s.66F where essential services are paralysed, and a CERT-In reportable incident (Topic 64)
3. Deception and Financial Frauds
Figure 4: The phishing family
- The phishing family. Phishing casts mass deceptive messages to harvest credentials or payments; spear phishing researches and aims at a chosen victim; whaling targets executives; smishing works by SMS and messaging apps; vishing by voice call, often a spoofed authority. The standard charge set is s.66C for the credential misuse, s.66D for the impersonation, s.66 for any intrusion, with BNS cheating.
- Spoofing. Forging the apparent source, email spoofing (forged headers), website spoofing (look-alike sites), IP spoofing (forged network addresses), the deception layer beneath phishing and BEC, punished through ss.66C, 66D and the cheating and forgery provisions.
- Identity theft and impersonation. Dishonest use of another's password, signature or unique identifier is s.66C; cheating by personation through a computer resource is s.66D, the section carrying every customer-care, KYC and fake-profile fraud (Topic 60)
- Account takeover frauds. SIM swap (a duplicate SIM captures OTP traffic), OTP fraud (the victim is talked into reading out the code), remote access app fraud (screen-sharing apps installed on pretext), QR code fraud (a scan that debits instead of crediting), feeding UPI, card and internet banking frauds: ss.66C and 66D with BNS cheating, and the bank's limited-liability circulars on the civil side.
- Business email compromise. A spoofed or hijacked corporate mailbox redirects genuine payment flows to attacker accounts, the highest-value fraud class: ss.66, 66C, 66D with cheating and forgery, and often a cross-border trail (Topic 86)
- Investment, crypto and job frauds. Long-con platforms showing fictitious returns, fake exchanges and wallet drains, advance-fee and task-based job scams, frequently run at scale from organised compounds; the charges are cheating and s.66D, with money laundering law on the proceeds.
- The digital arrest scam. The current signature fraud: callers posing as police, customs or courts on video, complete with uniforms and fabricated warrants, keep the victim under continuous surveillance as under arrest until savings are transferred for verification. There is no such thing as a digital arrest in law; the conduct is s.66D impersonation with cheating and extortion, and Government advisories and mass blocking of the calling infrastructure have followed.
- Social engineering and extortion. The common engine of the fraud chapter is psychological, urgency, authority, fear and greed rather than code; online extortion threatens exposure, attack or embarrassment for payment, BNS extortion with the relevant IT Act sections.
Figure 5: Anatomy of a financial cyber fraud
4. Against Persons and Society
- Stalking, bullying, harassment and trolling. Cyberstalking is persistent monitoring and contact, BNS stalking expressly covering electronic means; cyberbullying and harassment span insults, threats and coordinated abuse, prosecuted through BNS intimidation, insult and stalking provisions since s.66A's fall; trolling is actionable only when it crosses into those offences or defamation (Topic 59)
- Doxxing. Publishing a person's private identifying details to direct harassment at them; charged through stalking, intimidation and privacy provisions, with the 2026 intermediary clocks for removal.
- Sextortion and image-based abuse. Sextortion extorts money or acts under threat of publishing intimate material; revenge porn, non-consensual intimate imagery, is s.66E and s.67 or 67A territory with BNS voyeurism; deepfake pornography adds the synthetic dimension, s.66E, 67, 67A with the SGI labelling regime and the two-hour removal clock (Topics 60, 61, 75)
- Grooming and child sexual abuse material. Online grooming and every dealing with child sexual abuse material fall under s.67B, which reaches creation, collection, browsing, downloading and facilitation, alongside POCSO; Just Rights for Children Alliance settles that storage and viewing are themselves punishable, and intermediaries carry reporting duties (Topic 61)
- Cyber terrorism, espionage and warfare. Cyber terrorism is s.66F, striking at sovereignty, security or critical infrastructure with terror intent, punishable to life; cyber espionage is state or corporate theft of protected information, ss.66, 66F and the Official Secrets Act; cyber warfare denotes state-on-state operations, governed by international law rather than the domestic statute, with NCIIPC and CERT-In as the defensive institutions (Topics 60, 62 to 64)
- Cyber defamation. Defamatory imputations published electronically, the BNS defamation offence and the civil action, with the intermediary's position governed by s.79 and Shreya Singhal's actual-knowledge rule (Topic 67)
5. The Map from Conduct to Provision
Figure 6: Where each family sits in the statute book
⚠ Exam trap Answer definition questions with structure: no statutory definition, then the two classifications, by target (individuals, property, businesses, government, society) and by the computer's role (target, instrument, repository). Attach a section to every species you name, phishing to ss.66C and 66D, ransomware to s.43 with s.66 and extortion, CSAM to s.67B with POCSO, cyber terrorism to s.66F, and remember that defamation, cheating and extortion have no IT Act section at all and travel under the BNS. And do not present hacking as a defined offence: the word left the statute in 2008, and the conduct lives in s.43 with s.66. |
6. Frequently Asked Questions
How is cybercrime classified?
Two classifications organise the field. By target: crimes against individuals (identity theft, stalking, image-based abuse), against property (data theft, ransomware, system damage), against businesses (breaches, business email compromise), against government (attacks on protected systems, espionage) and against society (obscenity, child sexual abuse material, cyber terrorism, mass frauds). By the computer's role: the computer as target of the crime, as instrument of the crime, and as repository of the evidence of any crime.
7. Related Topics
- Topic 60: Sections 66B to 66F. The specific offences behind the fraud vocabulary.
- Topic 86: Cybercrime Investigation. How these crimes are traced and prosecuted.