Information Technology Act, 2000

Phishing vs Spoofing: Difference, Types and Legal Provisions

The two words travel together because the crimes do: nearly every phishing message arrives wearing a spoofed identity. But they name different things, phishing is an attack, defined by what the victim is deceived into surrendering, while spoofing is a technique, defined by what the attacker pretends to be, and the distinction organises both the analysis and the charge sheet. Topic 85 placed both in the fraud ecosystem; this note, as asked, is the dedicated comparison.

1. Attack Against Technique

The con and the mask

Figure 1: The con and the mask

  • Phishing. A deception campaign, by email, SMS, call, message or advertisement, that lures the victim into surrendering credentials, card details, OTPs or payments, classically through a link to a counterfeit page where the details are typed. Its species vary by channel and target, spear phishing, whaling, smishing, vishing (Topics 85, 103), but the constant is the victim's induced act: the fraud completes when something is handed over.
  • Spoofing. The forgery of apparent identity in electronic communication: making a message, call or connection appear to come from someone else. It needs no response from anyone, a forged header is spoofed the moment it is sent, and it serves many masters: phishing lures, business email compromise, malware delivery, and network attacks that defeat filters or hide origin.
  • The relationship. Spoofing is the mask, phishing the con played from behind it: most phishing uses spoofing to look like the bank, the courier or the boss, but spoofing appears without phishing, IP spoofing in a DoS attack, and phishing can proceed with no technical forgery at all, a plausible unknown number and a persuasive script sufficing.

2. The Spoofing Families

Four masks and their law

Figure 2: Four masks and their law

  • Email spoofing. Forged sender addresses and headers, the oldest form, carrying phishing lures and the payment-diversion mails of business email compromise; the forgery of the electronic record engages BNS forgery alongside the IT Act sections.
  • Website spoofing. Look-alike domains and cloned login pages, the landing site of most phishing; typosquatted domains add the trademark dimension (Topic 90), and the page itself is the instrument of s.66D cheating by personation.
  • IP spoofing. Forged source addresses at the network layer, concealing origin, impersonating trusted hosts or amplifying denial of service; being pure intrusion technique, it is charged through s.43 with s.66 rather than the deception sections.
  • Caller ID and SMS sender spoofing. Displayed numbers and alphanumeric sender IDs imitating banks and authorities, the costume of vishing and smishing and of the digital arrest scam; telecom regulations on header registration attack the channel while ss.66C and 66D attack the fraud (Topics 85, 103)

3. The Charges

  • For phishing. s.66C for the dishonest use of the harvested passwords and unique identification features, s.66D for cheating by personation through the computer resource or communication device, BNS cheating for the property obtained, and s.66 where accounts or systems were penetrated; the money is chased through the 1930 freeze machinery (Topics 60, 86)
  • For spoofing. s.66 read with s.43 for the unauthorised acts on systems and networks, BNS forgery where a false electronic record is made with intent to deceive, and, the moment the spoofed identity is deployed against a victim, ss.66C and 66D exactly as in phishing, so the completed fraud usually carries both sets.
  • Proof in practice. Phishing is proved from the victim's end, the message, the fake page, the surrendered data and the money trail; spoofing from the technical end, headers, server logs and registrar records tracing the forged source, the s.79A examination tying both to the accused (Topics 82, 86)

⚠ Exam trap

Define by category first: phishing is an attack measured by what the victim surrenders, spoofing a technique measured by what the attacker pretends to be, and neither word appears in the statute, so the marks are in the mapping, ss.66C and 66D with cheating for the phishing fraud, s.66 with s.43 and forgery for the spoofed source, both sets together in the completed scam. And keep the one-way relationship straight: most phishing rides on spoofing, but spoofing serves intrusions and denial of service where no one is phished at all.

4. Frequently Asked Questions

What is the difference between phishing and spoofing?

Phishing is an attack: a deceptive message or call that induces the victim to surrender credentials, OTPs, card details or payments, complete when something is handed over. Spoofing is a technique: forging the apparent source of a communication, the sender address, website, IP address or caller ID, complete the moment the forged identity is presented, whether or not anyone responds. Most phishing uses spoofing as its mask, but spoofing also serves intrusions and denial of service attacks where nothing is extracted from any victim.

Under which provisions are phishing and spoofing punished?

Phishing is charged under Section 66C for dishonest use of passwords and unique identification features, Section 66D for cheating by personation using a computer resource or communication device, and BNS cheating, with Section 66 added where systems were penetrated. Spoofing is charged under Section 66 read with Section 43 for the unauthorised technical acts and BNS forgery for the false electronic record, and once the spoofed identity is used to deceive a victim, Sections 66C and 66D apply as well, so completed frauds ordinarily carry both sets.

5. Related Topics

  • Topic 85: Cybercrime typology. The fraud ecosystem around both.
  • Topic 103: Vishing vs Smishing. The phishing family's channel split.