All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Sections 66B to 66F IT Act: Specific Cyber Offences

Section 66 is the general offence; Sections 66B to 66F, all inserted in 2008, are the specialists. Each takes one recurring wrong and gives it defined elements: receiving stolen devices (66B), stealing identities (66C), cheating behind a false face (66D), violating bodily privacy through images (66E), and terrorising the nation through its computers (66F). Between them they cover most of what a cyber police station registers in a day. This note works through each offence, separates the commonly confused pairs, and maps the modern fraud patterns, phishing, OTP and UPI fraud, SIM swaps, romance scams, business email compromise, onto the exact provisions.

1. Five Specialists after One Generalist

A general physician treats whatever walks in; specialists own their organ. Section 66 is the generalist, taking any dishonest Section 43 act. The 2008 Amendment then hired five specialists: the receiver of stolen goods, the identity thief, the impersonating cheat, the privacy violator and the cyber terrorist each got a section with tailored elements and tailored punishment. In a problem question, always ask first whether a specialist section fits before falling back on the generalist.

The five specific offences at a glance

Figure 1: The five specific offences at a glance

2. Section 66B: Receiving Stolen Computer Resource or Device

Section 66B, Information Technology Act, 2000

Whoever dishonestly receives or retains any stolen computer resource or communication device knowing or having reason to believe the same to be stolen computer resource or communication device, shall be punished with imprisonment of either description for a term which may extend to three years or with fine which may extend to rupees one lakh or with both.

The elements of Section 66B

Figure 2: The elements of Section 66B

  • The cyber counterpart of receiving stolen property. It mirrors the classic offence (now s.317 BNS) for the digital economy: the market for stolen goods is what makes theft pay, so the receiver is punished alongside the thief.
  • Stolen mobile phones. The commonest application: buying a phone far below market price with the IMEI tampered or the seller unable to show ownership. Receiving or retaining are both punished, so keeping the device after learning the truth is enough.
  • Knowledge or reason to believe. Actual knowledge is not required; circumstances that would make a reasonable person believe the device was stolen, throwaway price, defaced identifiers, shady channel, supply the mental element, while a genuine bona fide purchaser lacks it.
  • Stolen data? The section speaks of a stolen computer resource, and 'computer resource' includes data; where data copied without permission can be called 'stolen' is debated, and prosecutors usually pair s.66B with ss.43(b) and 66 to avoid the definitional fight.

3. Sections 66C and 66D: The Fraud Pair

Sections 66C and 66D, Information Technology Act, 2000

66C. Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.

66D. Whoever, by means for any communication device or computer resource cheats by personation, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupees.

  • Identity theft (s.66C). The offence is the fraudulent or dishonest use of another's electronic signature, password or any other unique identification feature. 'Unique identification feature' is open-ended: OTPs, PINs, biometric templates, Aadhaar numbers, card credentials, account handles, digital signature tokens.
  • Cheating by personation (s.66D). Cheating by personation (defined through ss.318 and 319 BNS: cheating by pretending to be some other person, real or imaginary) committed through a communication device or computer resource. The deception and the inducement are the core.
  • Section 66C vs Section 66D. 66C punishes taking someone's identity credentials and using them, whether or not anyone is deceived; 66D punishes deceiving a victim by wearing a false identity, whether or not any credential was stolen. A phishing fraud typically involves both: 66D against the victim who was deceived, 66C for the credentials then used.

Identity theft and personation compared

Figure 3: Identity theft and personation compared

Today's fraud patterns mapped to the sections

Figure 4: Today's fraud patterns mapped to the sections

  • Phishing and online banking fraud. The fake mail or page personates the bank (66D); harvested credentials are then used (66C); the transfer out of the account is cheating and, through the computer, ss.43 and 66. Umashankar and Poona Auto Ancillaries add the civil claim against the negligent bank (Topics 53, 55)
  • OTP and UPI fraud. The caller who talks a victim into reading out an OTP or approving a collect request personates authority (66D) and then uses the victim's unique feature (66C); 'accidental transfer' and screen-sharing scams run the same way.
  • SIM-swap fraud. The fraudster personates the subscriber to obtain a duplicate SIM (66D); every OTP that follows is identity theft (66C); the account raids complete under ss.43, 66 and BNS cheating.
  • Aadhaar-related identity theft. Using another's Aadhaar number or biometric data is squarely 66C, and the Aadhaar Act, 2016 adds its own offences of impersonation and unauthorised use (ss.34 to 38)
  • Business email compromise. A compromised or lookalike corporate mailbox instructs staff to pay: 66C for the mailbox credentials, 66D for the personation, s.43(a) and s.66 for the intrusion, and BNS cheating for the payment.

4. Section 66E: Violation of Privacy

Section 66E, Information Technology Act, 2000 (substance)

Whoever, intentionally or knowingly captures, publishes or transmits the image of a private area of any person without his or her consent, under circumstances violating the privacy of that person, shall be punished with imprisonment which may extend to three years or with fine not exceeding two lakh rupees, or with both. The Explanation defines 'private area' as the naked or undergarment clad genitals, pubic area, buttocks or female breast, and 'under circumstances violating privacy' as circumstances in which a person can have a reasonable expectation that he or she could disrobe in privacy without being concerned that an image was being captured, or that any part of his or her private area would not be visible to the public, regardless of whether the person is in a public or private place.

The elements of Section 66E

Figure 5: The elements of Section 66E

  • Three separate acts. Capturing, publishing and transmitting are each an offence, so the photographer, the uploader and the forwarder are all within reach.
  • Consent. Consent must cover the act charged: consent to being photographed is not consent to publication, and consent to intimacy is never consent to capture. Sharing images once given in confidence is the classic 66E-plus-67 fact pattern.
  • Reasonable expectation of privacy. The statutory test, and it travels with the person, not the place: a trial room, a hostel bathroom or a crowd photo taken up-skirt all qualify, because the private area was reasonably expected to be unseen even in public.
  • Voyeuristic images. Hidden cameras in changing rooms and washrooms, drone or phone captures and their circulation are the section's home ground, with s.77 BNS voyeurism alongside where the victim is a woman.

Section 66E against BNS voyeurism and Section 67A

Figure 6: Section 66E against BNS voyeurism and Section 67A

5. Section 66F: Cyber Terrorism

The two limbs of Section 66F

Figure 7: The two limbs of Section 66F

  • Threat to unity, integrity, security or sovereignty; striking terror. Limb A opens with the terrorist intent, borrowed from anti-terror law: intent to threaten the nation or to strike terror in the people or any section of them.
  • The means. The intent must work through computer conduct: denial of access, unauthorised access or exceeding authorised access, or introducing a computer contaminant.
  • The consequences. The conduct must cause or be likely to cause death or injuries, damage to or destruction of property, disruption of supplies or services essential to the life of the community, or adversely affect the critical information infrastructure specified under Section 70. An attack crippling power grids, hospital networks or payment systems is the paradigm.
  • Unauthorised access to restricted information. Limb B is cyber espionage: knowingly penetrating a computer resource and obtaining access to information restricted for reasons of the security of the State or foreign relations, with reason to believe it may be used to injure the listed national interests or advantage a foreign nation or group.
  • Punishment. Imprisonment which may extend to imprisonment for life: the harshest sentence in the Act, cognizable and non-bailable, triable by the Court of Session.
  • Cyber attack on government infrastructure. Charging practice stacks s.66F with s.70 (protected systems), s.43 and s.66, and, for the organisation behind it, the UAPA or s.113 BNS.

Where cyber terrorism stands apart

Figure 8: Where cyber terrorism stands apart

⚠ Exam trap

Two precision points. First, under s.66F(1)(A) the intent, the computer means and the grave consequence must all be present; a defacement with a political slogan but no such consequence is s.66, not cyber terrorism. Secondly, keep the fraud pair straight: s.66C needs no cheating and s.66D needs no stolen credential, which is why one phishing episode is usually charged under both.

6. Quick Revision and Memory Aids

  • 'Receiver, thief, cheat, peeper, terrorist'. 66B, 66C, 66D, 66E, 66F.
  • 'B for buying stolen, C for credentials, D for deception'. The commonly confused trio.
  • '66C takes the key, 66D wears the mask'. Identity theft vs personation.
  • 'Capture, publish, transmit; consent to each'. Section 66E.
  • 'Intent, means, consequence: all three or no 66F'. Cyber terrorism, limb A.
  • 'Three years mostly; life for terror'. The punishment ladder.

7. Frequently Asked Questions

What is the difference between Section 66C and Section 66D?

Section 66C punishes the fraudulent or dishonest use of another person's electronic signature, password or unique identification feature; nobody need be deceived. Section 66D punishes cheating by personation through a communication device or computer resource; the essence is deception of a victim. A phishing fraud commonly attracts both: 66D for the false front, 66C for the use of the harvested credentials.

What must be proved for cyber terrorism under Section 66F?

Under the first limb: the intent to threaten India's unity, integrity, security or sovereignty or to strike terror; conduct in the form of denial of access, unauthorised access or introduction of a contaminant; and actual or likely death, injury, property damage, disruption of essential supplies or an adverse effect on critical information infrastructure. The second limb covers knowing unauthorised access to information restricted for State security or foreign relations, with reason to believe it may injure national interests. Punishment may extend to life imprisonment.

8. Related Topics

  • Topic 58: Section 66. The general offence beside the specialists.
  • Topic 61: Sections 67 to 67B. The obscenity and sexual content offences.