Trap: Confusing 'CERT-In' (Computer Emergency Response Team — technical cybersecurity, under MeitY) with 'NCIIPC' (National Critical Information Infrastructure Protection Centre — protects critical infrastructure, under NTRO/NSA).
Most confused: The difference between 'cyber crime' (criminal activity using computers — IT Act) and 'cyber terrorism' (use of cyber means to threaten national security — may involve IPC, UAPA, and the IT Act together).
Key anchor: The IT Act 2000 is the primary law. It was amended in 2008 (IT Amendment Act) to add provisions on cyber terrorism (Section 66F), data protection (Section 43A), and intermediary liability (Section 79). The 2008 amendment was a direct response to gaps exposed by the 2000 Act.
Current affairs hook: The proposed Digital India Act (DIA) — which will replace the IT Act 2000; the surge in digital arrest scams; the Pegasus spyware controversy; India's National Cyber Security Strategy (2023); the increased focus on cyber crime in the National Security Council Secretariat.
Mains hinge: Cyber crime questions are best framed around the 'triple challenge' — (a) jurisdictional complexity (cyber crime knows no borders), (b) technological dynamism (laws lag behind technology), and (c) enforcement capacity (police lack cyber skills). Link to the need for international cooperation (Budapest Convention, UN Cyber Crime Convention).
Core Concept
Cyber crime refers to criminal activities committed using computers and the internet. India has witnessed an exponential rise in cyber crimes — from 1.16 lakh cases in 2020 (NCRB) to over 14 lakh complaints in 2024 (as reported by the National Cyber Crime Reporting Portal). The actual number is believed to be much higher due to under-reporting.
Major Types of Cyber Crime in India
Phishing and Social Engineering: Fake emails, SMS (smishing), phone calls (vishing) that trick victims into revealing sensitive data (banking credentials, OTPs). 'Digital arrest' scams — fraudsters impersonate police/CBI and demand 'digital bail' — have become India's most common cyber fraud in 2024-26.
Ransomware: Malware that encrypts data and demands payment for decryption. High-profile attacks: AIIMS Delhi (2022 — 30+ servers compromised), SpiceJet (2022), and various municipal corporations.
Identity Theft and Financial Fraud: Using stolen personal information (Aadhaar, PAN, bank details) for fraudulent loans, credit card transactions, and UPI-related theft. India's UPI ecosystem — while revolutionary — has also created new fraud vectors (UPI screen-sharing scams, QR code scams).
Cyber Stalking and Harassment: Online stalking, revenge porn (Section 67A of IT Act), cyber bullying — especially targeting women and minors. The Supreme Court's 2024 judgment on 'intimate image' sharing strengthened protections.
Data Breaches: Unauthorised access to databases. India is among the top three countries globally for data breaches. Major breaches include Mobikwik (2021 — 3.5 crore user data), COWIN (2023 — allegations), Air India (2021 — 45 lakh passengers).
Cyber Terrorism: Use of cyber attacks to threaten national security. Relatively rare but growing — includes website defacements by Pakistan-based groups and the 2016 'wannacry' impact on India.
Legal Framework
Information Technology Act 2000 (IT Act): India's primary cyber law. Originally enacted for electronic commerce; expanded through the 2008 amendment.
IT Amendment Act 2008: Added key sections — 66F (cyber terrorism), 67A/B (obscene material), 69 (interception), 69A (blocking of websites), 43A (data protection), 79 (safe harbour for intermediaries).
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021: Imposed 'traceability' obligations on social media intermediaries, grievance redressal mechanisms, and content regulation.
Digital Personal Data Protection Act 2023 (DPDP Act): India's first comprehensive data protection law — replaces Section 43A of the IT Act. Establishes rights for 'data principals' and obligations for 'data fiduciaries'.
Proposed Digital India Act (DIA): Will replace the IT Act 2000 — designed to address new categories of cyber crime and emerging technologies (AI, deepfakes, blockchain, non-personal data).
Bharatiya Nyaya Sanhita (BNS) 2023: The new criminal code — includes specific provisions for organised crime and cyber crime, expanding on the IPC's limited cyber coverage.
Institutional Framework
CERT-In (Computer Emergency Response Team — India): Under MeitY. The national nodal agency for cyber security incident response. Issues advisories, coordinates responses, mandates vulnerability disclosure.
National Cyber Crime Reporting Portal (cybercrime.gov.in): Single platform for reporting cyber crimes — linked to the 1930 helpline.
Indian Cyber Crime Coordination Centre (I4C): Under MHA. Coordinates law enforcement agencies on cyber crime — operates the 'Citizen Financial Cyber Fraud Reporting and Management System'.
National Critical Information Infrastructure Protection Centre (NCIIPC): Under NTRO — protects 'Critical Information Infrastructure' (power grids, banking, telecom, defence systems).
State Cyber Cells: Most states have specialised cyber crime police units.
Investigation Challenges
Jurisdictional complexity: Cyber crimes cross state and national borders. Investigation requires coordination between multiple police jurisdictions and international cooperation (MLAT process, mutual legal assistance treaties). India is not a signatory to the Budapest Convention (2001 — the first international treaty on cyber crime).
Digital forensics gap: Most police stations lack basic digital forensics equipment. Only 34 states/UTs have notified 'cyber forensic science laboratories' (as of 2024).
Awareness deficit: Victims often don't report cyber crimes immediately (destroying digital evidence) or fall for scams that could have been avoided with basic awareness.
Legal lag: The IT Act 2000 was written in a pre-smartphone era — cyber crimes involving AI, deepfakes, and cryptocurrency are not adequately covered.
Data retention: Service providers store data in foreign jurisdictions, making access difficult for Indian investigators. The DPDP Act and proposed DIA address this but implementation remains challenging.
Key Facts
Cyber crime complaints in India (2024): >14 lakh (National Cyber Crime Reporting Portal)
IT Act 2000: India's primary cyber law (amended 2008)