Offences and Penalties Under the IT Act 2000: Complete CAIIB IT Guide (2026)
Quick answer: The offences. Penalties under the IT Act 2000 are spread across Sections 43 to 76. Sections 43 to 47 deal with civil penalties and compensation.
While Sections 65 to 74 cover criminal offences like hacking. Identity theft and cyber terrorism. Penalties range from small daily fines to life imprisonment under Section 66F.
This is one of the highest-scoring topics in the CAIIB Information Technology paper.
If you are preparing for the CAIIB Information Technology (IT) paper. This single chapter can quietly decide your result. Examiners love it. The offences and penalties under the IT Act 2000 appear year after year. Often as direct one-mark questions on a specific section and fine.
The problem? Most students mix up the sections. Section 66 vs 66C vs 66F all blur together the night before the exam.
This guide fixes that. We break every important section into plain language. Add a quick-revision table, and show you exactly how to memorise it.
Why the IT Act 2000 Matters for CAIIB Aspirants
Banking runs on technology. Net banking. UPI.
Mobile wallets. KYC. Electronic records.
Digital signatures. Every one of these sits on a legal foundation called the Information Technology Act. 2000.
For a banker, this is not abstract law. When a customer's account is hacked. When a phishing fraud hits.
Or when an employee leaks confidential data. The IT Act decides who is liable and what the punishment is. That is why the CAIIB IT syllabus dedicates real weight to it.
Score well here and you build a cushion for tougher. Calculation-heavy topics in the same paper. Treat this chapter as low-hanging, high-value fruit.
Key Takeaways
- The IT Act 2000 came into force on 17 May 2000. Was amended by the IT (Amendment) Act. 2008.
- Sections 43–47 = civil penalties and compensation. Sections 65–74 = criminal offences.
- The harshest punishment is under Section 66F (cyber terrorism) — imprisonment for life.
- For CAIIB, memorise the section number + the act + the maximum penalty.
- Always confirm exact figures against the latest official IIBF notification before the exam.
What Is the Information Technology Act, 2000?
The Information Technology Act. 2000 was enacted on 17 May 2000 to give legal recognition to electronic transactions. To promote e-commerce in India.
It was later modified by the Information Technology (Amendment) Act. 2008. Which added many of the offence sections (66A to 66F) you will study below.
The main objectives of the Act are:
- Give legal recognition to electronic transactions.
- Give digital signatures legal validity so they can be used for authentication.
- Facilitate the electronic filing of data and information with government agencies.
- Permit the electronic storage of data.
- Recognise the keeping of accounting records in electronic form.
In short, the Act made the digital world legally trustworthy. The offences and penalties section is simply the enforcement arm. It tells you what happens when someone misuses that digital trust.
Offences vs Penalties: Know the Difference First
Students lose easy marks because they confuse two words. Get this clear before anything else.
- Penalties (civil): Found mainly in Sections 43 to 47. These deal with damage and compensation. You pay money to the affected party. There is no jail term for a pure civil penalty.
- Offences (criminal): Found mainly in Sections 65 to 74. These involve dishonest or fraudulent intent and carry imprisonment plus fines.
One word — compensation — usually signals a penalty section. Words like imprisonment, dishonestly or fraudulently signal an offence section. Train your eye to spot these triggers in the question.
Penalties and Compensation Under the IT Act 2000 (Sections 43–47)
These are the civil penalty provisions. They focus on damage to computers and failure to comply with rules.
Section 43 – Damage to Computer or Computer System
Anyone who damages a computer. Computer system. Or computer network without the owner's consent is liable to pay compensation to the affected person. This section is the foundation. Several criminal sections (like 66) refer back to it.
Section 44 – Failure to Furnish Information or Returns
This section penalises non-compliance with reporting duties:
- Failure to furnish a document. Return or report to the Controller of Certifying Authorities. Penalty up to Rs. 1,50,000 per failure.
- Failure to file information. Books or documents within the allotted time — penalty up to Rs. 5,000 per day of delay.
- Failure to maintain books of account or records — penalty up to Rs. 10,000 per day of default.
Memory hook: 1.5 lakh (one-time), 5k/day, 10k/day. Three figures, one section.
Offences Under the IT Act 2000 (Sections 65–74)
Now the heart of the chapter — the criminal offences. Read each one as a pattern: the act → the maximum imprisonment → the maximum fine.
Section 65 – Tampering With Computer Source Documents
Wilful tampering. Concealment. Destruction or alteration of a computer source document is punishable with imprisonment up to 3 years. Or a fine up to Rs. 2,00,000, or both.
Section 66 – Computer-Related Offences (Hacking)
Any person who dishonestly or fraudulently does an act referred to in Section 43 faces imprisonment up to 3 years. Or a fine up to Rs. 5,00,000, or both.
Section 66B – Receiving Stolen Computer Resource
Dishonestly receiving or retaining a stolen computer resource or communication device carries imprisonment up to 3 years. Or a fine up to Rs. 1,00,000, or both.
Section 66C – Identity Theft
Fraudulently using another person's electronic signature. Password or other unique identification feature attracts imprisonment up to 3 years. A fine up to Rs. 1,00,000.
Section 66D – Cheating by Personation (Phishing)
Cheating by impersonation using a computer resource or communication device is punishable with imprisonment up to 3 years. A fine up to Rs. 1,00,000. This is the classic phishing fraud section that bankers must know.
Section 66E – Violation of Privacy
Knowingly publishing or transmitting an image of a person's private area without consent carries imprisonment up to 3 years. Or a fine up to Rs. 2,00,000, or both.
Section 66F – Cyber Terrorism
Using a computer or doing an electronic act with intent to threaten the unity. Integrity, security or sovereignty of India is the gravest offence. It is punishable with imprisonment for life. Remember this as the single most severe penalty in the entire Act.
Section 67 / 67A – Publishing Obscene & Sexually Explicit Material
Section 67 punishes publishing or transmitting obscene material in electronic form. Section 67A deals with sexually explicit content. Carries imprisonment up to 5 years. Rising to 7 years on a second or subsequent conviction. Along with heavier fines.
Section 68 – Failure to Comply With Controller's Directions
If a Certifying Authority or its employee knowingly fails to comply with the Controller's order. The penalty is imprisonment up to 2 years. Or a fine up to Rs. 1,00,000.
Section 69 – Power to Intercept, Monitor or Decrypt
This section empowers the Central or State Government to intercept. Monitor or decrypt information through any computer resource when necessary in the interest of the sovereignty. Defence.
Security of India. Friendly relations with foreign states. Public order, or to prevent a cognizable offence.
Section 70 – Protected System
The government may declare any computer resource affecting Critical Information Infrastructure a protected system by notification in the Official Gazette. Securing or accessing it in violation can attract imprisonment up to 10 years. Along with a fine.
Sections 71 to 74 – Offences Relating to Certificates & Misrepresentation
- Section 71. Misrepresentation: Suppressing facts to obtain a licence or electronic signature certificate. Imprisonment up to 2 years. Or fine up to Rs. 1,00,000, or both.
- Section 72. Breach of Confidentiality. Privacy: Disclosing electronic records or information accessed under the Act without consent. Imprisonment up to 2 years. Or fine up to Rs. 1,00,000, or both.
- Section 73. Publishing False Certificate: Publishing an electronic signature certificate known to be revoked. Suspended or not accepted — imprisonment up to 2 years. Or fine up to Rs. 1,00,000.
- Section 74. Fraudulent Publication: Creating or publishing a certificate for any fraudulent or unlawful purpose. Imprisonment up to 2 years. Or fine up to Rs. 1,00,000.
Sections 75 & 76 – Extra-Territorial Reach & Confiscation
- Section 75: The Act applies to offences committed outside India by any person. Regardless of nationality. If the act involves a computer. Computer system or network located in India.
- Section 76: Any computer. System. Media or accessories used in contravention of the Act are liable to confiscation. If it is proven the resources were not used to commit the offence. Only the defaulting party is acted against.
IT Act 2000 Offences & Penalties: Quick-Revision Table
This is your night-before-exam sheet. Glance, recall, repeat. Always cross-check the latest official IIBF notification for any updated figures.
| Section | Offence / Default | Maximum Penalty |
|---|---|---|
| 43 | Damage to computer / system | Compensation to affected party |
| 44 | Failure to furnish info / returns | Up to Rs. 1,50,000 / 5,000 per day / 10,000 per day |
| 65 | Tampering source documents | 3 yrs and/or up to Rs. 2,00,000 |
| 66 | Hacking (Section 43 with intent) | 3 yrs and/or up to Rs. 5,00,000 |
| 66B | Receiving stolen resource | 3 yrs and/or up to Rs. 1,00,000 |
| 66C | Identity theft | 3 yrs and up to Rs. 1,00,000 |
| 66D | Cheating by personation (phishing) | 3 yrs and up to Rs. 1,00,000 |
| 66E | Violation of privacy | 3 yrs and/or up to Rs. 2,00,000 |
| 66F | Cyber terrorism | Imprisonment for life |
| 67A | Sexually explicit material | 5 yrs (7 yrs on repeat) + fine |
| 70 | Protected system violation | Up to 10 yrs + fine |
| 71–74 | Misrepresentation / breach / false certificate | 2 yrs and/or up to Rs. 1,00,000 |
How to Study Offences and Penalties for CAIIB IT
Reading the sections once is not enough. You need a method that makes the numbers stick. Here is a practical, step-by-step approach.
- Group by punishment, not by number. Cluster all the "3 years" sections (65. 66. 66B–66E) together. All the "2 years" sections (68. 71–74) together, and keep the outliers (66F life, 70 ten years) separate.
- Anchor the extremes. Remember the two anchors first — 66F = life and 70 = 10 years. Everything else is milder.
- Use one-word triggers. Identity = 66C, Impersonation/phishing = 66D, Privacy image = 66E, Terrorism = 66F. Link the keyword to the section.
- Write the table from memory. Close the book and reproduce the quick-revision table. Whatever you miss is your real weak spot.
- Test under pressure. Attempt timed mock tests so recall becomes automatic in the exam hall.
Spend ten focused minutes a day for a week on this chapter. By exam day, the section-to-penalty mapping will feel like second nature. For more structured walkthroughs, explore our free guides.
Common Mistakes Students Make
Avoid these traps. You will outscore most of the room on this topic.
- Confusing penalties with offences. Sections 43–47 are civil (compensation); 65–74 are criminal (imprisonment). Do not mix them.
- Swapping 66C and 66D. 66C is identity theft; 66D is cheating by personation. Different acts, same maximum term.
- Forgetting that 66F is life imprisonment. It is the only section with a life term. Examiners test it often.
- Memorising figures blindly. Fines are amended periodically. Learn the structure. Then confirm exact amounts on the latest official IIBF notification.
- Ignoring Sections 75 and 76. Extra-territorial application and confiscation are easy one-markers that students skip.
Frequently Asked Questions (FAQ)
What are offences and penalties under the IT Act 2000?
They are the legal consequences of misusing computers and electronic data. Penalties (Sections 43–47) are civil and require compensation. While offences (Sections 65–74) are criminal and carry imprisonment with fines.
Which section of the IT Act deals with hacking?
Section 66 deals with hacking and computer-related offences. It applies when an act under Section 43 is done dishonestly or fraudulently. With imprisonment up to 3 years and/or a fine up to Rs. 5,00,000.
What is the punishment for cyber terrorism under the IT Act?
Section 66F covers cyber terrorism. Prescribes the harshest punishment in the Act. Imprisonment for life. It is the section most likely to be asked in CAIIB.
Is the IT Act 2000 important for the CAIIB IT exam?
Yes. Offences and penalties are a recurring. High-yield topic in the CAIIB Information Technology paper. Direct section-and-penalty questions are common. Making it one of the easiest ways to secure marks.
Are the fine amounts in the IT Act 2000 fixed?
No. Fine amounts can be revised through amendments and rules. Learn the section structure for recall. But always verify the exact current figures against the latest official IIBF notification before your exam.
Final Word: Turn This Chapter Into Guaranteed Marks
The offences. Penalties under the IT Act 2000 reward disciplined revision more than raw intelligence. There is no calculation. No interpretation — just clean, structured recall of sections and punishments.
Build the quick-revision table into your daily routine. Anchor the extremes, and practise until the section numbers fire automatically. Do that. And this becomes one of the most reliable scoring chapters in your entire CAIIB IT paper.
You have got this. Stay consistent. Trust the process. And walk into the exam hall knowing this topic cold.
Related Guides
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.


Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading