🇮🇳 Happy Independence Day — celebrating 78 years of freedom!

Cyber Crime and the IT Act 2000: A Guide for Bankers

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 28 June 2026 · Updated 11 Aug 2026 · 6 min read · 34 views हिन्दी में पढ़ें
Cyber Crime and the IT Act 2000: A Guide for Bankers

As banking moves online, every customer and banker must understand cyber crime and the IT Act to stay safe. A clear grasp of cyber crime and the IT Act 2000 helps you recognise common digital frauds. Know your legal rights and obligations, and respond correctly when an attack strikes. This guide walks through the major categories of cyber crime, the provisions of India's Information Technology Act 2000, and the practical safeguards bankers must apply.

What is cyber crime?

Cyber crime is any criminal activity that uses a computer, network or digital device as the tool, target or location of the offence. In banking, cyber crime and the IT Act are deeply intertwined because financial systems are prime targets for fraudsters seeking money, data or disruption.

Broadly. Cyber crimes fall into three groups: crimes against individuals (identity theft, online harassment), crimes against property (hacking, virus attacks, financial fraud) and crimes against the state or society (cyber terrorism, spreading malware on critical infrastructure). For bankers, the property-related frauds are the most pressing concern.

The rapid growth of UPI, internet banking and mobile wallets has expanded the attack surface enormously. Understanding cyber crime and the IT Act is therefore no longer optional for banking professionals — it is a core competency tested across IIBF certifications. You can check your knowledge on the practice mock tests at iibf.store.

Common cyber crimes in banking

Bankers encounter a recurring set of digital frauds, and recognising them early is the best defence. The most common cyber crimes affecting banking customers include:

  • Phishing — fraudulent emails or messages that trick users into revealing credentials.
  • Vishing and smishing — voice calls and SMS impersonating banks to extract OTPs and PINs.
  • Skimming — capturing card data at ATMs or POS terminals using hidden devices.
  • SIM swap fraud — hijacking a victim's mobile number to intercept OTPs.
  • Malware and ransomware — malicious software that steals data or locks systems for ransom.
  • Identity theft — using stolen personal data to open accounts or take loans.
Common banking cyber crimes including phishing vishing skimming and SIM swap fraud
The most frequent cyber crimes targeting banking customers.

Social engineering underlies many of these — fraudsters exploit human trust rather than purely technical weaknesses. A strong understanding of cyber crime and the IT Act equips bankers to educate customers and spot red flags. For evolving fraud trends, follow IIBF news and updates.

The Information Technology Act 2000

The Information Technology Act, 2000 is India's primary law governing electronic commerce and cyber crime. It gives legal recognition to electronic records and digital signatures and defines penalties for a range of cyber offences — the legal backbone of cyber crime and the IT Act in India.

Key provisions every banker should know include:

SectionOffence / Provision
Section 43Damage to computer systems — civil liability and compensation
Section 66Computer-related offences (hacking) — imprisonment and fine
Section 66CIdentity theft
Section 66DCheating by personation using computer resources
Section 72Breach of confidentiality and privacy
Key sections of the IT Act 2000 covering hacking identity theft and data breach
Important penal sections of the IT Act 2000 for bankers.

The Act was significantly amended in 2008 to add provisions on data protection (Section 43A), cyber terrorism (Section 66F) and intermediary liability. Authoritative incident-response guidance is issued by the official CERT-In, India's national computer emergency response team. Bankers can deepen these topics through the JAIIB course at iibf.store.

Prevention, reporting and the banker's role

Preventing cyber crime requires a layered approach. Banks deploy technical controls such as multi-factor authentication. Encryption, fraud-monitoring engines and transaction limits, while customers must be educated never to share OTPs, PINs or passwords with anyone — including callers claiming to be from the bank.

When fraud occurs, prompt reporting is critical. Victims should immediately call the National Cyber Crime Helpline 1930 and file a complaint on the National Cyber Crime Reporting Portal. While the bank invokes its incident-response plan. RBI's framework also entitles customers to limited liability for unauthorised electronic transactions if they report quickly. Making awareness of cyber crime and the IT Act directly relevant to customer protection.

Cyber fraud prevention and reporting steps including helpline 1930 and limited liability
Prevention and reporting steps for banking cyber fraud.

The banker's role is to stay vigilant, follow internal security protocols, report suspicious activity, and continuously update customer awareness. For more worked examples and case studies, read the explainers on the iibf.store blog.

Digital payment safety and adjudication under the IT Act

Most banking cyber fraud today targets the digital-payments ecosystem, so payment safety deserves special attention. Customers should transact only on official apps and verified websites. Check for HTTPS and the padlock symbol, avoid public Wi-Fi for banking, and never scan unknown QR codes — a frequent trick is to make a victim scan a code that actually authorises a payment rather than receives one.

The legal machinery for redress is also worth knowing. The Information Technology Act 2000 created the office of the Adjudicating Officer (the State IT Secretary) to decide compensation claims up to a prescribed limit. With appeals lying to the appellate tribunal. This gives victims a civil remedy distinct from criminal prosecution under Sections 66 and 66D, and complements the limited-liability protection offered under RBI's customer-protection framework.

Banks, as intermediaries handling sensitive data, must observe reasonable security practices under Section 43A or face liability for negligence. Understanding both the technical safeguards and the remedies available under the law rounds out a banker's command of the subject. Candidates can drill these provisions using the match-the-concept game at iibf.store to fix section numbers in memory.

The regulatory landscape continues to evolve. The Digital Personal Data Protection Act 2023 now sits alongside the IT Act. Tightening obligations on how banks collect, store and process customer data and prescribing penalties for breaches.

RBI's own cyber-security framework for banks mandates board-approved security policies. A Security Operations Centre for larger banks, and prompt incident reporting to the regulator and CERT-In. For a banker.

The takeaway is that cyber-security is now a continuous, layered discipline — combining law, technology, customer education and rapid incident response — rather than a one-time control, and exam questions increasingly reflect that integrated view.

What is phishing?

Phishing is a fraud where attackers send fake emails. Messages or websites pretending to be a trusted bank to trick users into revealing passwords, OTPs or card details. It is one of the most common cyber crimes in banking and relies on social engineering.

Which section of the IT Act covers identity theft?

Section 66C of the Information Technology Act 2000 deals with identity theft — the fraudulent use of another person's electronic signature, password or unique identification. Section 66D covers cheating by personation using computer resources.

What is the national cyber crime helpline number?

Victims of financial cyber fraud in India should immediately call 1930 and file a complaint on the National Cyber Crime Reporting Portal. Quick reporting improves the chances of freezing fraudulent transfers and limits the customer's liability.

What is limited liability for unauthorised transactions?

Under RBI's framework. A customer's liability for unauthorised electronic banking transactions is limited — and can be zero — if the fraud is reported promptly and was not due to customer negligence. This protects customers when they act quickly.

Conclusion: A firm grasp of cyber crime and the IT Act 2000 protects both you and your customers in an increasingly digital banking world. Reinforce these concepts with realistic practice — begin your free cyber security and IT Act mock tests at iibf.store and ace your IIBF exam.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading