Cyber Crime in Banking: IT Act, CERT-In & IIBF 2026 Guide
Cyber crime in banking has moved from a niche IT concern to the single biggest operational and reputational threat facing Indian banks - and the IIBF Prevention of Cyber Crime paper tests it from both a legal and a practical angle. As banking shifts almost entirely to mobile apps, UPI rails and net banking, every transaction is also a potential attack surface. This guide walks you through the major attack types, the governing law, the regulatory framework and the day-to-day controls that examiners expect a competent banker to know in detail.
If you have struggled with this chapter, the problem is rarely the difficulty of any single idea. It is that the syllabus blends three different worlds - criminal technique, statutory sections and RBI circulars - and the exam loves to test the joins between them. Once you can map an attack to a section of the IT Act and then to the right reporting obligation, the questions become straightforward.

Key takeaways
- Cyber crime in banking splits into social-engineering frauds (phishing, vishing, smishing) and technical attacks (malware, ransomware, man-in-the-middle, SIM swap, card skimming).
- The Information Technology Act, 2000 is the legal backbone - know Sections 43, 43A, 66, 66C, 66D and 72A and what each one penalises.
- The RBI Cyber Security Framework requires a board-approved policy, a Security Operations Centre and a tested Cyber Crisis Management Plan.
- CERT-In is the national nodal agency for incident response, with strict reporting timelines and log-retention rules.
- The RBI limited liability framework protects customers who report unauthorised transactions promptly - a near-certain exam theme.
What cyber crime in banking really means
For the exam, treat cyber crime as any offence where a computer, network or digital identity is either the target or the tool. In a banking context that ranges from a fraudster tricking a pensioner into sharing an OTP, to an organised gang deploying ransomware that locks a co-operative bank's core system. The common thread is that money, data or trust is stolen through digital means.
Why does this matter so much now? Because the bank's perimeter is no longer a branch with a guard at the door. It is millions of customer devices, third-party payment apps and APIs, any of which can be the weak link. Understanding cyber crime in banking therefore means understanding both the human and the technical paths an attacker can take.
Major types of banking cyber crime
You should be able to define each attack type precisely, because one-mark questions often hinge on a single distinguishing word. Phishing uses fraudulent emails or cloned websites that impersonate a bank to trick customers into revealing credentials. Vishing is its voice equivalent, where a caller posing as a bank official extracts OTPs or card details. Smishing does the same through SMS, often with a malicious link.
These three are social-engineering attacks: they exploit human trust rather than a technical flaw, which is exactly why customer awareness is the strongest single defence. No firewall stops a customer who voluntarily reads out an OTP.
The technical attacks are equally examinable. Malware and ransomware infect systems to steal data or lock files until a ransom is paid. A man-in-the-middle attack secretly intercepts communication between the customer and the bank. SIM swap fraud hijacks a victim's mobile number so the criminal receives the OTPs. Card skimming copies card data at a tampered ATM or point-of-sale terminal, and money mule accounts then move and launder the stolen proceeds.

The Information Technology Act, 2000 - section by section
The legal backbone of India's response to cyber crime is the Information Technology Act, 2000. It gives legal recognition to electronic records and digital signatures, and it creates offences for computer-related wrongdoing. For a banker, a handful of sections do most of the work, and direct one-mark questions on section numbers are common.
Section 43 provides civil liability for unauthorised access, downloading, or damage to a computer system. Section 66 covers computer-related offences such as hacking carried out with dishonest or fraudulent intent. Section 66C deals with identity theft - the fraudulent use of someone's electronic signature, password or unique identification. Section 66D covers cheating by personation using a computer resource, which captures most online impersonation frauds against bank customers.
Two sections are especially important for the bank as an institution. Section 43A requires a body corporate handling sensitive personal data to maintain reasonable security practices and procedures; failing that, it is liable to pay compensation to the affected person. Section 72A penalises the disclosure of information in breach of a lawful contract. The Act also established the Adjudicating Officer and the appellate machinery for resolving cyber disputes.
One forward-looking point worth a line in your notes: the IT Act's data-handling duties are being reinforced by the Digital Personal Data Protection regime, which raises the bar for how banks collect, store and process customer data. For the precise scope and any recent amendments, always confirm against the latest released IIBF notification and the bare Act, since statutory detail can change.
Quick reference: IT Act sections for bankers
| Section | What it covers | Banking relevance |
|---|---|---|
| Section 43 | Unauthorised access, damage or data theft (civil) | Basis for compensation when systems are misused |
| Section 43A | Failure to protect sensitive personal data | Imposes reasonable-security duty on the bank |
| Section 66 | Hacking with dishonest or fraudulent intent | Core criminal offence for system intrusion |
| Section 66C | Identity theft | Stolen passwords, OTPs and credentials |
| Section 66D | Cheating by personation using a computer | Most online impersonation frauds |
| Section 72A | Disclosure of information in breach of contract | Protects customer data shared with the bank |
Reinforce this section-to-offence mapping with the cyber law matching game - active recall on section numbers sticks far better than re-reading. You can also revisit the deeper breakdown in our guide on types of cyber crime in banking and the IT Act 2000.
RBI Cyber Security Framework and CERT-In
On top of the law sits the regulator's rulebook. The Reserve Bank of India has issued a comprehensive Cyber Security Framework that requires every bank to maintain a board-approved cyber security policy that is distinct from its broader IT policy, a Security Operations Centre (SOC) for continuous monitoring, and a tested Cyber Crisis Management Plan (CCMP). Banks are categorised by the size of their digital footprint, with progressively stricter baseline controls expected from larger and more digitally active institutions.
At the national level, the Indian Computer Emergency Response Team (CERT-In) is the nodal agency for responding to cyber security incidents. Under its directions, organisations must report specified cyber incidents within a strict timeline and retain logs for a defined period. Banks additionally report fraud and security incidents to the RBI through its prescribed channels. For the exact timelines and the current categorisation, confirm against the latest released CERT-In direction and RBI circular, as these specifics are periodically updated.
The customer-protection layer is a perennial favourite with examiners. Under the RBI's limited liability framework, a customer who reports an unauthorised electronic transaction promptly bears little or no loss, with the burden of proof shifting to the bank. The growth of the National Cyber Crime Reporting Portal and the 1930 helpline has made it far easier for victims to report quickly and for banks to freeze fraudulent transfers before the money is siphoned away. For the regulator's primary material, see the IIBF website and the official notification. You can also build the wider regulatory picture in our RBI and CERT-In cyber security framework guide.
Prevention, controls and incident response
Preventing cyber crime is a layered exercise, and the syllabus expects you to discuss both technical and human controls. On the technical side, banks deploy multi-factor authentication, encryption of data in transit and at rest, network firewalls, intrusion-detection systems and timely patching of vulnerabilities. Vulnerability Assessment and Penetration Testing (VAPT) is conducted periodically to find weaknesses before attackers do, and access is governed on a least-privilege, need-to-know basis with maker-checker controls for sensitive actions.
Equally vital are the human and procedural controls: continuous staff training, customer-awareness campaigns built around the simple rule that a bank never asks for an OTP or PIN, and a well-rehearsed incident response plan. A complete plan covers five stages in order - detection, containment, eradication, recovery and post-incident review - so that when an attack lands, nobody is improvising. The post-incident review is where lessons feed back into stronger controls.
A simple study plan for this chapter
Spread over a focused week, this sequence works well for most candidates:
- Day 1-2: Learn the attack typologies and their red flags until you can identify any of them from a one-line scenario.
- Day 3: Memorise the IT Act sections using the table above, then test yourself with the matching game.
- Day 4: Study the RBI framework pillars (policy, SOC, CCMP) and the CERT-In reporting duty.
- Day 5: Master the customer limited-liability rule and the role of the 1930 helpline and reporting portal.
- Day 6-7: Attempt full-length timed mocks, review every wrong answer, and re-revise weak areas.
Browse the full set of exam explainers any time on our cyber crime guides hub, and anchor the chapter within its parent paper through the Prevention of Cyber Crime course and its subject page.
Common mistakes candidates make
- Confusing the section numbers. 66C is identity theft and 66D is cheating by personation - mixing these up is the most frequent slip, and the exam tests it directly.
- Treating 43 and 43A as the same. Section 43 is general unauthorised-access liability; 43A is specifically about a body corporate failing to protect sensitive personal data.
- Ignoring reporting timelines. Knowing that CERT-In and RBI reporting exist is not enough - candidates lose marks by not noting that there are defined, strict timelines.
- Overlooking customer liability. Many forget that prompt reporting shifts the burden to the bank, which is one of the most repeated exam points.
- Memorising names, not behaviour. Rote definitions fail in the case study, where you must recognise an attack from how it unfolds.
Frequently asked questions
What is the difference between phishing, vishing and smishing?
All three are social-engineering frauds that aim to steal credentials or OTPs. Phishing uses fraudulent emails or cloned websites, vishing uses voice calls from someone posing as a bank official, and smishing uses SMS messages, usually with a malicious link. The channel differs, but the goal of tricking the customer is identical.
Which IT Act section covers identity theft?
Section 66C of the Information Technology Act, 2000 covers identity theft, such as the fraudulent use of another person's password, electronic signature or unique identifier. The closely related Section 66D covers cheating by personation using a computer resource. Examiners frequently test the distinction between these two sections.
What is CERT-In's role in banking cyber security?
CERT-In is India's national nodal agency for cyber security incident response. It issues advisories and binding directions, and organisations - banks included - must report specified incidents to it within prescribed timelines and retain logs for a defined period. Always verify the exact timelines against the latest CERT-In direction, as they are periodically revised.
What is a customer's liability for an unauthorised electronic transaction?
Under the RBI's limited-liability framework, a customer who reports an unauthorised electronic transaction promptly generally bears little or no loss. The burden of proof then shifts to the bank to show the transaction was authorised. Delay in reporting can, however, increase the customer's share of the loss, so prompt reporting is essential.
What does the RBI Cyber Security Framework require banks to have?
At a minimum, it requires a board-approved cyber security policy that is separate from the general IT policy, a Security Operations Centre for continuous monitoring, and a tested Cyber Crisis Management Plan. The depth of controls scales with the bank's digital footprint, so larger and more digitally active banks face stricter baseline requirements.
How should I study this chapter for the IIBF 2026 exam?
Connect the three layers - attack types, IT Act sections, and the RBI and CERT-In frameworks - rather than learning them in isolation, because the exam tests the links between them. Use a matching game for section recall, then practise with timed scenario-based mocks. Confirm any time-sensitive figures or timelines against the official IIBF notification before the exam.
Conclusion
Cyber crime in banking rewards candidates who can join three layers into one picture: the attack typologies, the IT Act sections, and the RBI and CERT-In frameworks, all underpinned by practical controls and the customer-protection rule. Lock down the section numbers and the reporting obligations precisely, because those are near-certain marks. Do the recall work this week, and the case-study questions will start to feel routine rather than intimidating.
Related Guides
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.