Cyber Crime Classification: IIBF Exam Guide for Bankers

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 27 August 2026 · Updated 10 Oct 2026 · 12 min read · 44 views
Cyber Crime Classification: IIBF Exam Guide for Bankers

Cyber crime classification is the first analytical move in every IIBF Prevention of Cyber Crime question: before you can pick a control, a statutory section or a reporting channel, you must decide what role the computer resource actually played. Indian practice sorts an incident three ways — the computer as target, as tool, or as store of evidence — and then applies a second cut by victim and by statute. Sort correctly and the applicable section, the escalation clock and the customer-remediation route all fall out on their own. Sort wrongly and you file the wrong complaint with the wrong agency.

🧩 The Three-Way Test Behind the Classification

Investigators and question-setters both begin from the same question: what did the machine do? Everything downstream — section, punishment, forum, evidence strategy — follows from that answer.

  • Computer as target: the system, network or data is itself the victim. Unauthorised access to a core banking database, exfiltration of customer records, denial-of-service against an internet banking gateway, deployment of malware. These are the offences the Information Technology Act, 2000 was drafted for, and they have no clean pre-digital equivalent.
  • Computer as tool: the machine is only the weapon used to commit a conventional crime — cheating, forgery, criminal breach of trust, extortion. The substantive offence still lives in general criminal law; the IT Act adds a technology-specific overlay on top of it.
  • Computer as store or incidental object: the device was neither attacked nor used to attack, but holds the proof — a seized laptop carrying forged sanction notes, a phone carrying the conspiracy chat. Here the contest is about the admissibility of electronic records, not about the offence itself.

A single banking fraud usually occupies more than one box at once. A spoofed e-mail that induces a relationship manager to release a payment is the computer as tool for the cheating, the computer as target for the mailbox compromise, and the computer as evidence store when the mail server logs are pulled. The chapter on cyber crime methods walks through each of those layers, while the notes on computer hackers explain why motive changes the answer.

💡 Exam Tip: When a stem mixes several acts, classify by the act that caused the loss, not by the act that came first in the narrative. The unauthorised access may be the opening move, but if the money moved through a cheating-by-personation step, that is the offence the question is testing.

📊 Mapping Each Class to Its Statute

The reason classification matters commercially, not just academically, is that each box lands in a different legal regime with a different remedy, a different burden of proof and a different limitation period. The table below is the version worth memorising for the paper.

ClassRole of the computerTypical banking caseMain statutory anchorCriminal offence?
Computer as targetSystem or data is the victimUnauthorised access to a core banking databaseIT Act s. 43 (civil) read with s. 66✅ under s. 66
Computer as toolDevice is the weaponCheating by personation on a net-banking channelIT Act s. 66D plus cheating under the BNS, 2023✅
Computer as evidence storeDevice only holds proofSeized laptop containing forged sanction notesForgery under the BNS, plus the electronic-records certificate regime that replaced s. 65B of the Indian Evidence Act, 1872✅ for the underlying offence
Security-practice failureNo criminal act by the institutionNegligent handling of sensitive personal data by a body corporateIT Act s. 43A❌ compensation only

Note the fourth row carefully, because candidates lose marks on it every cycle. A bank that fails to maintain reasonable security practices and thereby causes wrongful loss is exposed to a claim for compensation, not to prosecution. That is a civil proceeding before the adjudicating officer, and it sits alongside — never instead of — the criminal case against the actual fraudster. Our companion piece on computer insecurity threats in banking takes the control-failure side of that story further.

Key Concepts — Prevention of Cyber Crime
Key Concepts — Prevention of Cyber Crime

⚖️ How the IT Act, 2000 Cuts the Same Conduct

The IT Act does not use the words target, tool and store. It uses a civil chapter and a penal chapter, and mature exam answers show that you know which is which.

On the civil side, section 43 creates liability to pay damages for acts such as accessing, downloading, introducing a contaminant, damaging, disrupting or manipulating a computer resource without permission. Section 43A extends the same logic to a body corporate that handles sensitive personal data negligently. Claims of this type go to an adjudicating officer under section 46.

On the penal side, section 65 punishes tampering with computer source documents; section 66 converts the section 43 acts into an offence when done dishonestly or fraudulently; section 66C covers identity theft through another person's electronic signature or unique identification feature; section 66D covers cheating by personation using a computer resource — the workhorse provision in almost every digital banking fraud charge sheet; section 66F covers cyber terrorism. Sections 72 and 72A deal with breach of confidentiality and disclosure of information in breach of a lawful contract.

Two supporting provisions repay memorisation. Section 70B designates CERT-In as the national nodal agency for incident response, which is what makes its directions binding rather than advisory. Section 79 grants conditional safe harbour to intermediaries, which is why a payment aggregator's exposure differs from the bank's. The chapter on cyber laws in India sets out the full architecture, and the primary text is available on India Code.

⚠️ Common Mistake: Section 66A was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India (2015). It was never repealed by Parliament and it is not part of any amendment question — any option that treats it as live law is wrong.

🏦 The Second Cut: Who the Victim Is

The role-of-the-machine test tells you which section applies. A victim-based classification tells you which department in the bank owns the response, and IIBF papers test the distinction more often than candidates expect.

  • Against an individual: account takeover, identity theft, obscene or harassing content, privacy violations. The branch and the customer-service function lead; remediation runs through the bank's grievance machinery and then the RBI Ombudsman.
  • Against property: fraudulent electronic funds transfer, cloning of instruments, intellectual property theft, misuse of trade secrets. Fraud risk management leads, and recovery depends on how fast the beneficiary account is frozen.
  • Against the organisation: ransomware, data breaches, insider abuse of privileged access, sabotage of the switch. Information security and business continuity lead, and the reporting obligations are the heaviest.
  • Against the State or society: cyber terrorism, terror financing through mule networks, circulation of counterfeit instruments at scale. Compliance and the principal officer under the anti-money-laundering framework lead, and the reporting goes well beyond the banking regulator.

The victim test also decides who can lawfully complain. A customer whose account was drained is the aggrieved person for the transaction, but the bank is the aggrieved person for the intrusion into its systems, and the two complaints can proceed in parallel. The material on channels of cyber crimes maps each victim class to the delivery route the fraudster used, which is the fastest way to line the same grid up against attacker motive and opportunity.

Process & Framework — Prevention of Cyber Crime
Process & Framework — Prevention of Cyber Crime

🛡️ Why the Classification Decides Your Reporting Clock

This is where classification stops being theory. Each class triggers a different obligation, and the deadlines do not come from a single source — a point candidates routinely get wrong.

  1. CERT-In: its April 2022 directions under section 70B require notified categories of cyber security incident to be reported within six hours of noticing them. The trigger is the incident being on the notified list, not the size of the loss.
  2. Reserve Bank of India: the RBI's 2016 cyber security framework circular sets the supervisory expectation of reporting unusual incidents within roughly two to six hours. The Master Direction on IT Governance, Risk, Controls and Assurance Practices issued in 2023 imposes no fixed hour limit of its own, so never attribute the six-hour rule to it.
  3. Law enforcement: a criminal complaint is filed with the police cyber cell or through the national portal, and the golden hour for freezing funds is the first sixty minutes. Our walkthrough of the national cyber crime reporting portal covers the workflow end to end.
  4. Ombudsman: if the customer is dissatisfied, RB-IOS 2026 — which replaced the 2021 scheme on 1 July 2026 — gives a window of 90 days from the bank's reply, an award ceiling of Rs 30 lakh and a separate cap of Rs 3 lakh for consequential loss such as time, effort and harassment.

The criminal characterisation itself has moved too: the Bharatiya Nyaya Sanhita replaced the Indian Penal Code from 1 July 2024, so the cheating and forgery limbs of any computer-as-tool case now sit in new sections. Our explainer on Cyber Crime under BNS 2023 maps the old numbering onto the new. For the supervisory circulars themselves, go to the source at rbi.org.in rather than to a coaching handout.

In Practice — Prevention of Cyber Crime
In Practice — Prevention of Cyber Crime

🧠 Practice MCQs: Cyber Crime Classification

Q1. A fraudster uses a customer's harvested credentials on a bank's internet banking portal to impersonate her and transfer funds. Under the three-way test this is best described as: (a) computer as target (b) computer as tool (c) computer as evidence store (d) computer as incidental object

Answer: (b) — the portal was the weapon used to commit a conventional cheating offence, so the computer functioned as the tool.

Q2. Which provision of the Information Technology Act, 2000 makes a body corporate liable to pay compensation for negligence in implementing reasonable security practices for sensitive personal data? (a) section 43A (b) section 65 (c) section 66C (d) section 72A

Answer: (a) — section 43A creates civil liability to compensate; section 72A punishes disclosure of information in breach of a lawful contract, which is a different situation.

Q3. Section 66A of the Information Technology Act, 2000 is no longer enforceable because: (a) it was omitted by the IT (Amendment) Act, 2008 (b) it was repealed by the Bharatiya Nyaya Sanhita, 2023 (c) it was superseded by the DPDP Act, 2023 (d) it was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015)

Answer: (d) — the Supreme Court held it unconstitutional in 2015; it was never repealed by Parliament, which is why it still appears in bare Act reprints.

Q4. What determines whether an incident must be reported to CERT-In within six hours? (a) whether the customer suffered a loss (b) whether the amount exceeds Rs 1 crore (c) whether the incident falls in CERT-In's notified list of reportable cyber security incidents (d) whether the accused has been identified

Answer: (c) — the six-hour clock is triggered by the incident type appearing in the notified list, not by the value of the loss.

Q5. Under RB-IOS 2026, the maximum compensation an Ombudsman may award for consequential loss such as time lost, expense incurred and harassment is: (a) Rs 1 lakh (b) Rs 5 lakh (c) Rs 20 lakh (d) Rs 3 lakh

Answer: (d) — RB-IOS 2026 raised the consequential-loss cap to Rs 3 lakh, separate from the overall award ceiling of Rs 30 lakh.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

What are the three main categories used in cyber crime classification?

Computer as target, where the system or data is the victim; computer as tool, where the machine is used to commit a conventional offence such as cheating or forgery; and computer as store of evidence, where the device merely holds proof of a crime committed elsewhere.

Does the Information Technology Act, 2000 still apply after the BNS, 2023?

Yes. The Bharatiya Nyaya Sanhita replaced the Indian Penal Code, not the IT Act. Technology-specific offences such as identity theft and cheating by personation using a computer resource continue under the IT Act, and the two statutes are charged together in most banking fraud cases.

Is every cyber incident at a bank also a cyber crime?

No. An incident is a security event; an offence requires the ingredients of a statutory provision, usually including a dishonest or fraudulent intent. A misconfiguration that exposes data is a reportable incident and possibly a compensation claim under section 43A, but it is not by itself a criminal offence.

Who decides a compensation claim arising from a data security failure?

The adjudicating officer appointed under section 46 of the IT Act, 2000, with an appeal route to the Telecommunications Dispute Settlement and Appellate Tribunal. The criminal case against the fraudster runs separately before the ordinary criminal courts.

🚀 Key Takeaways and Next Steps

Classify by the role of the machine first, by the victim second, and only then reach for a section number. That sequence turns a messy fraud narrative into a defensible file note and an answer the examiner can mark. Keep the reporting clocks separate in your head — CERT-In's six hours, the RBI's supervisory expectation from 2016, and the 90-day Ombudsman window under RB-IOS 2026 — because the paper rewards candidates who do not blend them into one number.

Build the same recall discipline you would use for a treasury rule such as the HTM portfolio sale limit: one table, one trigger, one consequence. Work through more articles in the Prevention of Cyber Crime tag hub, then test yourself with a full chapter-wise paper on IIBF mock tests.

Prefer revising from a printed book?

Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.

All books →
MSME 2026 Edition
Micro, Small and Medium Enterprises (MSME)

132 pages · 225 MCQs

Learning Sessions · Ashish Sir

Micro, Small and Medium Enterprises (MSME) 15 chapters · 225 MCQs ₹1,199₹2,39850% off
CCP 2026 Edition
Certified Credit Professional (CCP)

188 pages · 435 MCQs

Learning Sessions · Ashish Sir

Certified Credit Professional (CCP) 29 chapters · 435 MCQs ₹1,199₹2,39850% off
KYCAML 2026 Edition
KYC, AML and CFT

117 pages · 236 MCQs

Learning Sessions · Ashish Sir

KYC, AML and CFT 16 chapters · 236 MCQs ₹1,199₹2,39850% off
TIRM 2026 Edition
Treasury, Investment and Risk Management (TIRM)

Learning Sessions · Ashish Sir

Treasury, Investment and Risk Management (TIRM) ₹1,199₹2,39850% off
ITSEC 2026 Edition
IT Security

118 pages · 299 MCQs

Learning Sessions · Ashish Sir

IT Security 20 chapters · 299 MCQs ₹1,199₹2,39850% off
RFS 2026 Edition
Risk in Financial Services

Learning Sessions · Ashish Sir

Risk in Financial Services ₹1,199₹2,39850% off
SFB 2026 Edition
Small Finance Banks

Learning Sessions · Ashish Sir

Small Finance Banks ₹1,199₹2,39850% off
TREASURY 2026 Edition
Treasury Management

Learning Sessions · Ashish Sir

Treasury Management ₹1,199₹2,39850% off
NBFC 2026 Edition
Non-Banking Financial Companies (NBFC)

115 pages · 255 MCQs

Learning Sessions · Ashish Sir

Non-Banking Financial Companies (NBFC) 17 chapters · 255 MCQs ₹1,199₹2,39850% off
ITF 2026 Edition
International Trade Finance

Learning Sessions · Ashish Sir

International Trade Finance ₹1,199₹2,39850% off
CAAP 2026 Edition
Certified Accounting and Audit Professional (CAAP)

334 pages · 936 MCQs

Learning Sessions · Ashish Sir

Certified Accounting and Audit Professional (CAAP) 63 chapters · 936 MCQs ₹1,199₹2,39850% off
RM 2026 Edition
Risk Management

Learning Sessions · Ashish Sir

Risk Management ₹1,199₹2,39850% off
FEFI 2026 Edition
Foreign Exchange Facilities for Individuals (FEFI)

115 pages · 344 MCQs

Learning Sessions · Ashish Sir

Foreign Exchange Facilities for Individuals (FEFI) 24 chapters · 344 MCQs ₹1,199₹2,39850% off
IIBF 2026 Edition
Debt Recovery Agents (DRA)

107 pages · 240 MCQs

Learning Sessions · Ashish Sir

Debt Recovery Agents (DRA) 16 chapters · 240 MCQs ₹1,199₹2,39850% off
DIGIBANK 2026 Edition
Digital Banking

90 pages · 150 MCQs

Learning Sessions · Ashish Sir

Digital Banking 10 chapters · 150 MCQs ₹1,199₹2,39850% off
BCP 2026 Edition
Banking Compliance Professional

Learning Sessions · Ashish Sir

Banking Compliance Professional ₹1,199₹2,39850% off
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading