Cyber Crime Classification: IIBF Exam Guide for Bankers
Cyber crime classification is the first analytical move in every IIBF Prevention of Cyber Crime question: before you can pick a control, a statutory section or a reporting channel, you must decide what role the computer resource actually played. Indian practice sorts an incident three ways — the computer as target, as tool, or as store of evidence — and then applies a second cut by victim and by statute. Sort correctly and the applicable section, the escalation clock and the customer-remediation route all fall out on their own. Sort wrongly and you file the wrong complaint with the wrong agency.
🧩 The Three-Way Test Behind the Classification
Investigators and question-setters both begin from the same question: what did the machine do? Everything downstream — section, punishment, forum, evidence strategy — follows from that answer.
- Computer as target: the system, network or data is itself the victim. Unauthorised access to a core banking database, exfiltration of customer records, denial-of-service against an internet banking gateway, deployment of malware. These are the offences the Information Technology Act, 2000 was drafted for, and they have no clean pre-digital equivalent.
- Computer as tool: the machine is only the weapon used to commit a conventional crime — cheating, forgery, criminal breach of trust, extortion. The substantive offence still lives in general criminal law; the IT Act adds a technology-specific overlay on top of it.
- Computer as store or incidental object: the device was neither attacked nor used to attack, but holds the proof — a seized laptop carrying forged sanction notes, a phone carrying the conspiracy chat. Here the contest is about the admissibility of electronic records, not about the offence itself.
A single banking fraud usually occupies more than one box at once. A spoofed e-mail that induces a relationship manager to release a payment is the computer as tool for the cheating, the computer as target for the mailbox compromise, and the computer as evidence store when the mail server logs are pulled. The chapter on cyber crime methods walks through each of those layers, while the notes on computer hackers explain why motive changes the answer.
💡 Exam Tip: When a stem mixes several acts, classify by the act that caused the loss, not by the act that came first in the narrative. The unauthorised access may be the opening move, but if the money moved through a cheating-by-personation step, that is the offence the question is testing.
📊 Mapping Each Class to Its Statute
The reason classification matters commercially, not just academically, is that each box lands in a different legal regime with a different remedy, a different burden of proof and a different limitation period. The table below is the version worth memorising for the paper.
| Class | Role of the computer | Typical banking case | Main statutory anchor | Criminal offence? |
|---|---|---|---|---|
| Computer as target | System or data is the victim | Unauthorised access to a core banking database | IT Act s. 43 (civil) read with s. 66 | ✅ under s. 66 |
| Computer as tool | Device is the weapon | Cheating by personation on a net-banking channel | IT Act s. 66D plus cheating under the BNS, 2023 | ✅ |
| Computer as evidence store | Device only holds proof | Seized laptop containing forged sanction notes | Forgery under the BNS, plus the electronic-records certificate regime that replaced s. 65B of the Indian Evidence Act, 1872 | ✅ for the underlying offence |
| Security-practice failure | No criminal act by the institution | Negligent handling of sensitive personal data by a body corporate | IT Act s. 43A | ❌ compensation only |
Note the fourth row carefully, because candidates lose marks on it every cycle. A bank that fails to maintain reasonable security practices and thereby causes wrongful loss is exposed to a claim for compensation, not to prosecution. That is a civil proceeding before the adjudicating officer, and it sits alongside — never instead of — the criminal case against the actual fraudster. Our companion piece on computer insecurity threats in banking takes the control-failure side of that story further.

⚖️ How the IT Act, 2000 Cuts the Same Conduct
The IT Act does not use the words target, tool and store. It uses a civil chapter and a penal chapter, and mature exam answers show that you know which is which.
On the civil side, section 43 creates liability to pay damages for acts such as accessing, downloading, introducing a contaminant, damaging, disrupting or manipulating a computer resource without permission. Section 43A extends the same logic to a body corporate that handles sensitive personal data negligently. Claims of this type go to an adjudicating officer under section 46.
On the penal side, section 65 punishes tampering with computer source documents; section 66 converts the section 43 acts into an offence when done dishonestly or fraudulently; section 66C covers identity theft through another person's electronic signature or unique identification feature; section 66D covers cheating by personation using a computer resource — the workhorse provision in almost every digital banking fraud charge sheet; section 66F covers cyber terrorism. Sections 72 and 72A deal with breach of confidentiality and disclosure of information in breach of a lawful contract.
Two supporting provisions repay memorisation. Section 70B designates CERT-In as the national nodal agency for incident response, which is what makes its directions binding rather than advisory. Section 79 grants conditional safe harbour to intermediaries, which is why a payment aggregator's exposure differs from the bank's. The chapter on cyber laws in India sets out the full architecture, and the primary text is available on India Code.
⚠️ Common Mistake: Section 66A was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India (2015). It was never repealed by Parliament and it is not part of any amendment question — any option that treats it as live law is wrong.
🏦 The Second Cut: Who the Victim Is
The role-of-the-machine test tells you which section applies. A victim-based classification tells you which department in the bank owns the response, and IIBF papers test the distinction more often than candidates expect.
- Against an individual: account takeover, identity theft, obscene or harassing content, privacy violations. The branch and the customer-service function lead; remediation runs through the bank's grievance machinery and then the RBI Ombudsman.
- Against property: fraudulent electronic funds transfer, cloning of instruments, intellectual property theft, misuse of trade secrets. Fraud risk management leads, and recovery depends on how fast the beneficiary account is frozen.
- Against the organisation: ransomware, data breaches, insider abuse of privileged access, sabotage of the switch. Information security and business continuity lead, and the reporting obligations are the heaviest.
- Against the State or society: cyber terrorism, terror financing through mule networks, circulation of counterfeit instruments at scale. Compliance and the principal officer under the anti-money-laundering framework lead, and the reporting goes well beyond the banking regulator.
The victim test also decides who can lawfully complain. A customer whose account was drained is the aggrieved person for the transaction, but the bank is the aggrieved person for the intrusion into its systems, and the two complaints can proceed in parallel. The material on channels of cyber crimes maps each victim class to the delivery route the fraudster used, which is the fastest way to line the same grid up against attacker motive and opportunity.

🛡️ Why the Classification Decides Your Reporting Clock
This is where classification stops being theory. Each class triggers a different obligation, and the deadlines do not come from a single source — a point candidates routinely get wrong.
- CERT-In: its April 2022 directions under section 70B require notified categories of cyber security incident to be reported within six hours of noticing them. The trigger is the incident being on the notified list, not the size of the loss.
- Reserve Bank of India: the RBI's 2016 cyber security framework circular sets the supervisory expectation of reporting unusual incidents within roughly two to six hours. The Master Direction on IT Governance, Risk, Controls and Assurance Practices issued in 2023 imposes no fixed hour limit of its own, so never attribute the six-hour rule to it.
- Law enforcement: a criminal complaint is filed with the police cyber cell or through the national portal, and the golden hour for freezing funds is the first sixty minutes. Our walkthrough of the national cyber crime reporting portal covers the workflow end to end.
- Ombudsman: if the customer is dissatisfied, RB-IOS 2026 — which replaced the 2021 scheme on 1 July 2026 — gives a window of 90 days from the bank's reply, an award ceiling of Rs 30 lakh and a separate cap of Rs 3 lakh for consequential loss such as time, effort and harassment.
The criminal characterisation itself has moved too: the Bharatiya Nyaya Sanhita replaced the Indian Penal Code from 1 July 2024, so the cheating and forgery limbs of any computer-as-tool case now sit in new sections. Our explainer on Cyber Crime under BNS 2023 maps the old numbering onto the new. For the supervisory circulars themselves, go to the source at rbi.org.in rather than to a coaching handout.

🧠 Practice MCQs: Cyber Crime Classification
Q1. A fraudster uses a customer's harvested credentials on a bank's internet banking portal to impersonate her and transfer funds. Under the three-way test this is best described as: (a) computer as target (b) computer as tool (c) computer as evidence store (d) computer as incidental object
Answer: (b) — the portal was the weapon used to commit a conventional cheating offence, so the computer functioned as the tool.
Q2. Which provision of the Information Technology Act, 2000 makes a body corporate liable to pay compensation for negligence in implementing reasonable security practices for sensitive personal data? (a) section 43A (b) section 65 (c) section 66C (d) section 72A
Answer: (a) — section 43A creates civil liability to compensate; section 72A punishes disclosure of information in breach of a lawful contract, which is a different situation.
Q3. Section 66A of the Information Technology Act, 2000 is no longer enforceable because: (a) it was omitted by the IT (Amendment) Act, 2008 (b) it was repealed by the Bharatiya Nyaya Sanhita, 2023 (c) it was superseded by the DPDP Act, 2023 (d) it was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015)
Answer: (d) — the Supreme Court held it unconstitutional in 2015; it was never repealed by Parliament, which is why it still appears in bare Act reprints.
Q4. What determines whether an incident must be reported to CERT-In within six hours? (a) whether the customer suffered a loss (b) whether the amount exceeds Rs 1 crore (c) whether the incident falls in CERT-In's notified list of reportable cyber security incidents (d) whether the accused has been identified
Answer: (c) — the six-hour clock is triggered by the incident type appearing in the notified list, not by the value of the loss.
Q5. Under RB-IOS 2026, the maximum compensation an Ombudsman may award for consequential loss such as time lost, expense incurred and harassment is: (a) Rs 1 lakh (b) Rs 5 lakh (c) Rs 20 lakh (d) Rs 3 lakh
Answer: (d) — RB-IOS 2026 raised the consequential-loss cap to Rs 3 lakh, separate from the overall award ceiling of Rs 30 lakh.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
What are the three main categories used in cyber crime classification?
Computer as target, where the system or data is the victim; computer as tool, where the machine is used to commit a conventional offence such as cheating or forgery; and computer as store of evidence, where the device merely holds proof of a crime committed elsewhere.
Does the Information Technology Act, 2000 still apply after the BNS, 2023?
Yes. The Bharatiya Nyaya Sanhita replaced the Indian Penal Code, not the IT Act. Technology-specific offences such as identity theft and cheating by personation using a computer resource continue under the IT Act, and the two statutes are charged together in most banking fraud cases.
Is every cyber incident at a bank also a cyber crime?
No. An incident is a security event; an offence requires the ingredients of a statutory provision, usually including a dishonest or fraudulent intent. A misconfiguration that exposes data is a reportable incident and possibly a compensation claim under section 43A, but it is not by itself a criminal offence.
Who decides a compensation claim arising from a data security failure?
The adjudicating officer appointed under section 46 of the IT Act, 2000, with an appeal route to the Telecommunications Dispute Settlement and Appellate Tribunal. The criminal case against the fraudster runs separately before the ordinary criminal courts.
🚀 Key Takeaways and Next Steps
Classify by the role of the machine first, by the victim second, and only then reach for a section number. That sequence turns a messy fraud narrative into a defensible file note and an answer the examiner can mark. Keep the reporting clocks separate in your head — CERT-In's six hours, the RBI's supervisory expectation from 2016, and the 90-day Ombudsman window under RB-IOS 2026 — because the paper rewards candidates who do not blend them into one number.
Build the same recall discipline you would use for a treasury rule such as the HTM portfolio sale limit: one table, one trigger, one consequence. Work through more articles in the Prevention of Cyber Crime tag hub, then test yourself with a full chapter-wise paper on IIBF mock tests.
Prefer revising from a printed book?
Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.
132 pages · 225 MCQs
Learning Sessions · Ashish Sir
188 pages · 435 MCQs
Learning Sessions · Ashish Sir
117 pages · 236 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
118 pages · 299 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 255 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
334 pages · 936 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 344 MCQs
Learning Sessions · Ashish Sir
107 pages · 240 MCQs
Learning Sessions · Ashish Sir
90 pages · 150 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
131 pages · 672 MCQs
Learning Sessions · Ashish Sir
221 pages · 831 MCQs
Learning Sessions · Ashish Sir
128 pages · 524 MCQs
Learning Sessions · Ashish Sir
107 pages · 445 MCQs
Learning Sessions · Ashish Sir
148 pages · 478 MCQs
Learning Sessions · Ashish Sir
151 pages · 465 MCQs
Learning Sessions · Ashish Sir
148 pages · 375 MCQs
Learning Sessions · Ashish Sir
216 pages · 895 MCQs
Learning Sessions · Ashish Sir
109 pages · 300 MCQs
Learning Sessions · Ashish Sir
104 pages · 360 MCQs
Learning Sessions · Ashish Sir
82 pages · 297 MCQs
Learning Sessions · Ashish Sir
151 pages · 600 MCQs
Learning Sessions · Ashish Sir
98 pages · 282 MCQs
Learning Sessions · Ashish Sir
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.