Cyber Crime in Banking: IT Act & RBI Framework Guide

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 15 June 2026 · Updated 28 Jul 2026 · 12 min read · 15 views
Cyber Crime in Banking: IT Act & RBI Framework Guide

Cyber crime in banking has become the single most important risk theme for every Indian banker, and for anyone preparing for the IIBF Prevention of Cyber Crime certification it sits at the very heart of the syllabus. Digital banking has transformed how India saves, borrows and pays, but the same connectivity that brings a branch to your phone has dramatically widened the attack surface for fraudsters. Today a single careless OTP can drain a savings account in seconds.

This guide pulls the whole subject together in one place: the common attack types you must recognise, the offences defined under the Information Technology Act 2000, the RBI cyber security framework and CERT-In's role, and the customer-protection rules that decide who bears a fraud loss. Whether you sit the IIBF paper this cycle or simply want to protect your customers better, this is the working knowledge a modern banker cannot do without.

Cyber crime in banking IT Act and RBI framework guide for IIBF aspirants
Cyber crime in banking: how the IT Act 2000 and the RBI framework protect customers.

Key Takeaways

  • Most banking cyber crime attacks the customer through social engineering, not the bank's core systems directly.
  • The Information Technology Act 2000 (strengthened by the IT Amendment Act 2008) is the primary law; Sections 66C and 66D matter most for banking fraud.
  • The RBI Cyber Security Framework (2016) mandates a board-approved policy, a Security Operations Centre and time-bound incident reporting.
  • CERT-In, under MeitY, is the national nodal agency for cyber incident response.
  • Under the RBI customer-protection rules, prompt reporting on helpline 1930 is the strongest shield a customer has.

What Counts as Cyber Crime in Banking?

Cyber crime in banking covers any offence that uses a computer, mobile device or network to defraud a bank, its customers or its systems. In practice the overwhelming majority of cases do not involve hackers breaking encryption. They involve a fraudster persuading a genuine customer to hand over credentials, or hijacking the second authentication factor.

Understanding this distinction is the first thing an examiner wants to see. The technology is only the channel; the real vulnerability is human trust. That is why customer awareness sits alongside firewalls as a core control in every regulatory framework.

Common Types of Cyber Crime in Banking

Examiners love typology questions, so you must be able to name each attack and describe how it works in a sentence. The families below cover the bulk of what appears in both the question paper and the real fraud register.

  • Phishing — fake emails, websites or links that mimic a bank to harvest login credentials and card data.
  • Vishing — voice phishing, where a caller impersonates a bank, RBI or KYC official and pressures the victim into sharing an OTP or PIN.
  • Smishing — the same trick delivered by SMS, often carrying a malicious link or a fake "account blocked" warning.
  • Card skimming and cloning — a hidden device at an ATM or POS terminal copies magnetic-stripe data to create a duplicate card.
  • SIM swap fraud — the criminal obtains a duplicate SIM to intercept OTPs sent to the victim's number.
  • Ransomware and malware — malicious software encrypts a bank's or business's systems and demands payment to restore access.
  • Money mule and malicious APK fraud — stolen funds are routed through unwitting third-party accounts, and fake apps installed outside official stores steal data or hijack sessions.

Spotting these patterns early is what separates a confident banker from a reactive one. You can stress-test your recall of fraud typologies with the topic-wise practice sets on the Prevention of Cyber Crime mock tests, and read the channel-specific deep dive on phishing and vishing red flags before moving on to the law.

Exam tip: When a question describes a fake call demanding an OTP, the channel is vishing and the most likely charging section is 66D. Anchor every scenario to both the attack type and the section.
Common banking cyber crime types including phishing vishing smishing and card skimming
Phishing, vishing, smishing, skimming and SIM swap: the attack types every banker must recognise.

The Information Technology Act 2000 and Key Offences

The Information Technology Act 2000 is the primary law governing cyber crime and electronic commerce in India, and it was substantially strengthened by the IT (Amendment) Act 2008. It gives legal recognition to electronic records and digital signatures, and it defines penalties for a range of computer-related offences that map directly onto banking fraud.

For the exam, your job is to take a fraud scenario and pin it to the correct section. The provisions below come up most often.

Section What it covers Banking relevance
Section 43Civil liability and damages for unauthorised access, downloading or damaging data.Compensation route for data theft and tampering.
Section 43ACompensation where a body corporate fails to protect sensitive personal data.Holds banks accountable for data-security lapses.
Section 66Punishment for computer-related offences done dishonestly or fraudulently, such as hacking.Core hacking and unauthorised-access offence.
Section 66CIdentity theft — misuse of passwords, OTPs, electronic signatures or unique IDs.Account-takeover and OTP-misuse cases.
Section 66DCheating by personation using a computer resource.Directly covers phishing and vishing.
Section 72APenalty for disclosure of information in breach of a lawful contract.Insider and vendor data-leak situations.

The Act also empowers the appointment of adjudicating officers and establishes the appellate framework for cyber disputes. For bankers, Sections 66C and 66D are the workhorses because they speak to the impersonation and identity-theft tactics behind almost every account takeover. Tie this legal layer to the practice questions in the Prevention of Cyber Crime course hub, and study the section-by-section breakdown in our guide to the IT Act 2000 cyber crime sections every IIBF aspirant needs.

RBI Cyber Security Framework and CERT-In

The RBI Cyber Security Framework, issued in June 2016, requires every bank to maintain a board-approved cyber security policy that is distinct from its broader IT policy. It mandates a baseline set of controls, continuous surveillance, and security arrangements scaled to each bank's risk profile and digital footprint.

A central requirement is a Security Operations Centre (SOC) for round-the-clock monitoring and rapid incident response. The framework obliges banks to report cyber incidents to the RBI within a defined window — typically within two to six hours of detection — and to maintain a tested cyber crisis management plan. For the exact reporting timelines applicable in the current cycle, always confirm the latest RBI circular and the relevant IIBF notification.

CERT-In, the Indian Computer Emergency Response Team, operates under the Ministry of Electronics and Information Technology (MeitY) and is the national nodal agency for responding to cyber security incidents. It issues alerts and advisories, and banks must coordinate with it and report incidents in line with its directions.

Other pillars you should be able to list include:

  • Multi-factor authentication for sensitive transactions and privileged access.
  • Network segmentation to contain the blast radius of any breach.
  • Vulnerability assessment and penetration testing (VAPT) on a regular cycle.
  • Vendor and outsourcing risk management, since third parties are a frequent weak link.
  • Customer awareness programmes as a frontline defence against social engineering.

The RBI also supervises banks through dedicated cyber security and IT examination teams. To keep current with evolving directions, pair this section with our RBI and CERT-In cyber security framework exam guide, and browse the full library of Prevention of Cyber Crime guides for circular-driven updates.

Customer Protection and Fraud Reporting Measures

The RBI Customer Protection circular of 2017 limits a customer's financial liability in unauthorised electronic banking transactions, and it is one of the most testable topics in the entire syllabus. The core principle is zero liability: where the loss is due to bank negligence or a system fault, the customer bears nothing, regardless of when they report it.

Zero liability also applies where third-party fraud occurs through no fault of the bank or the customer, provided the customer reports it within three working days of receiving the bank's communication. Limited liability applies when reporting is delayed, with the cap rising as the delay increases. The loss falls entirely on the customer only where it results from their own negligence — such as sharing a PIN or OTP — and even then only until the fraud is reported.

The reporting and redress channels every banker should know are:

  • National Cyber Crime Reporting Portal (cybercrime.gov.in) and the financial-fraud helpline 1930.
  • Bank fraud reporting through registered email, phone banking or the branch, triggering immediate account freezing.
  • RBI Ombudsman scheme for complaints left unresolved after the bank's reply or 30 days.
  • Reversal timelines — banks must credit the disputed amount within ten working days of notification in eligible cases.

Prompt reporting is, quite simply, the most powerful protection a customer has. Reinforce these rules with the regulatory practice questions on the Learning Sessions mock tests, and sharpen quick recall of liability windows with the cyber crime matching game.

A Practical Study Plan for the Cyber Crime Paper

Knowing the syllabus is one thing; retaining it under exam pressure is another. A focused two-week cycle works well for most candidates and keeps the four pillars balanced.

  1. Days 1–3 — Attack types: Learn each fraud family and write a one-line definition from memory. Practise spotting red flags in short scenarios.
  2. Days 4–7 — The IT Act: Drill Sections 43, 43A, 66, 66C, 66D and 72A until you can match any scenario to a section. Re-read the table above daily.
  3. Days 8–10 — RBI framework and CERT-In: Memorise the SOC requirement, the board-approved policy and the reporting chain, then revise the supporting controls.
  4. Days 11–12 — Customer protection: Lock in the zero, limited and full-liability rules and the three-working-day window. These convert into easy marks.
  5. Days 13–14 — Mixed mocks: Sit full-length tests, review every wrong answer, and revisit only your weak typologies and sections.

Active recall beats passive reading every time. Alternate a reading block with a short quiz so each concept is tested the same day you learn it.

Common Mistakes Candidates Make

A handful of avoidable errors cost marks year after year. Watch for these:

  • Confusing 66C with 66D — remember 66C is identity theft, while 66D is cheating by personation. Phishing and vishing are charged primarily under 66D.
  • Mixing up vishing and smishing — vishing is by voice call; smishing is by SMS.
  • Forgetting the reporting window — the customer-protection benefit hinges on the three-working-day rule; missing it changes the liability outcome.
  • Treating the cyber security policy as the IT policy — the RBI requires a separate, board-approved cyber security policy.
  • Quoting outdated figures — reporting timelines and thresholds are revised periodically, so verify the current numbers against the official notification rather than memorising stale ones.

Frequently Asked Questions

What is the difference between phishing and vishing in banking fraud?

Phishing uses fake emails, websites or links to trick customers into entering their credentials. Vishing uses voice calls, where a fraudster impersonates a bank or RBI official to extract OTPs, PINs or card details. Both are forms of social engineering and both are typically prosecuted under Section 66D of the IT Act 2000 for cheating by personation using a computer resource.

Which IT Act 2000 section covers identity theft and OTP misuse?

Section 66C of the IT Act 2000 deals specifically with identity theft, including the fraudulent or dishonest use of another person's password, electronic signature, OTP or unique identification feature. It is frequently charged alongside Section 66D in personation-based banking fraud. For the precise punishment in force, confirm the latest reading of the section, as penalties can be updated by amendment.

What is the role of CERT-In in banking cyber security?

CERT-In is the national nodal agency under the Ministry of Electronics and Information Technology that responds to cyber security incidents, issues alerts and advisories, and coordinates incident handling across sectors. Banks must report cyber incidents in line with CERT-In directions and the RBI framework. Together these ensure timely detection, escalation and remediation of attacks.

What is zero liability for customers in unauthorised banking transactions?

Under the RBI Customer Protection circular of 2017, a customer has zero liability when an unauthorised transaction results from bank negligence or a system fault, or from third-party fraud reported within three working days of the bank's communication. Beyond that window, liability becomes limited and rises with the delay. Reporting promptly on helpline 1930 or to the bank is therefore essential.

How quickly must banks reverse a disputed unauthorised transaction?

In eligible cases under the customer-protection rules, banks are required to credit the disputed amount to the customer's account within ten working days of being notified, without waiting for the investigation to conclude. This shadow credit protects the customer's funds while the matter is examined. Always confirm the exact eligibility conditions against the latest RBI circular.

Is the IT Act 2000 enough to prosecute all banking cyber crimes?

The IT Act 2000 is the primary law, but banking cyber crimes are often prosecuted alongside provisions of the general criminal law dealing with cheating and forgery. The IT Act supplies the computer-specific offences, while broader statutes cover the underlying fraud. For exam purposes, focus on mapping each scenario to the correct IT Act section first.

Conclusion

Cyber crime in banking is a moving target, but the defence rests on four solid pillars: recognising the attack types, applying the right sections of the IT Act 2000, following the RBI cyber security framework with CERT-In coordination, and enforcing the customer-protection rules. Master these and you are ready both for the IIBF question paper and for the real-world job of keeping customers safe. Start a full-length attempt on the Prevention of Cyber Crime mock tests today, and confirm every time-sensitive detail against the official IIBF website before your exam.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading