Cyber Crime Types and the IT Act 2000: IIBF Guide 2026

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 04 July 2026 · Updated 18 Aug 2026 · 7 min read · 24 views
Cyber Crime Types and the IT Act 2000: IIBF Guide 2026

Understanding cyber crime types and the legal shield of the IT Act 2000 is essential for every banker preparing for IIBF certification. As digital banking expands, so does the attack surface, and questions on phishing, ransomware, card fraud and the Information Technology Act now feature regularly in IIBF exams. This guide walks through the major categories of cyber crime, the statutory provisions that govern them, the role of CERT-In and the RBI cyber security framework, and the reporting channels every bank employee must know. Master these fundamentals and you will handle both the exam and real-world incident response with confidence.

Major Cyber Crime Types Every Banker Must Recognise

The most frequently examined cyber crime types fall into a handful of recognisable patterns. Phishing is a fraudulent attempt to obtain sensitive data such as passwords, card numbers and OTPs by masquerading as a trustworthy entity, usually through email or fake websites. Vishing is its voice-based cousin, where fraudsters call victims pretending to be bank officials and coax them into revealing credentials or approving transactions. Smishing carries the same trick over SMS. Ransomware is malicious software that encrypts an organisation's files and demands payment for the decryption key, a threat that has crippled banks, hospitals and utilities worldwide.

Card fraud covers skimming at ATMs and POS terminals, card-not-present fraud in online purchases, and the cloning of magnetic-stripe cards. Identity theft, SIM swapping and the growing menace of UPI-based social engineering round out the list. Denial-of-service attacks, malware injection and man-in-the-middle interception are further categories that examiners expect candidates to name. For bankers, the common thread is that most attacks exploit human trust rather than technical weakness, which is why customer awareness is the strongest defence. Recognising these categories quickly, and knowing which controls counter each, is exactly what IIBF wants candidates to demonstrate. A strong grounding here also supports your wider studies for the CAIIB curriculum, where risk and technology modules build on the same concepts.

The IT Act 2000 and Its Key Sections

The Information Technology Act, 2000 is India's primary law for electronic commerce, digital signatures and cyber offences, and it was significantly strengthened by the 2008 amendment. Several sections appear repeatedly in IIBF question banks. Section 43 imposes civil liability and compensation for unauthorised access, downloading, or damage to computer systems. Section 66 covers computer-related offences done dishonestly or fraudulently, carrying imprisonment and fine. Section 66C specifically penalises identity theft, while Section 66D targets cheating by personation using computer resources, the provision most relevant to phishing and vishing prosecutions.

Section 65 deals with tampering with computer source documents, and Section 67 addresses the publishing of obscene material in electronic form. Section 69 empowers the government to intercept, monitor or decrypt information in the interest of national security, and Section 70 protects designated protected systems. Section 72 penalises breach of confidentiality and privacy. Together these provisions form the legal backbone against which banks report offences and pursue remedies. Candidates should memorise the mapping between offence and section, because IIBF often frames scenario questions that ask which section applies. You can reinforce this with structured revision using the platform's practice tests and quick-reference notes on the iibf.store blog.

Key Concepts — Prevention of Cyber Crime
Key Concepts — Prevention of Cyber Crime

CERT-In and the RBI Cyber Security Framework

Two institutional pillars govern cyber resilience in Indian banking. The Indian Computer Emergency Response Team, or CERT-In, is the national nodal agency under the Ministry of Electronics and Information Technology for responding to cyber security incidents. Under its 2022 directions, entities including banks must report specified cyber incidents to CERT-In within six hours of noticing them, maintain logs for 180 days, and synchronise system clocks to NPL or NIC time sources. This tight reporting window is a favourite exam point.

The Reserve Bank of India complements this with its Cyber Security Framework for banks, first issued in June 2016. The framework requires every bank to put in place a board-approved cyber security policy distinct from the general IT policy, to implement baseline controls, and to establish a Security Operations Centre for continuous surveillance. Banks must also report unusual cyber incidents to the RBI. The circular emphasises that cyber security preparedness must be commensurate with the bank's risk profile and the complexity of its technology. The RBI has since layered on guidance for cyber resilience of payment systems and digital lending. Reading the primary circular on the RBI website is worthwhile, and you can track further regulatory moves through IIBF news updates.

Reporting Cyber Fraud and Protecting Customers

Knowing how to report an incident is as important as recognising it. Victims of financial cyber fraud should immediately call the National Cyber Crime Helpline number 1930 or file a complaint on the National Cyber Crime Reporting Portal, cybercrime.gov.in. Rapid reporting increases the chance of freezing the fraudulent transaction before funds are withdrawn. Within the bank, staff must escalate suspected fraud to the fraud-monitoring cell and, where thresholds are met, to CERT-In and the RBI as described above.

Customer protection also rests on the RBI's limited-liability circular of July 2017, which caps a customer's liability for unauthorised electronic transactions when the fraud is reported promptly and the loss is not due to customer negligence. Where the deficiency lies with the bank, the customer bears zero liability; where neither party is at fault, liability depends on how quickly the customer notifies the bank. Bankers should counsel customers never to share OTPs, PINs or card details, to verify caller identity independently, and to enable transaction alerts. Two-factor authentication, device binding, and velocity checks on transactions add technical depth to this human-centred advice. Regular awareness campaigns, strong authentication, and prompt reporting together form the practical defence layer that regulators expect every bank to maintain. To lock in these concepts, work through scenario drills and quizzes, and revisit the fundamentals of the CAIIB syllabus so that cyber security sits within your broader risk-management understanding.

Process & Framework — Prevention of Cyber Crime
Process & Framework — Prevention of Cyber Crime

Conclusion: Turn Knowledge Into Exam Success

Cyber crime types and the IT Act 2000 sit at the intersection of law, technology and customer trust, which is why IIBF places such weight on them. If you can distinguish phishing from vishing, map an offence to its IT Act section, recall the six-hour CERT-In reporting rule, and outline the RBI cyber security framework, you are well ahead of the curve. The final step is disciplined practice. Start now with the full IIBF mock test series on iibf.store, apply what you have learned to timed scenario questions, and build the confidence to clear your certification and protect the customers who depend on you.

What is the difference between phishing and vishing?

Phishing uses fraudulent emails or fake websites to steal sensitive data, while vishing uses voice calls where the fraudster impersonates a bank official. Both aim to trick victims into revealing credentials or OTPs.

Which IT Act section covers cheating by personation online?

Section 66D of the Information Technology Act, 2000 penalises cheating by personation using a computer resource, making it the key provision for prosecuting phishing and vishing frauds.

Within how many hours must a bank report a cyber incident to CERT-In?

Under the CERT-In 2022 directions, entities including banks must report specified cyber security incidents to CERT-In within six hours of noticing or being notified of them.

What number should a customer call to report cyber fraud in India?

Victims should call the National Cyber Crime Helpline 1930 immediately, or file a complaint on the portal cybercrime.gov.in, to improve the chance of freezing the fraudulent transaction.

In Practice — Prevention of Cyber Crime
In Practice — Prevention of Cyber Crime
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading