Cyber Crime under BNS 2023: New Legal Framework for Bankers

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 25 August 2026 · Updated 07 Oct 2026 · 9 min read · 38 views
Cyber Crime under BNS 2023: New Legal Framework for Bankers

Bankers preparing for the Prevention of Cyber Crime paper often assume the Information Technology Act, 2000 is the whole legal story. It is not. Cyber Crime under BNS 2023 is now a live examinable area because the Bharatiya Nyaya Sanhita, 2023 — along with the Bharatiya Sakshya Adhiniyam, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023 — replaced the colonial-era Indian Penal Code, Evidence Act and CrPC with effect from 1 July 2024. Every FIR for cheating, forgery, intimidation or electronic fraud registered on or after that date now cites BNS and BSA section numbers, not the old IPC ones candidates memorised for years.

📜 Why BNS, BSA and BNSS Replaced India's Colonial Criminal Code

Three new codes came into force together on 1 July 2024: the Bharatiya Nyaya Sanhita (substantive offences, replacing the IPC 1860), the Bharatiya Nagarik Suraksha Sanhita (procedure, replacing the CrPC 1973), and the Bharatiya Sakshya Adhiniyam (evidence, replacing the Evidence Act 1872). None of the three touches the Information Technology Act, 2000, which remains a separate special law administered independently by the Ministry of Electronics and Information Technology. That distinction matters for the exam: hacking, data theft, identity theft and cyber terrorism are still charged under IT Act sections, while cheating, forgery, criminal intimidation and defamation carried out through a computer, phone or app now fall under BNS provisions instead of the repealed IPC chapters candidates once memorised.

In practice, investigators file cyber-fraud FIRs under a combination of both statutes — the IT Act for the technology-specific offence and the BNS for the underlying deception or threat. A transitional rule also matters: offences registered before 1 July 2024 continue under the old IPC and Evidence Act sections, while anything after that date uses the new numbering. Study material quoting only IPC 420 or Evidence Act Section 65B is now dated.

💡 Exam Tip: Remember the three-code rule of thumb — BNS replaces IPC, BNSS replaces CrPC, BSA replaces the Evidence Act — and that the IT Act, 2000 sits alongside all three untouched.

🎭 Cheating and Cheating by Personation — BNS Sections 318 and 319

The offence bankers encounter most in digital fraud investigations — cheating — has been restructured, not abolished. What was Section 420 of the old IPC is now Section 318(4) of the BNS, covering dishonest inducement to deliver property or to alter a valuable security. Sections 318(1) to 318(3) cover the lighter forms of the same offence, giving investigators graded charging options depending on the harm caused.

A separate provision, Section 319 BNS, deals specifically with cheating by personation — assuming a false identity to deceive a victim. This is directly relevant to fraud typologies bankers study elsewhere: fake bank-official calls, cloned KYC profiles and impersonated customer-care handles are textbook cheating-by-personation patterns, now charged under this dedicated section. Learners revising the Introduction To Cyber Crimes chapter should map every fraud pattern to whichever section fits.

For the exam, the practical distinction is: if the fraud rests purely on a false promise or misrepresentation, Section 318 applies; if it rests on the offender pretending to be someone else — a bank employee, a relative, a courier agent — Section 319 is the more precise charge. Many real complaints involve both elements together, so investigators frequently frame charges under Sections 318 and 319 side by side rather than choosing only one, and candidates should be ready to identify both in a single case study.

Key Concepts — Prevention of Cyber Crime
Key Concepts — Prevention of Cyber Crime

📝 Forgery of Digital Documents — BNS Section 336

Forgery, previously scattered across IPC Sections 463, 465, 468 and 469, has been consolidated into a single provision — Section 336 of the BNS — with graded sub-sections replacing four separate old numbers. Section 336(2) covers general forgery, while forgery committed specifically to support cheating (forged loan documents, fabricated salary slips, altered KYC papers, manipulated digital signatures) is treated more severely under Section 336(3), the sub-section examiners test most often.

This consolidation is useful to remember for the exam because earlier study material forced candidates to juggle four separate IPC sections for what is now one section with internal grading. Cyber-forgery cases bankers encounter — forged cheque images used in remote deposit capture, tampered PDF statements submitted for loan sanction, or doctored digital mandates and forged e-signatures on loan agreements — sit squarely within Section 336(3) once the forged document induces a bank to part with money or approve a facility, and the sub-section grading determines the severity of punishment applied.

Candidates should also connect this provision to Electronic Card Frauds, where forged card data and cloned magnetic-stripe information often accompany a forgery charge alongside card-specific IT Act provisions. Exam anchor: a document, signature, mandate or record that was altered to deceive a bank starts at Section 336; if the deception also produced a wrongful gain, Section 318 joins the same chargesheet.

⚠️ Criminal Intimidation and Cyber Extortion — BNS Section 351

Sextortion, ransomware ransom demands and anonymous threat messages sent over email or messaging apps fall under criminal intimidation, now unified in Section 351 of the BNS. Where the old IPC split the offence across Section 503 (definition), Section 506 (punishment) and Section 507 (anonymous communication), BNS Section 351 merges all three into one provision and carries an enhanced-punishment limb for anonymous threats — precisely the pattern in ransomware notes and blackmail emails demanding cryptocurrency payment, a fact pattern examiners like to test.

The definition itself has been widened to expressly cover threats made through digital or electronic means, closing an ambiguity that earlier forced prosecutors to stretch old wording to fit online conduct. For bankers, this matters most where a customer or staff member is threatened with leaked data, doctored images or account compromise unless a payment is made — a pattern increasingly seen alongside phishing and social-engineering complaints. Because Section 351 sits independently of the IT Act, investigators can invoke it while the underlying technical offence is still being established, giving victims a faster route to a first police charge.

⚠️ Common Mistake: Candidates often assume intimidation delivered "anonymously" online is a lesser offence because the sender cannot be traced. Section 351 BNS treats anonymous digital threats as an aggravated form, attracting additional imprisonment on top of the base sentence.
Process & Framework — Prevention of Cyber Crime
Process & Framework — Prevention of Cyber Crime

💻 Electronic Evidence Gets a New Rulebook — BSA Section 63

No cyber-fraud prosecution succeeds without admissible electronic evidence. Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 replaces Section 65B of the old Evidence Act, retaining the same core idea — a record is admissible without producing the original device, given a certificate — but tightening the requirement.

Under Section 63(4), the certificate must be signed by both the person in charge of the device and an independent expert, and disclose the record's hash value, a safeguard old Section 65B never required. Scope also widened to "computer or any communication device," covering mobiles, servers and cloud logs — exactly what banks rely on for CCTV footage, SMS OTP logs, CBS data and call records. This is the single most operationally significant change for nodal officers who prepare evidence for law-enforcement requests, best read alongside the Cyber Laws In India chapter and the Ministry of Electronics and Information Technology, which still administers the IT Act, 2000.

Offence / ProvisionOld LawNew Law (in force 1 Jul 2024)Directly Cyber-Relevant?
CheatingSection 420, IPC 1860Section 318, BNS 2023✅
Cheating by personationSection 419, IPC 1860Section 319, BNS 2023✅
ForgerySections 463/465/468, IPC 1860Section 336, BNS 2023✅
Criminal intimidationSections 503/506/507, IPC 1860Section 351, BNS 2023✅
Electronic record admissibilitySection 65B, Evidence Act 1872Section 63, BSA 2023✅
Hacking, identity theft, cyber terrorismNot applicableUnchanged — IT Act, 2000❌
In Practice — Prevention of Cyber Crime
In Practice — Prevention of Cyber Crime

🧠 Practice MCQs: Cyber Crime under BNS 2023

Q1. Cheating, formerly Section 420 IPC, now corresponds to which BNS section? (a) Section 111 (b) Section 318 (c) Section 336 (d) Section 351

Answer: (b) — Mirrors old Section 420.

Q2. A fraudster impersonates a relationship manager to induce a customer into sharing an OTP. Which BNS provision fits? (a) Section 303 (b) Section 319 (c) Section 336 (d) Section 351

Answer: (b) — Cheating by personation.

Q3. Admissibility of electronic records without the original device is governed by: (a) Section 65B, Evidence Act (b) Section 63, BSA 2023 (c) Section 91, BNSS 2023 (d) Section 43, IT Act

Answer: (b) — Replaced Section 65B from 1 July 2024.

Q4. Under Section 63(4) BSA, the certificate must be signed by: (a) branch manager alone (b) magistrate alone (c) the device custodian and an independent expert (d) investigating officer alone

Answer: (c) — Dual signatures plus hash value.

Q5. From which date did the BNS, BNSS and BSA replace the IPC, CrPC and Evidence Act? (a) 26 January 2024 (b) 1 April 2024 (c) 1 July 2024 (d) 15 August 2024

Answer: (c) — All three took effect together.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Does the BNS 2023 replace the IT Act, 2000 for cyber crime cases?

No. BNS never touched the IT Act. Hacking stays an IT Act offence; BNS covers cheating, forgery and intimidation via computer or phone.

Are FIRs registered before 1 July 2024 renumbered under BNS?

No. Older cases continue under IPC, CrPC and Evidence Act sections; only later offences use BNS, BNSS and BSA numbering.

Which BNS section applies to sextortion and ransomware ransom threats?

Section 351, covering criminal intimidation via digital means, with enhanced punishment when the threat is delivered anonymously.

Why should bank staff care about Section 63 of the BSA 2023?

Most fraud evidence — CCTV footage, SMS logs, server data, call records — is electronic, and Section 63 sets its certification rule.

Building the Legal-Framework Chapter Into Your Revision

Treat BNS, BNSS and BSA as an overlay on fraud typologies you already study. Cross-check case studies against the map above, revisit Human Traits, and read card not present fraud, customer liability in unauthorised transactions and the cyber crime prevention checklist for bankers. See also the role of credit rating agencies in India, browse the tag hub, and pair this with CAIIB.

Prefer revising from a printed book?

Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.

All books →
MSME 2026 Edition
Micro, Small and Medium Enterprises (MSME)

132 pages · 225 MCQs

Learning Sessions · Ashish Sir

Micro, Small and Medium Enterprises (MSME) 15 chapters · 225 MCQs ₹1,199₹2,39850% off
CCP 2026 Edition
Certified Credit Professional (CCP)

188 pages · 435 MCQs

Learning Sessions · Ashish Sir

Certified Credit Professional (CCP) 29 chapters · 435 MCQs ₹1,199₹2,39850% off
KYCAML 2026 Edition
KYC, AML and CFT

117 pages · 236 MCQs

Learning Sessions · Ashish Sir

KYC, AML and CFT 16 chapters · 236 MCQs ₹1,199₹2,39850% off
TIRM 2026 Edition
Treasury, Investment and Risk Management (TIRM)

Learning Sessions · Ashish Sir

Treasury, Investment and Risk Management (TIRM) ₹1,199₹2,39850% off
ITSEC 2026 Edition
IT Security

118 pages · 299 MCQs

Learning Sessions · Ashish Sir

IT Security 20 chapters · 299 MCQs ₹1,199₹2,39850% off
RFS 2026 Edition
Risk in Financial Services

Learning Sessions · Ashish Sir

Risk in Financial Services ₹1,199₹2,39850% off
SFB 2026 Edition
Small Finance Banks

Learning Sessions · Ashish Sir

Small Finance Banks ₹1,199₹2,39850% off
TREASURY 2026 Edition
Treasury Management

Learning Sessions · Ashish Sir

Treasury Management ₹1,199₹2,39850% off
NBFC 2026 Edition
Non-Banking Financial Companies (NBFC)

115 pages · 255 MCQs

Learning Sessions · Ashish Sir

Non-Banking Financial Companies (NBFC) 17 chapters · 255 MCQs ₹1,199₹2,39850% off
ITF 2026 Edition
International Trade Finance

Learning Sessions · Ashish Sir

International Trade Finance ₹1,199₹2,39850% off
CAAP 2026 Edition
Certified Accounting and Audit Professional (CAAP)

334 pages · 936 MCQs

Learning Sessions · Ashish Sir

Certified Accounting and Audit Professional (CAAP) 63 chapters · 936 MCQs ₹1,199₹2,39850% off
RM 2026 Edition
Risk Management

Learning Sessions · Ashish Sir

Risk Management ₹1,199₹2,39850% off
FEFI 2026 Edition
Foreign Exchange Facilities for Individuals (FEFI)

115 pages · 344 MCQs

Learning Sessions · Ashish Sir

Foreign Exchange Facilities for Individuals (FEFI) 24 chapters · 344 MCQs ₹1,199₹2,39850% off
IIBF 2026 Edition
Debt Recovery Agents (DRA)

107 pages · 240 MCQs

Learning Sessions · Ashish Sir

Debt Recovery Agents (DRA) 16 chapters · 240 MCQs ₹1,199₹2,39850% off
DIGIBANK 2026 Edition
Digital Banking

90 pages · 150 MCQs

Learning Sessions · Ashish Sir

Digital Banking 10 chapters · 150 MCQs ₹1,199₹2,39850% off
BCP 2026 Edition
Banking Compliance Professional

Learning Sessions · Ashish Sir

Banking Compliance Professional ₹1,199₹2,39850% off
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading