IT Act 2000 Sections for Cyber Crime: Banker's Guide (IIBF 2026)

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 29 July 2026 · Updated 09 Sep 2026 · 10 min read · 29 views
IT Act 2000 Sections for Cyber Crime: Banker's Guide (IIBF 2026)

Every cyber fraud FIR a bank files, every compensation claim a customer raises, and every phishing site a bank gets taken down rests on a specific legal foundation. Knowing the IT Act 2000 sections for cyber crime is not optional trivia for IIBF candidates — it is the statute your branch's fraud, legal and IT security teams actually invoke when an account is hacked, a card is cloned, or a customer's KYC data leaks. This article walks through the key sections, the penalties attached to each, how adjudication and appeals work, and how bankers apply the Act in real incidents, in the order the exam typically tests them.

📜 IT Act 2000 Sections for Cyber Crime: The Core Framework

The Information Technology Act, 2000 (as amended in 2008) is India's primary cyber law, and a cluster of its sections deal directly with offences bankers encounter. Section 43 is the foundation — it makes unauthorised access, downloading, introducing a virus, damaging data, or denying access to a computer system a civil wrong, with the victim entitled to compensation for the actual loss caused, without any statutory ceiling after the 2008 amendment.

Section 43A is the one bankers should know cold: it makes a "body corporate" — including a bank — liable to pay compensation if it is negligent in implementing and maintaining "reasonable security practices and procedures" while handling sensitive personal data or information (SPDI), a standard fleshed out by the IT (Reasonable Security Practices) Rules, 2011. Section 65 covers tampering with computer source documents, while Section 66 criminalises the dishonest or fraudulent acts described in Section 43 — this is the general "hacking" provision. Building context on how these attacks actually happen helps the sections stick; see Computer Insecurity and Computer Hackers for the underlying technical methods these sections were drafted to punish.

Key IT Act 2000 sections for cyber crime relevant to banking, from Section 43 to Section 72A
Key IT Act 2000 sections for cyber crime relevant to banking, from Section 43 to Section 72A
💡 Exam Tip: Section 43 is civil (compensation), Section 66 is criminal (imprisonment/fine) for the same underlying acts done dishonestly or fraudulently — examiners frequently test this civil-versus-criminal distinction.

⚖️ Penalties and Punishments Under the Act

Beyond Sections 43 and 66, a family of sub-sections targets specific digital offences that map directly onto banking fraud patterns. Section 66B punishes dishonestly receiving stolen computer resources or communication devices. Section 66C is the identity-theft provision — fraudulent use of another person's password, digital signature or any other unique identification feature, directly relevant to net-banking credential theft. Section 66D punishes cheating by personation using a computer resource, the exact offence underlying most phishing and vishing scams. Section 66F covers cyber terrorism, carrying the harshest punishment in the Act. Section 67 deals with publishing or transmitting obscene material electronically, and Section 70 protects "protected systems" notified as critical information infrastructure, which can include core banking and payment infrastructure.

The table below summarises punishments as prescribed under the Act. Fines and imprisonment terms are the statutory maximums; courts and adjudicating officers exercise discretion within these limits based on facts. For the authoritative text of every section, the Ministry of Electronics and Information Technology hosts the consolidated Information Technology Act, 2000, which is the primary reference candidates should cite over any secondary summary.

SectionOffencePunishment (maximum)Relevant to Banking
43 / 43AUnauthorised access/damage; negligent data security (civil)Compensation for actual loss (no statutory cap)✅ Yes
66Computer-related offences (dishonest/fraudulent hacking)3 years imprisonment or fine up to ₹5 lakh, or both✅ Yes
66CIdentity theft (password/credential misuse)3 years imprisonment and fine up to ₹1 lakh✅ Yes
66DCheating by personation (phishing/vishing)3 years imprisonment and fine up to ₹1 lakh✅ Yes
66FCyber terrorismImprisonment for life❌ Rare in routine banking fraud
72 / 72ABreach of confidentiality/privacy; unlawful disclosureUp to 3 years imprisonment or fine, or both✅ Yes
Table of IT Act penalties for cyber crime offences most relevant to Indian banks
Table of IT Act penalties for cyber crime offences most relevant to Indian banks
⚠️ Common Mistake: Candidates often assume every cyber offence in the Act is bailable and minor. Section 66F (cyber terrorism) carries life imprisonment, and several offences involving repeat conviction or aggravated harm attract significantly higher exposure than first-time Section 66 cases.

🏛️ Adjudication, Compensation and the Appeal Process

Compensation claims under Section 43/43A are not decided by a criminal court in the first instance — they go to an Adjudicating Officer, appointed under Section 46, typically an officer not below the rank of Director in the state IT department. The Adjudicating Officer holds an inquiry, gives both parties a hearing, and can award compensation; claims beyond the Adjudicating Officer's pecuniary jurisdiction go to the competent civil court instead.

Appeals against an Adjudicating Officer's order originally went to the Cyber Appellate Tribunal (CAT) constituted under Section 48. Following the Finance Act, 2017, the CAT's functions were merged into the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which now hears these appeals. A further appeal on a question of law lies to the jurisdictional High Court. For banks, this matters operationally: how a suspected fraud is first logged, escalated and evidenced determines whether a later compensation claim or adjudication proceeds smoothly — a process detailed in Incident Management.

Corporate liability is fixed under Section 85: where a company commits an offence, every person in charge of and responsible to the company for its conduct at the time of the offence is deemed guilty, unless they prove the offence occurred without their knowledge and despite due diligence. This is why banks maintain documented IT security governance and named responsibility — it is the primary defence available under Section 85.

Adjudication and appeal process under the IT Act 2000 for banking cyber fraud disputes
Adjudication and appeal process under the IT Act 2000 for banking cyber fraud disputes

🔍 Applying These Sections in Bank Fraud Investigations

When a branch or bank CERT team investigates an incident — a compromised net-banking login, a cloned debit card, or a business email compromise — the legal workflow runs in parallel with the technical one. FIRs typically cite the applicable IT Act sections (43A, 66, 66C, 66D depending on the fact pattern) alongside relevant provisions of the Bharatiya Nyaya Sanhita, 2023, which replaced the IPC's cheating and forgery offences. Electronic evidence — server logs, CCTV, SMS/OTP records, transaction trails — must satisfy the certification requirements now under the Bharatiya Sakshya Adhiniyam, 2023 (which replaced Section 65B of the erstwhile Evidence Act) before a court will admit it, so preserving a clean, certified digital trail from the first hour of an incident is critical.

Section 79 gives intermediaries limited safe-harbour protection from liability for third-party content, provided they exercise due diligence — relevant where a bank's platform is misused by a fraudster to route stolen funds, distinct from cases where the bank itself was negligent under Section 43A. Understanding the channels through which such fraud typically enters is covered in Channels Of Cyber Crimes, and card-specific incidents overlap heavily with card skimming fraud detection techniques your fraud team should already be applying at the point of sale and ATM.

Once funds move, tracing typically involves accounts flagged for money mule accounts, and customers are directed to report promptly through the 1930 cyber crime helpline so the golden-hour freeze window under banking-sector reporting protocols can be used effectively. None of this legal and procedural response works without the physical layer holding first — server rooms, access controls and hardware safeguards covered under physical and environmental security controls are what keep an incident from becoming a Section 43A negligence finding in the first place.

📌 Remember: The technical chapter and the legal section are two views of the same incident — a hacking method under Electronic Card Frauds is what happened; Section 66C or 66D is what it is charged as.

✅ Conclusion: Locking the IT Act Down for the Exam

For IIBF's Prevention of Cyber Crime paper, do not try to memorise every sub-section in isolation. Anchor your revision around four clusters: Section 43/43A for civil liability and compensation, Section 66 and its sub-sections (66B–66F) for criminal offences, Sections 46/48 and the TDSAT route for adjudication and appeal, and Section 85 for corporate liability. Every case study question the exam sets will map to one of these clusters, usually combined with a fact pattern you can trace back to the exact IT Act 2000 sections for cyber crime covered above. Browse more chapter notes on the Prevention of Cyber Crime tag hub for the full picture beyond these legal provisions.

Ready to test your recall under exam conditions? Practise chapter-wise mock questions on iibf.store and check where your section-wise knowledge still has gaps before the real exam.

🧠 Practice MCQs: IT Act 2000 Sections for Cyber Crime

Q1. Which section of the IT Act, 2000 makes a bank liable to pay compensation for negligence in implementing reasonable security practices while handling sensitive personal data? (a) Section 66 (b) Section 43A (c) Section 72 (d) Section 85

Answer: (b) — Section 43A fixes civil liability on a body corporate for negligent handling of sensitive personal data or information.

Q2. Cheating by personation using a computer resource, the offence underlying most phishing scams, falls under which section? (a) Section 66B (b) Section 66C (c) Section 66D (d) Section 67

Answer: (c) — Section 66D specifically punishes cheating by personation by means of a computer resource or communication device.

Q3. Appeals against an order of the Adjudicating Officer under the IT Act now lie with which tribunal, following the Finance Act, 2017? (a) Cyber Appellate Tribunal (b) National Company Law Tribunal (c) Telecom Disputes Settlement and Appellate Tribunal (TDSAT) (d) Securities Appellate Tribunal

Answer: (c) — The Cyber Appellate Tribunal's functions were merged into TDSAT after the Finance Act, 2017.

Q4. Under Section 85 of the IT Act, who is primarily held liable when a company commits a cyber offence? (a) Only the IT department (b) Every person in charge of and responsible to the company for its conduct at the time of the offence (c) Only the CEO regardless of role (d) No one, as companies cannot be prosecuted

Answer: (b) — Section 85 fixes liability on persons in charge of and responsible for the company's conduct, subject to a due-diligence defence.

Q5. Which IT Act section prescribes the harshest punishment, up to imprisonment for life, among the offences discussed? (a) Section 66B (b) Section 66F (cyber terrorism) (c) Section 43 (d) Section 79

Answer: (b) — Section 66F, covering cyber terrorism, carries the possibility of imprisonment for life, the most severe punishment under these provisions.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

What are the main IT Act 2000 sections for cyber crime relevant to banking?

The core cluster is Section 43/43A (unauthorised access and negligent data security, civil compensation), Section 66 and its sub-sections 66B to 66F (criminal offences like hacking, identity theft, phishing-based cheating and cyber terrorism), Section 70 (protected systems), Section 72/72A (breach of confidentiality), and Section 85 (corporate liability).

What is the difference between Section 43 and Section 66 of the IT Act?

Section 43 creates civil liability — the wrongdoer must pay compensation for the loss caused by unauthorised access or damage. Section 66 criminalises the same acts when done dishonestly or fraudulently, attracting imprisonment up to three years and/or a fine up to five lakh rupees.

Where do compensation claims under the IT Act get decided?

Claims under Section 43/43A are first heard by an Adjudicating Officer appointed under Section 46. Appeals from the Adjudicating Officer's order now go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), following the merger of the Cyber Appellate Tribunal's functions under the Finance Act, 2017.

Is the IT Act, 2000 the only law used in banking cyber fraud cases?

No. Investigators typically apply the relevant IT Act sections alongside the Bharatiya Nyaya Sanhita, 2023 for cheating and forgery offences, and electronic evidence must meet the certification standards under the Bharatiya Sakshya Adhiniyam, 2023, which replaced the erstwhile Evidence Act provisions on electronic records.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading