Phishing, Ransomware & the IT Act 2000: Banker's Guide

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 16 June 2026 · Updated 31 Jul 2026 · 12 min read · 16 views
Phishing, Ransomware & the IT Act 2000: Banker's Guide

Phishing, ransomware and the IT Act 2000 sit right at the heart of the Prevention of Cyber Crime syllabus - and at the heart of every Indian banker's working day. One describes the most common ways fraudsters trick customers, another describes the malware that can freeze an entire branch, and the third is the legal machinery built to punish both. If you can explain how these attacks work, how the Information Technology Act 2000 criminalises them, and how the Reserve Bank of India expects banks to respond, you are not just collecting marks - you are protecting real people's money.

This guide walks through each pillar in plain, exam-ready English. You will learn to recognise the attack, apply the correct control, and quote the right section or circular. Bankers are the first line of defence against criminals who impersonate institutions, deploy malicious software and exploit human trust, so let's build that defence from the ground up.

Phishing, ransomware and IT Act 2000 banker guide cover for IIBF cyber crime exam
Phishing, ransomware and the IT Act 2000 form the core of the Prevention of Cyber Crime syllabus.

Key takeaways

  • Phishing, ransomware and the IT Act 2000 together cover the threat (attack), the impact (malware) and the deterrent (law).
  • Section 66D (cheating by personation using a computer resource) is the section most often applied to phishing and vishing; Section 66C covers identity theft.
  • Banks never ask for your OTP, PIN, CVV or full card number - this single rule stops most retail fraud.
  • RBI's customer-protection circular gives zero liability when fraud is due to bank negligence or is reported within three working days.
  • The correct ransomware response is do not pay - contain, restore from offline backups, preserve evidence and report through CERT-In.

What counts as cyber crime in banking

In a banking context, cyber crime is any offence where a computer, network or digital channel is the tool, the target, or both. The defining feature is direct monetary loss combined with regulatory exposure - a single compromised endpoint can cascade into thousands of fraudulent transactions within minutes. For IIBF candidates, grouping the major categories makes them far easier to recall under exam pressure.

  • Data and identity theft - stealing card numbers, login credentials, Aadhaar or KYC data to impersonate a customer.
  • Unauthorised access and hacking - breaking into core banking systems, ATMs or payment switches.
  • Financial fraud - account takeover, mule accounts, UPI fraud and fraudulent fund transfers.
  • Malware-based attacks - trojans, keyloggers and ransomware that compromise systems.
  • Social engineering - tricking people rather than machines, which we cover in detail below.

Prevention is deliberately layered: technology controls, staff awareness, customer education and legal deterrence all reinforce one another. A strong candidate can take any fraud scenario, map it to one of these categories, and then name the matching control. You can rehearse exactly that skill on our scenario-driven cyber crime mock tests, which mirror the style examiners increasingly favour. For the broader picture of how the law and the RBI framework fit together, our companion explainer on Cyber Crime in Banking 2026: IT Act and RBI Framework is the ideal next read.

Phishing, vishing, smishing and social engineering

The largest single channel of customer-facing fraud is social engineering, where the attacker manipulates a human being into revealing secrets or authorising a transaction. The exam expects you to distinguish the variants precisely, so learn these four cold.

  • Phishing - fraudulent emails or fake websites that imitate a bank to harvest passwords, OTPs and card details.
  • Vishing - voice phishing over the telephone, where the caller poses as a bank officer or KYC agent.
  • Smishing - SMS-based phishing carrying malicious links or fake reward and account-block alerts.
  • Pharming - redirecting a genuine web address to a counterfeit site through DNS tampering.

Every one of these exploits urgency and authority. A message warns that an account will be frozen, a refund is pending, or a reward will lapse, and the victim acts before thinking. The antidote is a single, repeatable rule: banks never ask for OTP, PIN, CVV or full card numbers. Reinforcing that one line prevents the majority of retail fraud. For staff the defences are just as human - verify before you act, never share credentials, and report suspicious contact immediately.

India's institutional support is strong here. The Reserve Bank and the Indian Cyber Crime Coordination Centre run continuous awareness campaigns, and the national cyber-fraud helpline 1930 lets victims report within the critical "golden hour", when funds can still be held before they are siphoned away. You can drill these definitions quickly with our cyber crime matching game, then go deeper with the focused guide on Phishing and Vishing Attacks on Banks 2026: Red Flags and Defence.

Phishing vishing and smishing attack channels targeting bank customers explained
Phishing, vishing and smishing all exploit urgency and authority to bypass human judgement.

Ransomware and the wider malware threat

Ransomware is malicious software that encrypts an organisation's files and demands a payment - usually in cryptocurrency - for the decryption key. For a bank the damage is twofold: operations halt because systems are locked, and sensitive data may also be stolen and threatened with public release in a double-extortion model. Recovery is invariably far more expensive than prevention.

  • Entry points - phishing attachments, compromised remote-access credentials and unpatched software vulnerabilities.
  • Spread - lateral movement across the network once a single machine is infected.
  • Impact - service outages, regulatory penalties, reputational damage and customer distrust.

The defensive playbook is well established and very testable. Maintain offline, tested backups so systems can be restored without paying. Patch operating systems and applications promptly. Segment networks so an infection cannot spread freely. Enforce least-privilege access and multi-factor authentication. Run endpoint detection tools, and rehearse an incident-response plan rather than merely writing one.

RBI guidance is explicit that paying a ransom is discouraged: it funds further crime and offers no guarantee of recovery. Instead, institutions must contain the incident, preserve evidence and report through the proper channels. Keeping pace with evolving threats is part of the job, which is why the dedicated Cyber Security Framework: RBI & CERT-In Exam Guide 2026 is worth bookmarking alongside this one.

The Information Technology Act 2000 and its key sections

The Information Technology Act 2000, substantially amended in 2008, is India's primary cyber law. It gives legal recognition to electronic records and digital signatures, and it criminalises a range of cyber offences. For banking fraud, a handful of headline sections come up again and again, so commit them to memory.

Section What it covers Typical banking use
43Penalty & compensation for unauthorised access, downloading or introducing a virus/contaminantCivil remedy for data tampering
43ACompensation where a body corporate is negligent in protecting sensitive personal dataBank liability for KYC data leaks
66Computer-related offences such as hacking; imprisonment up to three years or fineCore banking intrusions
66CIdentity theft - fraudulent use of passwords or electronic signaturesStolen credentials & account takeover
66DCheating by personation using a computer resourcePhishing & vishing - the go-to section
66E / 67Violation of privacy / publishing obscene material in electronic formMisuse of captured data
70 / 72Protected systems / breach of confidentiality and privacyInsider misuse of critical systems

Two institutional pillars sit alongside the Act. The Indian Computer Emergency Response Team, CERT-In, is the national nodal agency for cyber incidents, and its 2022 directions require certain incidents to be reported within six hours of detection. The RBI Cyber Security Framework of 2016 mandates a board-approved cyber security policy, a Security Operations Centre, and prompt incident reporting for banks. Because exact thresholds and timelines are revised over time, always confirm the current numbers against the official IIBF notification and the live RBI/CERT-In circulars rather than relying on memory alone. For a section-by-section deep dive, see IT Act 2000: Cyber Crime Sections Every IIBF Aspirant Needs.

Customer protection and the limited-liability circular

Legal deterrence means little to a defrauded customer unless their money is restored. RBI's Customer Protection circular on limiting the liability of customers (2017) addresses exactly this, setting out when a customer bears zero liability for an unauthorised electronic transaction. The burden of proving customer liability rests on the bank, which strongly incentivises robust controls.

  • Zero liability - where the fraud results from bank negligence or a system failure, or where the customer reports an unauthorised transaction within three working days.
  • Limited liability - a capped amount depending on account type, where the customer reports within roughly four to seven working days.
  • Shadow reversal - banks must credit the disputed amount within ten working days of notification.

The circular places a clear duty on banks to provide easy, 24x7 reporting channels and to register customer mobile numbers and email IDs for transaction alerts. For the exam, hold the principle firmly in mind: prompt reporting protects the customer. The IT Act, the RBI framework, the CERT-In directions and this circular form a single integrated answer to cyber crime - technology to prevent, law to deter, and regulation to remediate. Treat the precise day-count thresholds as time-sensitive and verify them on the latest released RBI circular before quoting figures in a high-stakes answer.

A practical study plan and defence checklist

Knowing the theory is one thing; recalling it in a 90-second scenario question is another. Here is a compact, repeatable plan that works for both the exam and the branch floor.

  1. Week 1 - vocabulary. Lock down phishing vs vishing vs smishing vs pharming, plus the malware family, until you can define each in one line.
  2. Week 2 - the law. Memorise Sections 43, 43A, 66, 66C, 66D and their banking application using the table above.
  3. Week 3 - the regulator. Learn the RBI Cyber Security Framework, CERT-In's reporting role, and the customer-liability timelines.
  4. Week 4 - application. Solve scenario questions daily, mapping each case to category - control - section - circular.

For daily defence, staff and customers alike can follow a simple checklist: never share OTP/PIN/CVV; hover over links before clicking; confirm caller identity through the official number; keep software patched; and report anything suspicious to 1930 immediately. Anchor your revision with the full Prevention of Cyber Crimes & Fraud Management syllabus and free PDF, and explore every related guide on the cyber crime blog hub. When you are ready to register, the official source of truth for dates and rules is always the Indian Institute of Banking & Finance (IIBF).

Common mistakes candidates make

  • Confusing 66C and 66D. Identity theft (misusing a password) is 66C; impersonating someone to cheat is 66D. Phishing usually triggers 66D.
  • Assuming a customer is always liable. The default under the RBI circular is the opposite - the bank must prove the customer was at fault.
  • Recommending payment of ransom. Examiners want "do not pay"; payment funds crime and guarantees nothing.
  • Quoting outdated timelines as gospel. Reporting windows and thresholds get revised - frame them as "per the latest RBI/CERT-In circular".
  • Treating prevention as purely technical. Awareness and customer education are weighted just as heavily in scenario answers.

Avoiding these five traps is often the difference between a near-miss and a confident pass. To stress-test yourself, run a timed set on the Learning Sessions mock tests and review every wrong answer against the relevant section.

Frequently asked questions

What is the difference between phishing and vishing?

Phishing uses fraudulent emails or fake websites to steal credentials, while vishing uses voice calls in which the fraudster impersonates a bank officer or KYC agent. Both rely on social engineering, but the channel differs - phishing is digital text and web pages, whereas vishing is the telephone. Smishing is the SMS equivalent.

Which IT Act 2000 section applies to phishing fraud?

Section 66D, which covers cheating by personation using a computer resource, is most commonly applied to phishing and vishing. Section 66C on identity theft is also frequently invoked where passwords or electronic signatures are misused. In practice, investigators often charge both together depending on the facts.

Should a bank pay a ransomware demand?

No. RBI guidance discourages paying because it funds further crime and offers no guarantee that data will be restored. The correct response is to contain the incident, restore from offline backups, preserve evidence, and report through CERT-In and the regulator within the required timeframe.

When does a customer have zero liability for online fraud?

Under the RBI customer-protection circular, a customer bears zero liability when the fraud arises from bank negligence or a system failure, or when they report an unauthorised transaction within three working days of receiving the alert. Because exact day-counts can be revised, confirm the current threshold on the latest RBI circular before relying on it.

What is CERT-In's role in cyber incidents?

CERT-In is India's national nodal agency for responding to cyber security incidents. Under its 2022 directions, certain incidents must be reported within six hours of detection. Banks coordinate with CERT-In alongside the RBI framework when containing and disclosing an attack.

How should I revise this topic for the IIBF exam?

Start with the vocabulary, then the IT Act sections, then the RBI and CERT-In frameworks, and finish with scenario practice. The winning habit is mapping each case to category, control, section and circular. Daily timed questions on Learning Sessions cement recall far better than passive reading.

Conclusion

Master phishing, ransomware and the IT Act 2000 and you gain two things at once: solid exam marks and the professional judgement to protect customers in the real world. The pattern never changes - recognise the attack, apply the right control, and invoke the correct legal and regulatory provision. Keep the section numbers and reporting timelines at your fingertips, verify the time-sensitive figures against the official IIBF and RBI notifications, and practise until scenario questions feel routine. You have the framework; now go and make it second nature.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading