Cyber Crime Prevention in Banking: IT Act, RBI Framework & IIBF Guide

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 26 June 2026 · Updated 01 Aug 2026 · 10 min read · 39 views
Cyber Crime Prevention in Banking: IT Act, RBI Framework & IIBF Guide

Cyber crime is one of the fastest-growing threats facing the Indian banking system today. And every banking professional preparing for IIBF certifications must have a thorough understanding of how digital fraud operates and how it can be prevented. As banks deepen their digital presence.

The attack surface for criminals has widened dramatically — from mobile banking apps to internet banking portals, UPI platforms, and beyond. This article covers the key types of cyber crime targeting banking customers. The legal framework under the Information Technology Act 2000, the RBI cyber security framework, the role of CERT-In, and the practical steps customers and banking staff must take to stay protected.

Common Types of Cyber Crime in Banking

Understanding the varieties of cyber crime is fundamental both for the IIBF Prevention of Cyber Crime certification examination and for day-to-day banking practice. Criminals deploy a wide range of techniques to steal credentials, divert funds, and compromise systems. The most prevalent attacks on the Indian banking sector can be grouped as follows:

Phishing, Vishing, and Smishing

Phishing is the practice of sending deceptive emails that impersonate a bank. Payment gateway, or regulatory body to trick a recipient into revealing login credentials, OTPs, or card details. Vishing (voice phishing) involves fraudulent phone calls — callers pretend to be bank officials or RBI representatives and pressure victims into sharing sensitive information under the guise of KYC updates or account suspension alerts. Smishing uses SMS text messages containing malicious links designed to harvest credentials or install malware on the victim's device. All three exploit trust and urgency, and all three are legally actionable under Indian law.

SIM Swap Fraud

In a SIM swap attack. The fraudster contacts the victim's telecom operator — often using forged identity documents — to port the victim's mobile number to a new SIM card under the criminal's control. Once successful, all OTPs and transaction alerts intended for the genuine customer are redirected to the fraudster, enabling unauthorised fund transfers. Banks have strengthened defences by introducing cooling periods for SIM-swap-linked transactions and SMS/email dual-channel alerts.

Malware and Ransomware

Banking malware such as keyloggers, screen scrapers, and man-in-the-browser tools silently capture credentials as customers type them. Ransomware encrypts critical data on bank systems or customer devices and demands payment for decryption keys. In recent years, ransomware attacks on financial institutions have caused significant operational disruptions globally. Banks must maintain up-to-date endpoint protection, segregated backup environments, and incident response playbooks to manage such threats.

Social Engineering and Business Email Compromise (BEC)

Social engineering leverages psychological manipulation rather than technical exploits. Fraudsters research targets on social media and craft personalised pretexts to gain trust. Business Email Compromise is a sophisticated form targeting corporates and banks, where criminals impersonate senior executives or vendors to redirect large payments. Staff training and strict dual-authorisation controls for fund transfers are the primary defences.

Common cyber crime attack vectors targeting banking customers in India
Common cyber crime attack vectors targeting banking customers in India

Legal Framework: IT Act 2000 and Its Amendments

India's primary legislation governing cyber crime is the Information Technology Act, 2000 (IT Act), subsequently amended by the Information Technology (Amendment) Act, 2008. IIBF examination candidates must be familiar with the key sections that banking professionals encounter in practice:

  • Section 43 — Penalty for damage to computer systems without the owner's permission, including unauthorised access, downloading, introduction of viruses, and disruption of service. Compensation can be awarded to the affected person.
  • Section 43A — Liability of body corporates (including banks) that are negligent in implementing and maintaining reasonable security practices for sensitive personal data. Banks must maintain documented information security policies.
  • Section 66 — Criminal punishment (imprisonment up to three years or fine up to ₹5 lakh, or both) for the acts listed under Section 43 when done dishonestly or fraudulently.
  • Section 66C — Identity theft: fraudulently using someone else's electronic signature, password, or unique identification feature carries imprisonment up to three years and a fine up to ₹1 lakh.
  • Section 66D — Cheating by impersonation using a computer resource (covers phishing and vishing): imprisonment up to three years and fine up to ₹1 lakh.
  • Section 67 — Publishing obscene material in electronic form (relevant for misuse of digital banking platforms).
  • Section 72A — Disclosure of personal information in breach of lawful contract; up to three years' imprisonment or ₹5 lakh fine, or both.

Beyond the IT Act. Relevant provisions of the Indian Penal Code (IPC) — particularly those relating to cheating (Section 420), forgery (Sections 463–465), and extortion (Section 383) — apply concurrently to many cyber crime scenarios in banking. The Bharatiya Nyaya Sanhita (BNS), which replaced the IPC in 2023, carries these provisions forward with updated language.

For IIBF candidates. It is important to note that the IT Act establishes the Cyber Appellate Tribunal and designates Adjudicating Officers for civil disputes, while criminal prosecution is pursued through courts of competent jurisdiction.

RBI Cyber Security Framework and CERT-In

The Reserve Bank of India has built a robust regulatory architecture to protect the banking ecosystem from cyber threats. The RBI Cyber Security Framework for Banks (issued in 2016 and revised periodically) mandates that all Scheduled Commercial Banks implement a comprehensive cyber security policy. Approved by the Board, covering governance, risk assessment, incident response, vendor management, and customer awareness. Key requirements include:

  • Appointment of a Chief Information Security Officer (CISO) with direct reporting to the Board or its Risk Committee.
  • 24×7 Security Operations Centre (SOC) for real-time threat monitoring.
  • Mandatory reporting of cyber security incidents to RBI within prescribed timelines (2–6 hours for critical incidents).
  • Regular Vulnerability Assessment and Penetration Testing (VAPT) of all internet-facing systems.
  • Implementation of multi-factor authentication for all customer-facing digital channels.
  • Secure Software Development Lifecycle (SSDLC) for in-house and vendor-developed applications.
  • Network segregation, data-at-rest and data-in-transit encryption, and robust patch management.

The RBI also issues Master Directions on Digital Payment Security Controls. Requiring banks to monitor transaction patterns, set transaction velocity limits, and establish dispute resolution mechanisms for unauthorised digital transactions. Understanding these directions is directly examinable in the IIBF Prevention of Cyber Crime module.

CERT-In (Indian Computer Emergency Response Team), operating under the Ministry of Electronics and Information Technology (MeitY), is India's national agency for responding to cyber security incidents. Under the IT Act (Section 70B), CERT-In has the authority to issue guidelines, collect and analyse information about cyber incidents, and coordinate responses across sectors. Banks are required to report cyber incidents to CERT-In within six hours of detection (as per the 2022 directions). CERT-In publishes advisories on emerging threats, vulnerabilities in banking software, and best practices for incident response — all of which banking professionals must monitor through resources like IIBF news updates.

RBI cyber security framework pillars for Indian banks
RBI cyber security framework pillars for Indian banks

Customer Awareness and Due Care in Cyber Crime Prevention

No technical control is fully effective without informed customers. Banking staff must be equipped to educate account holders on cyber hygiene. This is a core theme in the IIBF Prevention of Cyber Crime syllabus, and the following practical guidance should be communicated proactively to customers:

Safe Digital Banking Practices

  1. Never share OTPs, PINs, or passwords — Banks will never ask for these over the phone, email, or SMS. Any such request is a red flag.
  2. Verify before you click — Check the sender's actual email domain (not just the display name) and hover over links to inspect the destination URL before clicking.
  3. Use official apps only — Download banking apps exclusively from the bank's official website or verified app store listings.
  4. Enable transaction alerts — Register for SMS and email alerts for all transactions so any unauthorised activity is detected immediately.
  5. Secure your SIM — If you lose connectivity unexpectedly, contact your telecom operator immediately to check for unauthorised SIM swaps.
  6. Keep software updated — Maintain updated operating systems, browsers, and antivirus software on devices used for banking.
  7. Use strong, unique passwords — Avoid using the same password across banking and non-banking platforms. Consider a reputable password manager.
  8. Log out after each session — Always formally log out of internet banking rather than just closing the browser window.

What to Do if You Suspect Fraud

Victims of banking cyber crime should act immediately:

  • Call the national helpline 1930 (Cyber Crime Helpline, operational 24×7) to report financial fraud and initiate a transaction freeze.
  • File a complaint at cybercrime.gov.in, the National Cyber Crime Reporting Portal operated by the Ministry of Home Affairs.
  • Notify the bank's customer care immediately to block compromised accounts, cards, or UPI handles.
  • File a First Information Report (FIR) at the nearest police station or the dedicated Cyber Crime Cell.

The RBI's framework on limiting customer liability in unauthorised electronic transactions is also crucial: if a customer reports an unauthorised transaction within the stipulated period (typically three working days for third-party fraud), zero or limited liability applies depending on the negligence involved. Banking staff must be able to guide affected customers through this process. For comprehensive exam preparation on such regulatory provisions, explore the JAIIB course or the CAIIB course on iibf.store, and sharpen your knowledge with practice tests and interactive concept-match games. You can also review the latest regulatory updates through RBI rates and policy updates and the IIBF blog.

For authoritative and up-to-date advisories on cyber threats affecting the banking sector, always refer to the official CERT-In website, which publishes vulnerability notes, incident alerts, and best-practice guidelines applicable to financial institutions.

Frequently Asked Questions

What is the difference between phishing, vishing, and smishing in the context of banking cyber crime?

Phishing uses fraudulent emails to trick banking customers into revealing credentials or clicking malicious links. Vishing (voice phishing) uses phone calls where fraudsters impersonate bank staff or regulators to extract OTPs and account details. Smishing uses SMS messages with deceptive links or instructions. All three are forms of social engineering and are punishable under Sections 66C and 66D of the IT Act 2000.

Under which sections of the IT Act 2000 is identity theft and phishing punishable?

Identity theft is covered under Section 66C of the IT Act 2000. Which prescribes imprisonment up to three years and a fine up to ₹1 lakh for fraudulent use of another person's electronic signature, password, or unique identification feature. Cheating by impersonation using a computer resource — which includes phishing and vishing — is covered under Section 66D, with the same punishment. Both sections were introduced by the IT (Amendment) Act 2008.

What is the role of CERT-In in the context of cyber crime affecting Indian banks?

CERT-In (Indian Computer Emergency Response Team) is the national nodal agency under MeitY for responding to cyber security incidents. Under Section 70B of the IT Act, CERT-In issues guidelines, collects and analyses incident data, and coordinates responses. Banks must mandatorily report cyber incidents to CERT-In within six hours of detection (per the 2022 directions). CERT-In also publishes threat advisories and vulnerability notes that banks use to strengthen their defences.

How should a banking customer report a cyber fraud incident in India?

A customer who suspects or has experienced banking cyber fraud should immediately call the national Cyber Crime Helpline at 1930 to report the incident and request a transaction hold. They should also file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in. Notify the bank's customer care to block affected accounts or cards, and, where appropriate, file an FIR at the nearest police station or Cyber Crime Cell. Early reporting within the RBI's stipulated timeline can limit customer liability for unauthorised transactions.

Mastering the prevention of cyber crime is not only essential for IIBF certification success but also a professional responsibility for every banker in India's digital economy. Test your understanding of these concepts — including IT Act provisions, RBI frameworks, and fraud prevention protocols — with full-length mock tests on iibf.store designed specifically for IIBF certification aspirants.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading