UNIT – II: COMPUTERS
6. CYBER CRIMES
1. A Brief History of the Internet
1. Introduction
The Internet is a global network of interconnected computers that enables
communication, information sharing, and online services across the world. Today,
it plays a vital role in education, business, governance, and social interaction.
However, the same technology that enables convenience and connectivity has also
given rise to cyber crimes.
To understand cyber crimes and cyber laws, it is essential to study the historical
development of the Internet, its evolution, and how its expansion created new
opportunities for criminal misuse.
2. Origin of the Internet – ARPANET
The origin of the Internet dates back to the 1960s during the Cold War period. The
United States Department of Defense initiated a research project called ARPANET
(Advanced Research Projects Agency Network) in 1969.
Objectives of ARPANET:
To enable secure communication between military and research institutions
To create a decentralized network that could survive partial destruction
ARPANET connected four major universities in the USA and introduced the concept
of packet switching, which became the foundation of modern Internet
communication.
3. Development of Networking Protocols
During the 1970s and 1980s, researchers developed communication rules known
as protocols to allow di erent computer systems to communicate.
The most important development was TCP/IP (Transmission Control Protocol /
Internet Protocol), introduced by Vinton Cerf and Robert Kahn. In 1983, TCP/IP
became the standard protocol for ARPANET, o icially marking the birth of the
Internet.
This standardization allowed multiple networks to interconnect, forming a network
of networks, known as the Internet.
4. Expansion through Academic and Research Networks
In the 1980s, the Internet expanded beyond military use to include:
Universities
Research institutions
Government organizations
Networks such as NSFNET (National Science Foundation Network) helped connect
academic institutions worldwide. Email became one of the first popular Internet
applications during this period.
5. Birth of the World Wide Web (WWW)
A major milestone in Internet history occurred in 1989, when Sir Tim Berners-Lee
invented the World Wide Web (WWW).
The World Wide Web introduced:
Web browsers
Hypertext (HTML)
Web servers and URLs
This development made the Internet user-friendly and accessible to the general
public, leading to rapid global adoption.
6. Commercialization of the Internet
In the 1990s, restrictions on commercial use were removed, allowing businesses to
operate online.
This phase led to:
E-commerce
Online banking
Digital communication platforms
Social networking websites
The commercialization of the Internet significantly increased Internet users but
also opened doors for online frauds, hacking, and cyber o ences.
7. Growth of Mobile Internet and Social Media
In the 2000s, the Internet evolved further with:
Mobile devices and smartphones
Wireless networks (Wi-Fi, 4G, 5G)
Social media platforms
This widespread connectivity resulted in massive data generation and increased
dependency on digital services, simultaneously increasing cyber threats and cyber
crimes.
8. Emergence of Cyber Crimes
As Internet usage increased, criminals began exploiting vulnerabilities for illegal
activities such as:
Hacking and unauthorized access
Identity theft
Online financial fraud
Cyber stalking
Malware and ransomware attacks
The borderless nature of the Internet made these crimes di icult to control,
leading to the need for cyber laws and international cooperation.
9. Need for Cyber Laws and Regulation
The rapid evolution of the Internet exposed limitations of traditional laws. To
address cyber crimes, countries enacted specific cyber legislations.
In India, this led to the enactment of the Information Technology Act, 2000, which
was later amended in 2008 to tackle modern cyber threats.
10. Conclusion
The Internet evolved from a small military research network into a global digital
infrastructure. While it has revolutionized communication and commerce, it has
also given rise to various forms of cyber crimes. Understanding the history of the
Internet helps in recognizing how technological progress influences criminal
behavior and why strong cyber laws are essential.
2. Recognizing and Defining Computer Crime
1. Introduction
With the rapid growth of computers, the Internet, and digital technologies, crimes
are no longer limited to physical spaces. Criminal activities are increasingly carried
out using computers and networks, giving rise to what is known as computer crime
or cyber crime.
Recognizing and defining computer crime is essential for:
Understanding the nature of cyber o ences
Investigating and prosecuting o enders
Framing e ective cyber laws and policies
2. Meaning of Computer Crime
A computer crime refers to any illegal or unauthorized activity in which a computer,
computer system, digital device, or network is involved either as a tool, a target, or
a place of crime.
Computer crimes involve acts such as unauthorized access, data theft, data
manipulation, disruption of services, or misuse of digital resources for criminal
purposes.
3. Definition of Computer Crime
Computer crime can be defined as:
“Any unlawful act where a computer or computer network is used to commit,
facilitate, or target a criminal o ence.”
This definition highlights three important aspects:
1. Use of computer technology
2. Presence of criminal intent
3. Violation of existing laws or rights
4. Recognizing Computer Crime
Recognizing computer crime involves identifying activities that violate legal,
ethical, or security norms in the digital environment.
Indicators of Computer Crime:
Unauthorized access to computer systems
Sudden data loss or alteration
Unusual system behavior or slow performance
Presence of malware or suspicious programs
Unauthorized financial transactions
Breach of confidentiality or privacy
These indicators help investigators and organizations detect potential cyber
o ences.
5. Characteristics of Computer Crime
Computer crimes have unique characteristics that distinguish them from
traditional crimes:
5.1 Borderless Nature
Computer crimes can be committed from any location in the world, making
jurisdiction and investigation di icult.
5.2 Speed and Automation
Cyber crimes can be executed within seconds using automated tools and scripts.
5.3 Anonymity of O enders
O enders can hide their identity using fake accounts, VPNs, and encryption
technologies.
5.4 Technical Complexity
Computer crimes often require specialized technical knowledge to understand,
investigate, and prosecute.
5.5 High Impact
A single cyber attack can a ect thousands of victims simultaneously.
6. Computer Crime vs Traditional Crime
Aspect Traditional Crime Computer Crime
Location Physical Virtual / Online
Evidence Physical Digital
Speed Slow Very Fast
Jurisdiction Local Global
Detection Easier Di icult
7. Scope of Computer Crime
Computer crime includes a wide range of o ences such as:
Hacking and unauthorized access
Data theft and manipulation
Online fraud and financial crimes
Identity theft
Cyber stalking and harassment
Malware distribution
The scope continues to expand with technological advancement.
8. Challenges in Defining Computer Crime
Defining computer crime poses several challenges:
Rapidly changing technology
New crime methods emerging frequently
Overlapping traditional and cyber o ences
Lack of uniform global laws
These challenges require continuous updates to cyber laws and investigative
techniques.
9. Legal Recognition of Computer Crime
Most countries have enacted specific cyber laws to define and punish computer
crimes.
In India, the Information Technology Act, 2000 and its amendment in 2008 legally
define and recognize various computer-related o ences such as:
Unauthorized access
Data damage
Identity theft
Online cheating
10. Importance of Recognizing and Defining Computer Crime
Proper recognition and definition of computer crime:
Helps law enforcement agencies investigate e ectively
Assists courts in delivering justice
Protects individuals and organizations
Strengthens national cyber security
[Link] of Cyber Crimes
1. Introduction
Cyber crimes refer to criminal activities committed using computers, digital
devices, or the Internet. As technology advances, cyber crimes have become
more sophisticated, widespread, and di icult to detect. Understanding the
types of cyber crimes helps investigators, policymakers, and legal authorities
take preventive and corrective measures.
Cyber crimes can be broadly classified based on the target of the crime and the
nature of harm caused.
2. Crimes Against Individuals
These cyber crimes directly a ect individuals by violating their privacy, dignity,
or financial security.
2.1 Cyber Stalking
Cyber stalking involves repeatedly harassing or threatening an individual using
electronic communication such as emails, social media, or messaging
platforms. It causes mental stress and fear to victims.
2.2 Identity Theft
Identity theft occurs when personal information such as Aadhaar number, bank
details, passwords, or social media credentials are stolen and misused for
fraudulent purposes.
2.3 Phishing and Email Spoofing
Phishing involves sending fake emails or messages that appear legitimate to
trick users into revealing sensitive information. Email spoofing hides the
sender’s true identity.
2.4 Online Harassment and Cyber Bullying
This includes abusive messages, defamation, spreading false information, or
humiliating content targeting individuals, especially minors.
3. Crimes Against Property
These crimes involve damage to or theft of digital property, financial assets, or
intellectual property.
3.1 Data Theft
Data theft refers to unauthorized copying or extraction of confidential data such
as business records, research data, or customer information.
3.2 Intellectual Property Crimes
These include software piracy, copyright infringement, and illegal distribution of
digital content, causing financial loss to creators.
3.3 Online Financial Fraud
Cyber criminals commit financial fraud using credit cards, online banking
systems, digital wallets, and e-commerce platforms.
3.4 Ransomware Attacks
Ransomware encrypts data and demands payment for its release, often
crippling organizations and institutions.
4. Crimes Against Organizations
Organizations are frequent targets due to their large data volumes and financial
resources.
4.1 Hacking and Unauthorized Access
Hacking involves gaining illegal access to computer systems or networks to
steal, alter, or destroy data.
4.2 Denial of Service (DoS and DDoS) Attacks
These attacks overwhelm systems with tra ic, making services unavailable to
legitimate users.
4.3 Insider Attacks
Employees or trusted insiders misuse access privileges to steal or damage
organizational data.
5. Crimes Against Society
These crimes a ect public order, morality, and social harmony.
5.1 Cyber Terrorism
Cyber terrorism involves attacks on critical infrastructure such as power grids,
transportation systems, or government networks to create fear and instability.
5.2 Spread of Obscene and Illegal Content
Publishing or distributing obscene, child sexual abuse material, or hate content
through digital platforms is a serious cyber o ence.
5.3 Fake News and Misinformation
False information spread online can cause panic, social unrest, or political
manipulation.
6. Crimes Against Government
Cyber crimes targeting governments pose serious national security threats.
6.1 Cyber Espionage
Cyber espionage involves unauthorized access to government systems to steal
classified or sensitive information.
6.2 Attacks on Government Websites
Website defacement, data breaches, and denial of service attacks are
commonly used to disrupt government operations.
7. Emerging and Contemporary Cyber Crimes
With technological advancements, new cyber crimes have emerged:
Cryptocurrency scams
Deepfake crimes
Artificial Intelligence-based frauds
Social engineering attacks
Internet of Things (IoT) attacks
These crimes are complex and di icult to detect.
8. Legal Perspective (Indian Context)
In India, cyber crimes are addressed under the Information Technology Act,
2000 and its 2008 Amendment. Various sections define and penalize o ences
such as identity theft, online cheating, data damage, and cyber terrorism.
9. Importance of Understanding Types of Cyber Crimes
Knowledge of cyber crime types helps:
Law enforcement agencies in investigation
Individuals and organizations in prevention
Governments in framing e ective cyber laws
4. Contemporary Crimes
1. Introduction to Contemporary Cyber Crimes
Contemporary cyber crimes refer to modern and evolving forms of cyber o ences
that have emerged with the rapid advancement of digital technologies such as
cloud computing, social media, artificial intelligence, cryptocurrency, and mobile
Internet.
Unlike traditional cyber crimes, contemporary crimes are highly sophisticated,
organized, and technology-driven, posing serious threats to individuals,
organizations, governments, and national security.
2. Ransomware Attacks
Ransomware is a type of malicious software that encrypts the victim’s data and
demands a ransom for restoring access.
Features:
Data encryption and system lockout
Demand for payment in cryptocurrency
Often targets hospitals, corporations, and government agencies
Ransomware attacks cause severe financial loss and disruption of essential
services.
3. Online Financial Frauds
Online financial frauds have increased significantly with digital banking and online
payment systems.
Examples:
Credit and debit card fraud
Online banking fraud
UPI and mobile wallet scams
Fake investment schemes
These crimes exploit user trust and lack of cybersecurity awareness.
4. Cryptocurrency-Related Crimes
The rise of cryptocurrencies has introduced new cyber crime opportunities.
Common crypto crimes:
Crypto investment scams
Money laundering using digital currencies
Crypto mining malware
Theft from digital wallets and exchanges
The anonymity of cryptocurrencies makes investigation challenging.
5. Deepfake Crimes
Deepfake technology uses Artificial Intelligence (AI) to create fake but realistic
audio, video, or images.
Misuse includes:
Fake videos for blackmail
Political misinformation
Impersonation fraud
Deepfake crimes pose serious threats to privacy, reputation, and democracy.
6. Social Engineering Attacks
Social engineering exploits human psychology rather than technical
vulnerabilities.
Common techniques:
Phishing
Vishing (voice phishing)
Smishing (SMS phishing)
Pretexting
These attacks trick victims into revealing confidential information.
7. Cyber Stalking and Online Harassment
With the expansion of social media platforms, cyber stalking and online
harassment have increased.
Victims face:
Emotional distress
Reputational damage
Threats and intimidation
Such crimes particularly a ect women and minors.
8. Internet of Things (IoT) Based Crimes
IoT devices such as smart cameras, wearables, and home automation systems are
vulnerable to cyber attacks.
IoT crimes include:
Unauthorized surveillance
Device hijacking
Botnet creation
Poor security standards make IoT devices easy targets.
9. Cloud Computing Crimes
Cloud-based services store large volumes of sensitive data.
Crimes include:
Data breaches
Unauthorized cloud access
Insider threats
Cloud crimes can impact millions of users simultaneously.
10. Cyber Terrorism
Cyber terrorism involves using digital attacks to create fear, panic, or disruption at
a national or international level.
Targets include:
Power grids
Transportation systems
Government networks
Cyber terrorism threatens national security and public safety.
11. Legal Perspective on Contemporary Cyber Crimes (India)
In India, contemporary cyber crimes are addressed under:
Information Technology Act, 2000
IT (Amendment) Act, 2008
Indian Penal Code (relevant sections)
New policies and cybersecurity frameworks continue to evolve to address
emerging threats.
12. Challenges in Combating Contemporary Cyber Crimes
Rapid technological evolution
Cross-border jurisdiction issues
Anonymity of o enders
Lack of cyber awareness
These challenges require international cooperation and continuous legal updates.
13. Conclusion
Contemporary cyber crimes represent a significant challenge in the digital age.
Their complexity, scale, and impact demand advanced technological solutions,
robust legal frameworks, and increased public awareness to ensure cyber safety.
5. Computers as Targets
1. Introduction
In cyber crimes, computers can play di erent roles such as targets, tools, or
contaminants. When computers themselves are attacked to disrupt their
functioning, steal data, or cause damage, they are referred to as computers as
targets.
In this category, the primary objective of the criminal is to attack the computer
system, network, or data stored within it. Such attacks can a ect individuals,
organizations, and governments.
2. Meaning of Computers as Targets
Computers as targets refers to cyber crimes in which computer systems,
networks, or digital data are the direct victims of the o ence. The intention is to:
Gain unauthorized access
Damage or destroy data
Disrupt services
Compromise system security
These crimes attack the confidentiality, integrity, and availability of computer
systems.
3. Common Cyber Crimes Where Computers Are Targets
3.1 Hacking and Unauthorized Access
Hacking involves illegally accessing a computer system or network without
permission. Hackers may steal data, modify files, or disable systems.
Impact:
Loss of sensitive information
System malfunction
Legal and financial consequences
3.2 Malware Attacks
Malware refers to malicious software designed to damage or disrupt computer
systems.
Types of malware include:
Viruses
Worms
Trojans
Spyware
Ransomware
Malware can corrupt files, steal information, or completely shut down systems.
3.3 Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks
DoS and DDoS attacks aim to overload computer systems or servers, making
them unavailable to legitimate users.
Targets often include:
Websites
Online services
Banking and e-commerce platforms
3.4 Website Defacement
Website defacement involves unauthorized modification of a website’s content,
often replacing it with o ensive or misleading messages.
This a ects the credibility and reputation of organizations and government
agencies.
3.5 Data Destruction and Data Corruption
Attackers intentionally delete, alter, or corrupt data stored in computer
systems.
Examples:
Logic bombs
Data wiping attacks
Unauthorized file modification
Such acts can cause irreversible damage to organizations.
3.6 Ransomware Attacks
Ransomware targets computer systems by encrypting data and demanding
payment for its release.
These attacks often cripple critical systems such as hospitals, educational
institutions, and government o ices.
4. Impact of Targeting Computers
When computers are targeted, the consequences may include:
Financial loss
Loss of confidential data
Disruption of essential services
Damage to reputation
Legal liability
In critical infrastructure systems, such attacks can endanger public safety.
5. Legal Perspective (Indian Context)
In India, cyber crimes targeting computers are punishable under the
Information Technology Act, 2000 and its 2008 Amendment.
Relevant sections include:
Section 43 – Damage to computer systems
Section 65 – Tampering with computer source documents
Section 66 – Computer-related o ences
Section 66F – Cyber terrorism
6. Importance of Understanding Computers as Targets
Understanding computers as targets helps:
Law enforcement agencies identify attack patterns
Organizations strengthen cybersecurity measures
Courts assess technical evidence accurately
It also aids in developing e ective cyber security policies and laws.
7. Conclusion
When computers are treated as targets in cyber crimes, the attacks directly
threaten digital infrastructure and information security. With increasing
dependence on technology, protecting computer systems from targeted attacks
has become a critical priority for individuals, organizations, and governments.
[Link] and Destruction of Data
1. Introduction
In the digital age, data is one of the most valuable assets for individuals,
organizations, and governments. Cyber criminals often target data either by
contaminating it with malicious elements or by destroying it completely. Such acts
compromise the confidentiality, integrity, and availability of information systems.
Contaminants and destruction of data are serious cyber o ences because they can
cause irreversible damage, financial loss, and disruption of critical services.
2. Meaning of Data Contaminants
Data contaminants refer to malicious programs, codes, or actions that
intentionally infect, alter, corrupt, or manipulate data stored in a computer system
or network.
The primary purpose of data contamination is to:
Disrupt normal functioning of systems
Corrupt or manipulate information
Gain unauthorized control over data
Spread infection to other systems
3. Types of Data Contaminants
3.1 Computer Viruses
A computer virus is a malicious program that attaches itself to legitimate files and
spreads when the infected file is executed.
E ects:
Corruption or deletion of data
Slow system performance
System crashes
3.2 Worms
Worms are self-replicating programs that spread automatically through networks
without user intervention.
Impact:
Network congestion
Data corruption
System overload
3.3 Trojan Horses
Trojan horses appear as legitimate software but perform hidden malicious actions.
They may:
Create backdoors
Steal data
Allow remote access to attackers
3.4 Logic Bombs
Logic bombs are malicious codes that remain dormant until a specific condition or
time is met.
Once activated, they may:
Delete files
Corrupt databases
Disable systems
3.5 Spyware and Adware
Spyware secretly monitors user activity and collects sensitive information, while
adware injects unwanted advertisements.
These contaminants compromise user privacy and data security.
4. Destruction of Data
Destruction of data refers to intentional deletion, alteration, or rendering data
unusable, making it inaccessible or permanently lost.
Unlike contamination, data destruction focuses on eliminating information rather
than infecting it.
5. Methods of Data Destruction
5.1 Unauthorized Deletion of Data
Attackers may delete important files, databases, or backups, causing operational
failure.
5.2 Data Wiping and Overwriting
Data wiping involves overwriting stored data so that it cannot be recovered using
forensic tools.
5.3 Ransomware-Based Destruction
In some cases, ransomware permanently deletes or damages data if ransom
demands are not met.
5.4 Insider Attacks
Employees or insiders with authorized access may intentionally destroy or
manipulate data due to revenge, greed, or negligence.
6. Impact of Data Contamination and Destruction
The consequences include:
Financial loss
Loss of critical and confidential information
Disruption of business and government services
Damage to reputation
Legal and regulatory penalties
In sectors like healthcare, banking, and defense, such attacks can threaten human
safety and national security.
7. Legal Perspective (Indian Context)
In India, o ences related to data contamination and destruction are punishable
under the Information Technology Act, 2000 and IT (Amendment) Act, 2008.
Relevant sections include:
Section 43 – Damage to computer, computer system, or data
Section 65 – Tampering with computer source documents
Section 66 – Computer-related o ences
Section 66F – Cyber terrorism (in severe cases)
8. Role of Digital Forensics
Digital forensics helps in:
Identifying malware and contaminants
Recovering damaged or deleted data
Tracing the source of attacks
Presenting electronic evidence in courts
Forensic analysis is essential for investigation and prosecution of such crimes.
9. Prevention and Control Measures
Regular data backups
Use of antivirus and anti-malware tools
Strong access control policies
Cyber security awareness training
Regular system updates and patching
10. Conclusion
Contaminants and destruction of data represent serious cyber threats in modern
digital systems. As dependence on digital data continues to grow, protecting
information from malicious contamination and intentional destruction has become
a critical responsibility for individuals, organizations, and governments
6. Indian IT ACT - 2000
1. Introduction to the Information Technology Act, 2000
The Information Technology Act, 2000 (IT Act, 2000) is the primary law in India
dealing with cyber activities, electronic governance, and cyber crimes. It was
enacted by the Indian Parliament and came into force on 17th October 2000.
The Act was introduced to provide legal recognition to electronic transactions,
facilitate e-commerce, and address the growing menace of cyber crimes arising
from the use of computers and the Internet.
2. Objectives of the IT Act, 2000
The main objectives of the IT Act, 2000 are:
To give legal recognition to electronic records and digital signatures
To facilitate electronic filing of documents with government agencies
To promote e-commerce and e-governance
To define and punish cyber crimes
To ensure security of electronic data and computer systems
3. Scope and Applicability of the Act
The IT Act, 2000 applies to:
The whole of India
O ences or contraventions committed outside India involving computer
systems located in India
The Act covers activities involving:
Computers
Computer systems and networks
Electronic data and communication
4. Legal Recognition of Electronic Records and Digital Signatures
One of the most significant contributions of the IT Act is granting legal
recognition to electronic records and digital signatures.
This ensures that:
Electronic documents are legally valid
Digital signatures can be used for authentication
Online contracts are enforceable by law
5. Cyber Crimes Under the IT Act, 2000
The IT Act defines several cyber o ences and prescribes penalties and
punishments.
5.1 Section 43 – Damage to Computer Systems
Section 43 deals with unauthorized access, downloading, introduction of
viruses, data damage, and disruption of computer systems.
Penalty: Compensation payable to the a ected person.
5.2 Section 65 – Tampering with Computer Source Documents
This section punishes intentional concealment, destruction, or alteration of
computer source code.
Punishment:
Imprisonment up to 3 years
Or fine
Or both
5.3 Section 66 – Computer-Related O ences
Section 66 applies when acts under Section 43 are committed dishonestly or
fraudulently.
Punishment:
Imprisonment up to 3 years
Or fine up to ₹5 lakh
Or both
5.4 Section 67 – Publishing Obscene Electronic Content
This section deals with publishing or transmitting obscene material in
electronic form.
Punishment:
First conviction: Imprisonment up to 3 years and fine
Subsequent conviction: Higher imprisonment and fine
6. Adjudication and Appellate Authorities
The Act provides for:
Appointment of Adjudicating O icers to handle cyber o ence cases
Establishment of a Cyber Appellate Tribunal for appeals
These mechanisms ensure speedy justice in cyber-related matters.
7. Powers of Authorities Under the Act
The IT Act empowers government authorities to:
Intercept, monitor, and decrypt information (Section 69)
Search and arrest without warrant (Section 80)
These powers are exercised in the interest of national security and public order.
8. Importance of IT Act, 2000 in Cyber Crime Control
The IT Act plays a crucial role in:
Deterring cyber criminals
Protecting digital infrastructure
Providing legal remedies to victims
Supporting digital forensics investigations
It laid the foundation for modern cyber law in India.
9. Limitations of the IT Act, 2000
Some limitations include:
Inadequate provisions for emerging cyber crimes
Lack of clarity in certain sections
Rapid technological changes outpacing the law
These limitations led to the amendment of the Act in 2008.
10. Conclusion
The Information Technology Act, 2000 marked a significant milestone in India’s
journey towards a secure digital society. It provided the legal framework
necessary to recognize electronic transactions and combat cyber crimes.
Despite its limitations, the Act remains the backbone of cyber law in India.
7. Indian IT Act 2008 and amendments.
1. Introduction
The Information Technology (Amendment) Act, 2008 was enacted to address the
shortcomings of the original IT Act, 2000 and to deal with emerging and
sophisticated cyber crimes resulting from rapid technological advancement.
The Amendment Act came into force on 27th October 2009. It strengthened
India’s cyber law framework by introducing new o ences, enhanced
punishments, data protection provisions, and national security measures.
2. Need for IT Act Amendment, 2008
The IT Act, 2000 was inadequate to handle:
Social media crimes
Identity theft and phishing
Cyber terrorism
Data protection and privacy issues
Online harassment and child pornography
Therefore, the 2008 amendment was introduced to modernize cyber law in line
with global standards.
3. Major Amendments Introduced in IT Act, 2008
3.1 Introduction of New Cyber Crimes
The amendment added several new o ences, making the law more
comprehensive and e ective.
3.2 Section 43A – Data Protection and Compensation
Section 43A deals with compensation for failure to protect sensitive personal
data.
Organizations handling sensitive data must maintain reasonable security
practices.
Penalty:
Compensation to a ected persons for negligence
3.3 Section 66 – Computer-Related O ences (Expanded)
Section 66 was expanded into multiple sub-sections to address specific crimes.
3.4 Section 66A – Sending O ensive Messages (Now Struck Down)
This section criminalized sending o ensive or menacing messages through
electronic communication.
Struck down by the Supreme Court in 2015 (Shreya Singhal vs Union of India)
for violating freedom of speech.
3.5 Section 66B – Dishonestly Receiving Stolen Computer Resource
Punishment:
Imprisonment up to 3 years
Or fine up to ₹1 lakh
Or both
3.6 Section 66C – Identity Theft
Covers fraudulent use of another person’s:
Password
Digital signature
Unique identification data
Punishment:
Imprisonment up to 3 years
Fine up to ₹1 lakh
3.7 Section 66D – Cheating by Personation Using Computer Resource
Covers online frauds such as phishing and impersonation.
Punishment:
Imprisonment up to 3 years
Fine up to ₹1 lakh
3.8 Section 66E – Violation of Privacy
Punishes capturing, publishing, or transmitting images of private areas without
consent.
Punishment:
Imprisonment up to 3 years
Fine up to ₹2 lakh
3.9 Section 66F – Cyber Terrorism
Defines cyber terrorism as acts threatening national security, sovereignty, or
public order.
Punishment:
Imprisonment for life
4. Amendments Related to Obscene Content
4.1 Section 67A – Sexually Explicit Content
Punishes publishing or transmitting sexually explicit material in electronic
form.
4.2 Section 67B – Child Sexual Abuse Material (CSAM)
Deals with child pornography and online child exploitation.
Punishment includes:
Imprisonment
Heavy fines
5. Intermediary Liability – Section 79
This section provides safe harbor protection to intermediaries like ISPs and
social media platforms, subject to due diligence.
Intermediaries must remove unlawful content upon receiving notice.
6. Government Powers Under IT Act, 2008
Section 69 – Interception, monitoring, and decryption of information
Section 69A – Blocking of public access to information
Section 69B – Monitoring of network tra ic
These powers are exercised for national security and public safety.
7. Impact of IT Act 2008 on Cyber Crime Control
Stronger punishment provisions
Recognition of modern cyber o ences
Enhanced privacy and data protection
Improved investigation and prosecution
The amendment significantly strengthened India’s cyber crime control
mechanism.
8. Criticism and Limitations
Section 66A misuse (before being struck down)
Concerns regarding privacy and surveillance
Need for continuous updates due to evolving technology
9. Conclusion
The Information Technology (Amendment) Act, 2008 marked a major
advancement in India’s cyber law regime. By addressing emerging cyber crimes,
strengthening data protection, and enhancing national security provisions, the
Act plays a crucial role in combating cyber crimes in the digital era.