CYBER CRIME, CYBER LAW AND IPR
CHAPTER-1
Cybercrime & cyber laws
Identify types of cyber crimes
Prepare checklist for reporting cyber-crime at Cybercrime Police Station.
Prepare checklist for reporting cyber-crime online.
Identify phishing emails
Analyze cybercrime cases and identify section applicable ( as per IT Act)
Discuss Data protection laws in India
What is a cyber crime?
The crimes that involves criminal activities done through cyber space by the devices connected
to the internet is called a cyber crime.
What is cyber space?
Cyberspace is the virtual environment that consists of computer systems and networks, where
all the computers communicate via networks and all networks are connected.
What is a Cyber Attack?
An offensive action by a malicious actor that is intended to undermine the functions of
networked computers and their related resources, including unauthorized access, unapproved
changes, and malicious destruction.
Examples of cyber attacks include Distributed Denial of Service (DDoS) and Man- in-the-
Middle (MITM) attacks.
What is cyber hygiene?
Cyber is a colloquial term that refers to best practices and other activities that computer system
administrators and users can undertake to improve their cyber security while engaging in
common online activities, such as web browsing, emailing, texting, etc
What is cyber threat?
cyber threat is the possibility that a particular attack may occur.
What is cyber risk?
The risk associated with the subject threat estimates the probability of potential losses that may
result.
What is a computer crime?
The crimes that involves the use of a computer is called a computer crime. It includes theft and
hacking.
What is a cyber crime?
The crimes that are committed over the internet is called a computer crime. It includes online
frauds, phishing etc.
What is malware?
Malware is an umbrella term derived from "malicious software", and refers to any software that
is intrusive (unauthorized access), disruptive, or destructive to computer systems and networks.
Malware may take many forms (executable code, data files) and includes, but is not limited to,
computer viruses, worms, trojan horses (trojans), bots (botnets), spyware (system monitors,
adware, tracking cookies), rogueware (scareware, ransomware), and other malicious programs.
The majority of active malware threats are usually worms or trojans rather than viruses.
What is a firewall?
A firewall is a network security system that monitors incoming and outgoing network message
traffic and prevents the transmission of malicious messages based on an updatable rule set.
How does a firewall work?
Firewalls function as a filter between a trusted, secure internal network and external networks
(e.g., the Internet) that are assumed to be untrustworthy and non-secure.
The firewall filter may be flexibly programmed to control what information packets are
allowed and blocked.
What is anti-virus software?
Anti-virus software, also known as, anti-malware software, is computer software used to scan
files to identify and eliminate malicious software (malware).
Although anti-virus software was originally developed to detect and remove computer viruses
(hence its name), it has been broadened in scope to detect other malware, such as worms,
Trojan horses, adware, spyware, ransomware, etc.
What is the relation between cybersecurity and cryptography?
Cyber security defenses are typically based on strong authentication and encryption
techniques(cryptography techniques), cryptography is a key enabling technology for
cybersecurity. In other words, cryptography helps to implement cyber security.
What are SQL Injections?
It is a cyber crime which occurs when hackers insert malicious code in the server using
Structured Query Language code to make the server reveal sensitive data.
Define Denial-of-Service (DOS)?
A Denial-of-Service (DoS) attack is cybercrime that floods a machine or network
with false requests in order to disrupt business operations. In a DoS attack, users are
unable to perform routine and necessary tasks, such as accessing email, websites,
online accounts or other resources that are operated by a compromised computer or
network.
Define Distrubuted Denial-of-Service(DDOS)?
DDoS Attack means "Distributed Denial-of-Service (DDoS) Attack" and it is a cybercrime in
which the attacker floods a server with internet traffic to prevent users from accessing
connected online services and sites.
Define Ransomware?
Ransomware is a type of malware attack in which the attacker locks and encrypts the
victim’s data, important files and then demands a payment to unlock and decrypt the data.
This type of attack takes advantage of human, system, network, and software vulnerabilities to
infect the victim’s device—which can be a computer, printer, smartphone, wearable, point-of-
sale (POS) terminal, or other endpoint.
What is cyber Stalking?
Cyberstalking is a crime committed when someone uses the internet and other technologies to
harass or stalk another person online. Even though cyberstalking is a broad term for online
harassment, it can include defamation, false accusations, teasing, and even extreme threats.
What is Cyberbullying?
Cyberbullying is when someone uses technology to harass, threaten, embarrass, or target
another person. It happens on devices like smartphones, computers, tablets, and gaming
systems. Cyberbullying hurts people, and in some cases is against the law.
What is Phishing?
Phishing is a common type of cyber attack that targets individuals through email, text messages,
phone calls, and other forms of communication. A phishing attack aims to trick the recipient
into falling for the attacker’s desired action, such as revealing financial information, system
login credentials, or other sensitive information.
What is cybersquatting ?
cybersquatting is the act of buying or registering domain names with the specific
intent of profiting off a trademark owned by another person.
What is Website Defacement?
Defacement (also website or web defacement) is an attack on a website that alters its visual
appearance or informational content.
What is Man-In-The-Middle -Attack?
A man-in-the-middle (MiTM) attack is a type of cyber attack in which the attacker secretly
intercepts and relays messages between two parties who believe they are communicating
directly with each other. The attack is a type of eavesdropping in which the attacker intercepts
and then controls the entire conversation.
What is Spamming?
Spamming is the act of sending unsolicited messages, often with commercial or malicious
purposes, to a large number of people.
What is Identity theft?
Identity Theft also called Identity Fraud is a crime that is being committed by a huge
number nowadays. Identity theft happens when someone steals your personal
information to commit fraud.
What is cyber forensics?
cyber forensics is the application of investigating and analysis technique to gather and
preserve evidence.
What is a worm?
A worm is a type of malware that can replicate and spread across devices within a
network. Worms can consume bandwidth, overload infected systems, and make them
unreliable or unavailable. They can also change and delete files or introduce other
malware.
What is a Virus?
A computer virus is a type of malicious software, or malware, that spreads between computers
and causes damage to data and software.
Why do cyber attacks happen?
[Link] gain
[Link] and revenge
[Link]
What is the difference between the virus and worm?
Define cyber Law?
Cyber law is fundamentally the branch of law that deals with legal issues related to the use
of information technology. It essentially encompasses laws relating to electronic and digital
signatures, cybercrime, cybersecurity, intellectual property, data protection and privacy.
What is jurisprudence?
Cyber jurisprudence is the legal study that concentrates on the logical structure, the
meaning and uses of the concepts, the formal terms and modes of cyber law.
What is Cyber Terrorism ?
Cyber terrorism is the use of the computer and internet to perform violent acts that result in
loss of life. This may include different type of activities either by software or hardware for
threatening life of citizens.
In general, Cyber terrorism can be defined as an act of terrorism committed through the use
of cyberspace or computer resources.
What is Cyber Extortion ?
Cyber extortion occurs when a website, e-mail server or computer system is subjected to or
threatened with repeated denial of service or other attacks by malicious hackers. These
hackers demand huge money in return for assurance to stop the attacks and to offer
protection.
What is Cyber Warfare?
The cyber attack that targets a country for the unauthorized use of the information or data is
called cyber warfare.
What is Internet Fraud ?
Internet fraud is a type of fraud or deceit which makes use of the Internet and could
include hiding of information or providing incorrect information for the purpose of
deceiving victims for money or property. Internet fraud is not considered a single,
distinctive crime but covers a range of illegal and illicit actions that are committed in
cyberspace.
What is the difference between DOS and DDOS?
What are the different types of cyber crimes?
1. Child Pornography OR Child sexually abusive material (CSAM)
2. Cyber Bullying
3. Cyber Stalking
4. Cyber Grooming
5. Online Job Fraud
6. Online Sextortion
7. Phishing
8. Vishing
9. Smishing
10. Sexting
11. SIM Swap Scam
12. Credit Card Fraud or Debit Card Fraud
13. Impersonation and identity theft
14Spamming
15. Ransomware
16. Viruses, Worms, and Trojans
17. Data Breach
18. Denial of Services (DoS) attack
19. Website Defacement
20. Cyber-Squatting
21. Pharming
22. Cryptojacking
23. Online Drug Trafficking
24. Espionage
Child Pornography or Child Sexually Abusive Material (CSAM): Illegal and explicit
images or videos involving minors, exploiting their sexual content.
Cyber Bullying: Harassment, threats, or intimidation of individuals through digital means,
often causing emotional distress.
Cyber Stalking: Persistent online harassment and monitoring of an individual, causing fear
and invasion of privacy.
Cyber Grooming: Online manipulation and persuasion by adults to exploit or sexually
abuse minors.
Online Job Fraud: Deceptive online schemes offering fake job opportunities to scam
money from job seekers.
Online Sextortion: Extortion involving threatening to release explicit photos or information
unless the victim complies with demands.
Phishing: Deceptive online tactics to trick individuals into revealing personal information,
such as passwords or credit card details or Phishing attacks are extremely common and
involve sending mass amounts of fraudulent emails to unsuspecting users, disguised as
coming from a reliable source. There are several different types of phishing attacks,
including:
• Spear Phishing—targeted attacks directed at specific companies and/or individuals. •
Whaling—attacks targeting senior executives and stakeholders within an organization. •
Pharming—leverages DNS cache poisoning to capture user credentials through a fake login
landing page.
Vishing: Voice-based phishing, where scammers use phone calls to deceive victims into
divulging sensitive information.
Smishing: Phishing conducted via SMS or text messages, aiming to trick recipients into
revealing personal information.
Sexting: Sending explicit texts, images, or videos of a sexual nature via electronic
communication.
SIM Swap Scam: Unauthorized transfer of a victim's phone number to a different SIM card
for fraudulent activities.
SIMS Credit Card Fraud or Debit Card Fraud: Illegitimate use of credit or debit card
information to make unauthorized transactions.
Impersonation and Identity Theft: Assuming another person's identity for fraudulent
purposes, often involving financial fraud.
Spamming: Sending unsolicited and often irrelevant messages or content in bulk through
various online channels.
Ransomware: Malicious software that encrypts data and demands a ransom for its release.
Viruses, Worms, and Trojans: Malicious software designed to harm or compromise
computer systems, each with distinct methods.
Data Breach: Unauthorized access, exposure, or theft of sensitive or confidential data from
a secure system or database.
Denial of Service (DoS) Attack: Deliberate disruption of online services by overwhelming
them with excessive traffic or requests.
Website Defacement: Unauthorized alteration of a website's content, often to convey a
message or cause damage.
Cyber-Squatting: Registering domain names similar to established brands with the intent to
profit or deceive. Pharming: Redirecting website traffic to fraudulent sites to steal personal
information, often through DNS manipulation.
Cryptojacking: Illegally using a victim's computer or device to mine cryptocurrency
without their consent.
Online Drug Trafficking: Illicit sale and distribution of drugs through online platforms and
the dark web.
Espionage: Covert activities involving the theft of sensitive information or state secrets,
often conducted by governments or hackers.
Challenges of Cyber Crime:
1. People are unaware of their cyber rights-
The Cybercrime usually happen with illiterate people around the world who are unaware
about their cyber rights implemented by the government of that particular country.
2. Anonymity-
Those who Commit cybercrime are anonymous for us so we cannot do anything to that
person.
3. Less numbers of case registered-
Every country in the world faces the challenge of cybercrime and the rate of cybercrime is
increasing day by day because the people who even don’t register a case of cybercrime and
this is major challenge for us as well as for authorities as well.
4. Mostly committed by well educated people-
Committing a cybercrime is not a cup of tea for every individual. The person who commits
cybercrime is a very technical person so he knows how to commit the crime and not get
caught by the authorities.
5. No harsh punishment
In Cybercrime there is no harsh punishment in every case. But there is harsh punishment in
some cases like when somebody commits cyber terrorism in that case there is harsh
punishment for that individual. But in other cases there is no harsh punishment so this
factor also gives encouragement to that person who commits cybercrime.
What is Identity Theft? Explain with an example?
Identity Theft also called Identity Fraud is a crime that is being committed by a huge
number nowadays. Identity theft happens when someone steals your personal information
to commit fraud. This theft is committed in many ways by gathering personal information
such as transactional information of another person to make transactions.
Example: Thieves use different mechanisms to extract information about customers’ credit
cards from corporate databases, once they are aware of the information they can easily
degrade the rating of the victim’s credit card. Having this information with the thieves can
make you cause huge harm if not notified early. With these false credentials, they can obtain a
credit card in the name of the victim which can be used for covering false debts.
Types of Identity Thefts:
There are various amount of threats but some common ones are :
Criminal Identity Theft – This is a type of theft in which the victim is charged guilty and
has to bear the loss when the criminal or the thief backs up his position with the false
documents of the victim such as ID or other verification documents and his bluff is
successful.
Senior Identity Theft – Seniors with age over 60 are often targets of identity thieves.
They are sent information that looks to be actual and then their personal information is
gathered for such use. Seniors must be aware of not being the victim.
Driver’s license ID Identity Theft – Driver’s license identity theft is the most common
form of ID theft. All the information on one’s driver’s license provides the name, address,
and date of birth, as well as a State driver’s identity number. The thieves use this
information to apply for loans or credit cards or try to open bank accounts to obtain
checking accounts or buy cars, houses, vehicles, electronic equipment, jewelry, anything
valuable and all are charged to the owner’s name.
Medical Identity Theft – In this theft, the victim’s health-related information is gathered
and then a fraud medical service need is created with fraud bills, which then results in the
victim’s account for such services.
Tax Identity Theft – In this type of attack attacker is interested in knowing your Employer
Identification Number to appeal to get a tax refund. This is noticeable when you attempt to
file your tax return or the Income Tax return department sends you a notice for this.
Social Security Identity Theft – In this type of attack the thief intends to know your
Social Security Number (SSN). With this number, they are also aware of all your personal
information which is the biggest threat to an individual.
Synthetic Identity Theft – This theft is uncommon to the other thefts, thief combines all
the gathered information of people and they create a new identity. When this identity is
being used than all the victims are affected.
Financial Identity Theft – This type of attack is the most common type of attack. In this,
the stolen credentials are used to attain a financial benefit. The victim is identified only
when he checks his balances carefully as this is practiced in a very slow manner.
Techniques of Identity Thefts : Identity thieves usually hack into corporate databases for
personal credentials which requires effort but with several social-engineering techniques, it is
considered easy. Some common identity theft techniques are:
Pretext Calling – Thieves pretending to be an employee of a company over phone asking
for financial information are an example of this theft. Pretending as legitimate employees
they ask for personal data with some buttery returns.
Mail Theft – This is a technique in which credit card information with transactional data is
extracted from the public mailbox.
Phishing – This is a technique in which emails pertaining to be from banks are sent to a
victim with malware in it. When the victim responds to mail their information is mapped
by the thieves.
Internet – Internet is widely used by the world as attackers are aware of many techniques
of making users get connected with public networks over Internet which is controlled by
them and they add spyware with downloads.
Dumpster Diving – This is a technique that has made much information out of the known
institutions. As garbage collectors are aware of this they search for account related
documents that contain social security numbers with all the personal documents if not
shredded before disposing of.
Card Verification Value (CVV) Code Requests – The Card Verification Value number is
located at the back of your debit cards. This number is used to enhance transaction security
but several attackers ask for this number while pretending as a bank official.
Steps Of Prevention From Identity Theft:
Following are some methods by which you can enhance your security for identity thefts :
1. Use Strong Passwords and do not share your PIN with anyone on or off the phone.
2. Use two-factor notification for emails.
3. Secure all your devices with a password.
4. Don’t install random software from the internet.
5. Don’t post sensitive information over social media.
6. While entering passwords at payment gateway ensure its authenticity.
7. Limit the personal information to be carried with out.
8. Keep a practice of changing your PIN and password regularly.
9. Never share your Aadhaar/PAN number (In India) with anyone whom you do not
know/trust.
[Link] not make all the personal information on your social media accounts public.
[Link] never share an Aadhaar OTP received on your phone with someone over a call.
[Link] sure that you do not receive unnecessary OTP SMS about Aadhaar (if you do, your
Aadhaar number is already in the wrong hands).
[Link] not fill personal data on the website that claims to offer benefits in return.
How are cybercrimes classified with examples?
(or)
What are the categories of cybercrime?
cybercrimes can be classified under three heads, depending on the groups they are targeted
at.
1. Cybercrime against Individual: This category includes a variety of cybercrimes
carried out against a single person.
▪Examples: cyberstalking, Identity theft and child pornography.
2. Cybercrime Against Property : This category includes variety of cybercrimes
against the property of the individual for the profit.
Examples: Credit card fraud, Intellectual property issues, phishing.
3. Cybercrime Against Organization :
▪ Unauthorized Accessing of Computer: Accessing the computer/network without
permission from the owner.
It can be of 2 forms: a) Changing/deleting data: Unauthorized changing of data. b)
Computer voyeur: The criminal reads or copies confidential or proprietary information, but
the data is neither deleted nor changed.
Examples:
▪ Denial Of service: When Internet server is flooded with continuous bogus requests so as
to denying legitimate users to use the server or to crash the server.
▪ Computer contamination / Virus attack: A computer virus is a computer program that
can infect other computer programs by modifying them in such a way as to include a
(possibly evolved) copy of it. Viruses can be file infecting or affecting boot sector of the
computer. Worms, unlike viruses do not need the host to attach themselves to.
▪ Email Bombing: Sending large numbers of mails to the individual or company or mail
servers thereby ultimately resulting into crashing.
▪ Salami Attack: When negligible amounts are removed & accumulated in to something
larger. These attacks are used for the commission of financial crimes.
▪ Logic Bomb: It is an event dependent program. As soon as the designated event occurs, it
crashes the computer, release a virus or any other harmful possibilities.
▪ Trojan Horse: This is an unauthorized program which functions from inside what seems
to be an authorized program, thereby concealing what it is actually doing.
▪ Data diddling: This kind of an attack involves altering raw data just before it is processed
by a computer and then changing it back after the processing is completed.
4. Cyber crime Against Society
▪ Forgery: Currency notes, revenue stamps, mark sheets etc. can be forged using computers
and high quality scanners and printers.
▪ Cyber Terrorism: Use of computer resources to intimidate or coerce people and carry out
the activities of terrorism.
▪ WebJacking : Hackers gain access and control over the website of another, even they
change the content of website for fulfilling political objective or for money
How to identify cyberattack?
What Signs Do I Look For?
Here are some signs that your email account has been hacked. Look for the following:
Your password has changed
There’s unusual inbox activity (check sent mail, read messages, no incoming emails)
You’ve received password reset emails from other sites
Account access from unexpected IP address/s (your email provider usually records
this information) has occurred
Your email contacts (whether within or outside of your business) let you know that
they have received strange emails from you
How Did This Happen?
Email hacks usually occur by one of the following methods of attack:
A password hack or brute force cyber attack
Social engineering
Phishing email
2. System Account Details Are Compromised
What Signs Do I Look For?
Your computer speed has slowed down significantly
Your security software has been disabled or compromised
Software or browser add-ons appear that you don’t recognize
Additional pop-ups are happening
Random shutdowns and restarts are happening
You’ve lost access to your account
How Did This Happen?
Your email was hacked/compromised and used to access another account
Phishing
Password hack
Man In The Middle attack
3. My Online Storage Account Was Hacked
What Signs Do I Look For?
Some examples of online storage accounts include Drop Box, Google Drive, OneDrive, and
iCloud.
Your site suddenly has content that shouldn’t be there
You cannot access your account
Files are missing/altered
There’s unusual outbound network traffic
You’re being notified of unexpected access locations and logins
A large number of requests for the same object/file have been received
Suspicious admin activity (see the previous attack)
Excessive read operations (someone is trying to gather data)
Contacts are receiving emails with files/links to open (make sure they don’t open
them!)
How Did This Happen?
System account was compromised
Phishing
Social engineering cyber attack
4)Email Demand
What Signs Do I Look For?
An email stating that they have incriminating evidence on you (this may or may not be
a bluff)
An email may claim they have accessed your password through a keylogger
They threaten to expose you to your contacts
They make a demand for payment (most likely in Bitcoin)
How Did This Happen?
Phishing attack
Ransomware download
Your account was involved in another data breach.
5. My Social Media Has Been Hacked
What Signs Do I Look For?
Changes to your follower count
Friend or contact requests you didn’t make
Duplicate accounts requesting your friends/contacts
Posts that you did not make
Old posts suddenly deleted
Password has been changed
Notification that your account was accessed from a new location/device
How Did This Happen?
Phishing email appearing to be from Facebook/other social media website
Sneaky social media apps
Malicious link within Facebook/Twitter
6. Our Network Has Been Attacked
What Signs Do I Look For?
Your files and/or server has been encrypted
Network becomes very sluggish/slow
Your data usage is unusually high
Programs are continually crashing
You received a ransomware message
Computers are functioning without local input
How Did This Happen?
Ransomware
Malware attack via phishing
Physical access
7. There’s Been a Fraudulent Financial Transaction
What Signs Do I Look For?
Money has been transferred to the wrong account
Account deductions that you didn’t authorize
Suspiciously large orders that don’t match usual order activity
Unexpected invoices that have not been verified
Large payments not arriving despite remuneration advice
Advice to change address or bank details without the appropriate cross-checks
How Did This Happen?
High ranking accounts compromised ― submitting payment requests to the accounts
department. An example of this is hackers posing as the director, requesting accounts
to submit a payment to X account
Man in the Middle (posed as a financial institution)
Invoice details were changed through a compromised system account (eg Xero,
MYOB account, or accounting system login)
8. We Got Infected With A Malware Cyber Attack
What Signs Do I Look For?
Excessively slow computer processing
Programs opening and closing automatically
Lack of storage space
New programs/add-ons that you did not install
Security software disabled
Excessive popups
Browser keeps redirecting sites
How Did This Happen?
Phishing
Opening or executing a malicious file (either by email or removable media)
Insufficient firewall protection
9. I Received a Suspicious Phone Call
What Signs Do I Look For?
You’re being offered money or a free product that you didn’t enter to win (reminder:
if it seems too good to be true, it usually is)
Any call that claims to have detected viruses or infections on your computer
Calls that claim you owe taxes or other government payments
If the caller deflects or refuses to answer your questions
The caller is pushing you to make an immediate financial decision
The caller is threatening deportation or arrest
How Did This Happen?
You submitted information somewhere that sold your information to a third-party
You recently signed up for a service or website
Social media ― your profile may be too public, and scammers used public
information against you
What is malware and what are the types of malware?
▪ Malware attacks are any type of malicious software designed to cause harm or damage to a
computer, server, client or computer network and/or infrastructure without end-user
knowledge
▪ Cyber attackers create, use and sell malware for many different reasons, but it is most
frequently used to steal personal, financial or business information.
Types of Malware:
1. Adware: Display ads (sometimes malicious ads) to users as they work on their computers
or browse the web.
2. Viruses: A virus infects a computer and performs a variety of payloads. It may corrupt
files, destroy operating systems, delete or move files, or deliver a payload at a specific date.
3. Worms: A worm is a self-replicating virus, but instead of affecting local files, a worm
spreads to other systems and exhausts resources.
4. Trojans: A Trojan is named after the Greek war strategy of using a Trojan horse to enter
the city of Troy. The malware masquerades as a harmless program, but it runs in the
background stealing data, allowing remote control of the system, or waiting for a command
from an attacker to deliver a payload.
5. Bots: Infected computers can become a part of a botnet used to launch a distributed
denial-of-service by sending extensive traffic to a specific host.
6. Keyloggers: Capture keystrokes as users type in URLs, credentials, and personal
information and send it to an attacker.
How do I know I’ve been infected with malware?
The most common signs that your computer has been compromised by malware are:
▪ Slow computer performance
▪ Browser redirects, or when your web browser takes you to sites you did not intend to visit
▪ Infection warnings, frequently accompanied by solicitations to buy something to fix them ▪
Problems shutting down or starting up your computer
▪ Frequent pop-up ads
How can I protect myself from malware?
1. Protect your devices ▪ Keep your operating system and applications updated.
Cybercriminals look for vulnerabilities in old or outdated software, so make sure
you install updates as soon as they become available.
2. Never click on a link in a popup. Simply close the message by clicking on “X” in
the upper corner and navigate away from the site that generated it.
3. Limit the number of apps on your devices. Only install apps you think you need
and will use regularly. And if you no longer use an app, uninstall it.
4. Be careful online Avoid clicking on unknown links. Whether it comes via email,
a social networking site or a text message, if a link seems unfamiliar, keep away
from it.
5. Be selective about which sites you visit. Do your best to only use known and
trusted sites,
6. Beware of emails requesting personal information. If an email appears to come
from your bank and instructs you to click a link and reset your password or access
your account, don't click it. Go directly to your online banking site and log in there
7. Perform regular checks . If you are concerned that your device may be infected,
run a scan using the security software you have installed on your device.
8. Check your bank accounts and credit reports regularly.
9. Once the files are encrypted or locked behind a password, a text file is available to
the victim, explaining how to make the ransom payment and unlock the files for it.
What is a Ransomware Attack Work?
▪ The spread of ransomware mostly starts with phishing attacks.
A ransomware attack gains access to a victim's device through infected emails, messages,
and malicious sites and encrypts the data in that device
▪ The ransomware uses simple asymmetric encryption algorithms, blocks a user's files,
and makes them difficult to decrypt without knowing the key.
▪ Another way to breach a system with ransomware is by using the Remote Desktop
Protocol or RDP access. It can access remotely a computer using this protocol,
allowing a hacker to install malicious software on the system with the owner, unaware
of these developments.
▪ Ransomware adds instruction files describing the pay-for-decryption process, then
uses those files to present a ransom note to the user.
▪ Ransomware usually terminates and destroys itself by leaving only the payment
instruction files
. Types of Ransomware :
1. Locker ransomware ▪ It is a type of malware that blocks standard computer
functions from being accessed until the payment to the hackers is not complete. ▪ It
shows a lock screen that doesn't allow the victim to use the computer for primary
purposes.
2. Crypto ransomware ▪ This ransomware encrypts the local files and documents on
the computers. ▪ Once the files are encrypted, finding the decryption key is impossible
unless the ransomware variant is old and the keys are already available on the internet.
3. Scareware ▪ It is a fake software that claims to have detected a virus or other issue
on your computer and directs you to pay to resolve the problem. ▪ Some scareware
locks the computer, while others flood the screen with pop-up alerts without damaging
files.
How to Prevent Ransomware Attacks?
▪ One must always have backups of their data. Cloud storage for backup is easy, but a
physical backup in a hard drive is always recommended.
▪ Keeping the system updated with the latest security patches is always a good idea.
▪ Apart from system updates, one must always have reputed antivirus software
installed.
▪ If a system is infected with ransomware already, there is a website,
'[Link].' It has a collection of decryption tools for most well-known
ransomware packages.
How to identify phishing mails?
Identifying phishing emails is crucial to protect yourself from online scams and fraud.
Here are some key indicators to help you recognize phishing emails:
1. Check the Sender's Email Address: Verify the sender's email address. Be
cautious if it looks suspicious, misspelled, or doesn't match the organization it claims
to be from.
2. Inspect the Greeting: Legitimate organizations often use your name in their
emails. Be cautious if the email uses generic greetings like "Dear Customer" or "Hello
User."
3. Look for Spelling and Grammar Mistakes: Phishing emails often contain
spelling and grammatical errors. Be on the lookout for these indicators.
4. Check for Urgent or Threatening Language: Phishing emails may use fear
tactics, urgency, or threats to pressure you into taking immediate action.
5. Examine the URL: Hover your mouse over any links without clicking to see the
actual URL. Ensure it matches the legitimate website domain.
6. Beware of Unusual Requests: Be suspicious of emails requesting personal
information, financial details, or passwords. Legitimate organizations usually don't
request sensitive data via email.
7. Check for Unusual Attachments: Avoid opening email attachments from
unknown sources. Malicious attachments can contain malware.
8. Verify the Logo and Branding: Phishers often use fake logos and branding to
mimic legitimate organizations. Compare them to the real brand for discrepancies.
9. Inspect the Email Signature: Genuine emails typically include contact details and
a professional signature. Lack of this information can be a red flag.
[Link]'t Trust Unsolicited Emails: Be cautious of emails you didn't expect or
subscribe to, especially those promising prizes, winnings, or unsolicited job offers.
[Link] for Mismatched Email Content: Inconsistent content or unusual
formatting within the email can be a sign of phishing.
[Link] the Security Certificate: For websites, ensure the URL begins with
"https" and look for a padlock icon in the address bar, indicating a secure connection.
[Link] Email Filtering and Security Software: Enable email filtering and use
reliable antivirus and anti-phishing software to automatically detect and block
phishing attempts.
[Link] Your Intuition: If something feels off or too good to be true, it's best to be
cautious and verify the email's authenticity.
[Link] the Organization Directly: If you're unsure about an email's legitimacy,
independently verify the information by contacting the organization using official
contact details from their website or other trusted sources.
Types of Phishing Attacks:
Email phishing: the general term given to any malicious email message meant to trick users
into divulging private information. Attackers generally aim to steal account credentials,
personally identifiable information (PII) and corporate trade secrets. However, attackers
targeting a specific business might have other motives.
Spear phishing: these email messages are sent to specific people within an organization,
usually high-privilege account holders, to trick them into divulging sensitive data, sending
the attacker money or downloading malware.
Malware: users tricked into clicking a link or opening an attachment might download
malware onto their devices. Ransomware, rootkits or keyloggers are common malware
attachments that steal data and extort payments from targeted victims.
Smishing: using SMS messages, attackers trick users into accessing malicious sites from
their smartphones. Attackers send a text message to a targeted victim with a malicious
link that promises discounts, rewards or free prizes.
Vishing: attackers use voice-changing software to leave a message telling targeted
victims that they must call a number where they can be scammed. Voice changers are
also used when speaking with targeted victims to disguise an attacker’s accent or gender
so that they can pretend to be a fraudulent person.
Pharming: pharming is a two-phase attack used to steal account credentials. The first
phase installs malware on a targeted victim and redirects them to a browser and a spoofed
website where they are tricked into divulging credentials. DNS poisoning is also used to
redirect users to spoofed domains.
HOW TO REPORT CYER CRIME CASE IN POLICE STATION
Steps to Prepare a checklist for reporting cybercrime at cybercrime police Station
1. Identification and Contact Information: • Provide your full name, contact details,
and a valid email address. • Have a government-issued ID ready.
2. Description of the Incident: • Document the date, time, and location of the
cybercrime. • Provide a detailed account of what happened, including any relevant
online interactions or transactions.
3. Type of Cybercrime: • Identify the specific type of cybercrime, such as hacking,
online fraud, cyberbullying, etc.
4. Evidence: • Collect any evidence related to the cybercrime, including screenshots,
emails, chat logs, or any other relevant digital data.
5. Financial Details (if applicable): • If the cybercrime involves financial loss, provide
information on the financial transactions, account details, and any suspicious
payments.
6. Witness Information (if applicable): • If there were witnesses to the incident,
provide their contact information and statements.
7. Device Information: • List the devices involved (e.g., computers, smartphones) and
their relevant details (e.g., IP addresses, device names).
8. Online Platforms and Websites: • Mention the websites, social media platforms, or
online services involved, including any user profiles, handles, or links.
9. Actions Taken: • Describe any actions you have taken in response to the
cybercrime, such as reporting the incident to online platforms or financial institutions.
[Link] for Action: • Specify the outcome you expect or any specific actions you
want the police to take. [Link] Complaints: • If you have previously reported the
incident elsewhere, provide details of those complaints.
Checklist for Reporting Cybercrime Online:
1. Visit the Official Portal: Go to the official website or portal designated for reporting
cybercrimes in your region.
2. Create an Account: If required, create an account on the portal using your contact
information.
3. File a Complaint: Follow the instructions to file a cybercrime complaint. Provide a
detailed description of the incident, including all relevant information.
4. Upload Evidence: Use the portal's interface to upload any evidence you have
collected, such as screenshots, emails, or chat logs.
5. Specify the Type of Cybercrime: Choose the appropriate category or type of
cybercrime from the options provided on the portal.
6. Provide Contact Information: Ensure that your contact information is accurate, as
this will be used for communication regarding the case.
7. Acknowledge Terms and Conditions: Read and acknowledge any terms and
conditions related to the complaint submission process.
8. Review and Submit: Review your complaint for accuracy and completeness, then
submit it through the online portal.
9. Receive Confirmation: After submission, you should receive a confirmation or
reference number for your complaint. Keep this for future reference.
10. Follow Up: Follow up with the relevant authorities if you do not receive a
response within a reasonable time frame. Remember to stay vigilant about the security
of your personal information and ensure that you are using an official and secure
portal or website for reporting cybercrimes.
Analyze cyber crimes with sections applicable
Analyze cybercrime cases and identify section applicable (as per IT Act - 2000) Cyber
Law Cases in India
1. Shreya Singhal v. UOI: • Challenge to the constitutionality of Section 66A of the
IT Act, which criminalized offensive online comments. • The Supreme Court
emphasized freedom of speech, distinguishing between discussion and incitement.
Section 66A was found capable of restricting all communication, violating free
speech.
2. Shamsher Singh Verma v. State of Haryana: • Recognized Compact Discs as
documents. • No need for personal admission or denial of documents; they can be
proven without it.
3. Syed Asifuddin and Ors. v. State of Andhra Pradesh and Anr.: • Hacking ESNs of
mobile handsets. • Court found that mobile handsets fall under the definition of
"computer" in the IT Act, and altering ESN is an offense under Section 65. Note: In
the case "Syed Asifuddin and Ors. v. State of Andhra Pradesh and Anr.," the term
"ESN" stands for "Electronic Serial Number." Electronic Serial Number is a unique
identifier associated with a mobile device, particularly in the context of older analog
and early digital cellular networks. It is used to track and identify individual mobile
devices on a network. The ESN is distinct from the International Mobile Equipment
Identity (IMEI) number, which is used in modern mobile devices to serve a similar
purpose.
4. Shankar v. State Rep: • Unauthorized access to a protected system. • Court ruled
that the charge sheet couldn't be quashed regarding non-granting of prosecution
sanction under Section 72 of the IT Act.
5. Christian Louboutin SAS v. Nakul Bajaj & Ors: Trademark violation by an e-
commerce portal. • Court found the e-commerce platform was more than an
intermediary, exempting it from Section 79 protections. 6. Avnish Bajaj v. State
(NCT) of Delhi: • CEO of [Link] arrested for cyber pornography. • Court ruled
that [Link] wasn't involved in broadcasting porn, but its platform could earn from
sales and advertisements.
7. State of Tamil Nadu v. Suhas Katti: • Conviction in a cyber harassment case in 7
months. • Accused convicted under Sections 67 of the IT Act and Indian Penal Code
sections.
8. CBI v. Arif Azim (Sony Sambandh case): • Unauthorized funds transfer from
Citibank accounts. • Court found the accused guilty of offenses under the IT Act and
IPC.
9. SMC Pneumatics (India) Pvt. Ltd. vs. Jogesh Kwatra: • Defamatory emails sent by
an employee. • Plaintiff's request for perpetual injunction denied due to lack of
certified evidence.
[Link] Citibank Mphasis Call Center Fraud • Summary: In 2005, $350,000 was
fraudulently taken from the Citibank accounts of four U.S. customers through the
internet and transferred to fake accounts. The fraudsters gained customers' trust and
acquired their PINs by posing as helpful advisors during difficult situations. Instead of
breaking encryption or firewalls, they exploited weaknesses in the MphasiS system. •
Court Decision: The accused were former employees of the MphasiS call center.
These employees were observed upon entry and exit, indicating that they likely
memorized customer account details. They used the SWIFT (Society for Worldwide
Interbank Financial Telecommunication) service for transferring funds, involving
unauthorized access to customer electronic accounts. This falls under "cybercrimes."
The court applied Section 43(a) of the IT Act, 2000 due to unauthorized access. The
accused were also charged under Section 66 of the IT Act, 2000, and Sections 420
(cheating), 465, 467, and 471 of the Indian Penal Code, 1860.
.
What is Cyber Law?
Cyber Law is a term used to describe the legal issues related to use of communication
technology, particularly Cyberspace, i.e., the internet.
Cyber law, also known as Internet Law, is the part of the overall legal system that is
related to
legal informatics and supervises the digital circulation of information, e-commerce,
software and
information security.
It covers many areas, such as access to and usage of the Internet, encompassing various
subtopics
as well as freedom of expression, and online privacy.
What is Cyber Law?
Cyber Law is a term used to describe the legal issues related to use of communication
technology, particularly Cyberspace, i.e., the internet.
Cyber law, also known as Internet Law, is the part of the overall legal system that is
related to
legal informatics and supervises the digital circulation of information, e-commerce,
software and
information security.
It covers many areas, such as access to and usage of the Internet, encompassing various
subtopics
as well as freedom of expression, and online privacy.
What are the advantages of Cyber Law ?
Advantages of Cyber Law:
1. Protecting personal information – Cyber law helps to ensure that our sensitive personal
information, such as our financial and medical records, are kept secure online.
2. Combatting cybercrime – Cyber law helps to deter and punish those who engage in illegal
activities on the internet, such as hacking and identity theft.
3. Promoting fair competition – Cyber law helps to level the playing field for businesses by
prohibiting unfair practices such as cyber espionage and false advertising.
4. Facilitating e-commerce – Cyber law helps to establish rules and regulations for buying and
selling goods and services online, making it easier and safer for consumers to make
transactions.
5. Protecting intellectual property – Cyber law helps to safeguard creative works such as music,
literature, and software from being pirated or used without permission.
Disadvantages of Cyber Law :
1. Complexity and confusion – Cyber law can be difficult to understand and apply, leading to
confusion for individuals and businesses trying to comply with it.
2. Limited jurisdiction – Cyber law can only be enforced within the borders of a particular
country, making it challenging to address cross-border cyber issues.
3. Encroachment on civil liberties – Some argue that cyber law may infringe upon civil
liberties, such as freedom of speech and privacy, in the name of protecting national security or
public order.
4. Slowing down innovation – Cyber law may impose burdensome regulations on new
technologies and innovations, stifling their development and adoption.
5. Lack of universal standards – There is currently a lack of universally agreed upon cyber
laws, leading to discrepancies and conflicts between different countries’ legal systems.
Importance of cyber crime laws
The following points can highlight the importance of cyber laws:
An important goal of any cyber law is to prosecute those who undertake illegal
activities using the internet. To effectively prosecute these types of crimes, such as
cyber abuse, assaults on other websites or individuals, theft of records, disrupting
every company’s online workflow, and other criminal activities, significant efforts
should be undertaken, and hence, which is where cyber laws come into the picture.
In the cases involving a violation of cyber law, the action is taken against the
individual on the basis of his location and how was he involved in that violation.
Prosecuting or retracting hackers is the most important thing since most cyber crimes
are beyond the reach of a felony, which is not a crime.
The use of the internet is also associated with security concerns and there are even
some malicious individuals who want to gain unauthorised access to the computer
device and commit fraud using it in the future. Hence, all rules and cyber laws are
designed to protect internet businesses and internet users from unwanted unauthorized
access and malicious cyber-attacks. There are a variety of ways in which individuals
or associations can take action against others who commit criminal acts or break cyber
laws.
Need for cyber crime laws in India:
Cyberlaw is of particular importance in countries such as India, where the internet is used
widely. In order to protect both individuals and organizations against cyber crime, the law was
enacted. The cyberlaw allows other people or organizations to take legal action against someone
if that person violates and breaks the provisions of the law.
Cyberlaw may be required in the following circumstances:
Due to the fact that all the transactions associated with stocks are now executed in
demat format, anyone who is involved with these transactions is protected by cyber
law in the event of any fraudulent transactions.
Almost all Indian companies have electronic records. A company may need this law to
prevent the misuse of such data.
As a result of the rapid development of technology, various government forms are
being filled out electronically, such as income tax returns and service tax returns.
Anybody can misuse those forms by hacking government portal sites, and thus,
cyberlaw is required under which legal action can be taken.
Shopping today is done through credit cards and debit cards. Unfortunately, some
frauds perpetrated by means of the internet clone these credit cards and debit cards.
The cloning of a credit or debit card is a technique that allows someone to obtain your
information via the Internet. This can be prevented by cyberlaw as under Section 66C
of the IT Act, there is 3-year imprisonment along with a fine up to one lakh rupees if
anyone tries to make use of any electronic password fraudulently or dishonestly.
Business transactions are typically carried out by means of digital signatures and
electronic contracts. The misuse of digital signatures and electronic contracts can be
easily accomplished by anyone involved with them. Cyberlaw provides protection
against these types of scams.
Role of Cyber Law:
In today’s techno-savvy environment, the world is becoming more and more digitally
sophisticated and so are the crimes. Internet was initially developed as a research and
information
sharing tool and was in an unregulated manner. As the time passed by it became more
transactional with
e-business, e-commerce, e-governance and e-procurement etc. All legal issues related to
internet crime
are dealt with through cyber laws. As the number of internet users is on the rise, the need for
cyber laws
and their application has also gathered great momentum
In today’s techno-savvy environment, the world is becoming more and more digitally
sophisticated and so are the crimes. Internet was initially developed as a research and
information
sharing tool and was in an unregulated manner. As the time passed by it became more
transactional with
e-business, e-commerce, e-governance and e-procurement etc. All legal issues related to
internet crime
are dealt with through cyber laws. As the number of internet users is on the rise, the need for
cyber laws
and their application has also gathered great momentum
In today’s techno-savvy environment, the world is becoming more and more digitally
sophisticated and so are the crimes. Internet was initially developed as a research and
information
sharing tool and was in an unregulated manner. As the time passed by it became more
transactional with
e-business, e-commerce, e-governance and e-procurement etc. All legal issues related to
internet crime
are dealt with through cyber laws. As the number of internet users is on the rise, the need for
cyber laws
and their application has also gathered great momentum
In today’s techno-savvy environment, the world is becoming more and more digitally
sophisticated and so are the crimes. Internet was initially developed as a research and
information
sharing tool and was in an unregulated manner. As the time passed by it became more
transactional with
e-business, e-commerce, e-governance and e-procurement etc. All legal issues related to
internet crime
are dealt with through cyber laws. As the number of internet users is on the rise, the need for
cyber laws
and their application has also gathered great momentum
Role of Cyber Law
• Cyber Laws have an important role in representing and defining the norms of the cyber
society.
• Cyber Laws help in giving the right to enter into legally enforceable digital contracts.
• Cyber Laws help in maintaining the Cyber properties.
• Cyber Laws help in to carry on online business.
• Cyber Laws help in providing legal reorganization for Electronic documents and Digital
signatur
Cyber Laws have an important role in representing and defining the norms of the cyber society.
• Cyber Laws help in giving the right to enter into legally enforceable digital contracts.
• Cyber Laws help in maintaining the Cyber properties.
• Cyber Laws help in to carry on online business.
• Cyber Laws help in providing legal reorganization for Electronic documents and Digital
signature.
Remedial and mitigation measures
Remedial Measures:
1. Incident Response: In the event of a cyber crime, organizations should have an incident
response plan in place to quickly identify, contain, and mitigate the impact of the attack. This
includes isolating affected systems, restoring backups, and applying patches or security updates.
2. Forensic Investigation: Engaging professional forensic investigators can help identify the
source and extent of the cyber crime, gather evidence, and aid in legal proceedings.
3. Data Recovery: If data is compromised or encrypted due to a cyber attack, organizations
should have backups in place to restore affected systems and minimize data loss.
Mitigation Measures:
1. Strong Security Practices: Implement robust security measures, such as firewalls, antivirus
software, and intrusion detection and prevention systems, to protect against cyber threats.
2. Regular Updates and Patching: Keep software, operating systems, and firmware up to date
with the latest security patches to mitigate vulnerabilities that cyber criminals may exploit.
3. Employee Education: Provide cybersecurity awareness and training programs to employees
to educate them about common cyber threats, phishing techniques, and safe online practices.
4. Multi-factor Authentication (MFA): Implement MFA wherever possible to add an extra
layer of security, making it harder for cyber criminals to gain unauthorized access to accounts
or systems.
5. Data Encryption: Encrypt sensitive data, both in transit and at rest, to ensure that even if it
is intercepted or stolen, it remains unreadable and unusable for unauthorized individuals.
6. Regular Security Audits: Conduct regular security audits and vulnerability assessments to
identify and address any weaknesses or potential entry points for cyber criminals.
Cyber Law in India:
In India, cyber laws are contained in the Information Technology Act, 2000 ("IT Act") which
came into force on October 17, 2000. The main purpose of the Act is to provide legal
recognition to electronic commerce and to facilitate filing of electronic records with the
Government.
The following Act, Rules and Regulations are covered under cyber laws:
[Link] Technology Act, 2000
[Link] Technology (Certifying Authorities) Rules, 2000
[Link] Technology (Security Procedure) Rules, 2004
[Link] Technology (Certifying Authority) Regulations, 2001.
Cyber law encompasses laws relating to:
➢ Cyber crimes
➢ Electronic and Digital signatures
➢ Intellectual property
➢ Data protection and privacy.
IT act 2000:
Cyber Laws in India Information Technology Act 2000 (IT Act 2000) is the main law
connected with cyber security in India. Indian Penal Code, 1860 is also used to book criminals
connected with cybercrimes .
The Information Technology Act 2000, also known as the IT Act 2000, is an Indian legislation
that was enacted to provide legal recognition and regulation for electronic transactions and
digital information.
Here are its key provisions:
1. Legal Recognition: The IT Act 2000 grants legal recognition to electronic records and
digital signatures, making electronic documents and transactions legally enforceable.
2. Digital Signatures: It establishes the framework for the use of digital signatures, enabling
secure and authentic electronic communications and transactions.
3. Cybercrimes: The act addresses various forms of cybercrimes, such as hacking, data theft,
and computer-related offenses, with defined penalties and legal procedures.
4. Data Protection: The act contains provisions for safeguarding the privacy and security of
electronic data and information. It also specifies requirements for data protection and security
practices.
5. Offenses and Penalties: It outlines various offenses related to electronic communication,
data breaches, and unauthorized access to computer systems, along with corresponding
penalties.
6. Adjudication: The act sets up specialized bodies and authorities to handle issues related to
electronic transactions, disputes, and cybercrimes.
7. Digital Evidence: The IT Act 2000 recognizes digital evidence in legal proceedings and
specifies procedures for its admissibility in court.
8. Cyber Appellate Tribunal: It establishes a Cyber Appellate Tribunal to hear appeals
against orders issued by the adjudicating officers under the act.
9. Electronic Governance: The act encourages the use of electronic means for government
communication and public services to promote efficiency and transparency.
[Link] Certifying Authorities: It regulates entities that issue digital certificates and
digital signatures to ensure their trustworthiness and security.
Overall, the IT Act 2000 is a comprehensive legal framework that addresses electronic
commerce, data security, and cybercrimes in India, providing a foundation for the country's
digital transformation and online legal framework. Please note that since my knowledge cutoff
date is January 2022, there may have been amendments or updates to the IT Act beyond that
date.
FLAWS IN IT ACT 2000:
Flaws of the IT Act 2000 The Information Technology Act 2000 (IT Act 2000) of India, while
serving as an important legal framework for the digital age, has faced criticism and exhibited
some flaws, including:
1. Lack of Comprehensive Amendments: The IT Act 2000 has not kept pace with the rapid
evolution of technology and the internet. It hasn't been comprehensively updated to address
emerging cyber threats and challenges, which has led to gaps in cybersecurity and legal
enforcement.
2. Ambiguity in Certain Provisions: Some provisions in the act are criticized for being vague
and open to interpretation, potentially leading to legal uncertainty in cybercrime cases.
3. Limited Data Protection: The act lacks comprehensive data protection provisions, which
has become a significant concern in the age of widespread data breaches and privacy violations.
India has introduced separate data protection laws to address this issue, but there is still debate
over how these laws interact with the IT Act.
4. Limited Accountability of Intermediaries: The act places certain responsibilities on
internet intermediaries, but there has been ongoing debate over the extent of their liability and
the potential for overreach in regulating online content and services.
5. Limited Focus on Cybersecurity: While the act addresses cybercrimes and legal recognition
of electronic records, it does not provide a comprehensive framework for promoting
cybersecurity measures or incident response.
6. Outdated Definitions: The definitions and terminology used in the act may not align with
the current state of technology and digital practices, leading to challenges in enforcement.
7. Slow Legal Processes: The legal processes under the IT Act can be timeconsuming and may
not keep up with the fast-paced nature of cybercrimes. Delays in prosecution can hinder the
effectiveness of the law.
8. Enforcement Challenges: Cybercrimes often transcend international borders, making
enforcement and extradition difficult. The act doesn't provide a clear mechanism for handling
these challenges.
9. Digital Evidence Handling: There may be challenges in handling and presenting digital
evidence in court due to the lack of clear procedures and standards under the act.
[Link] Public Awareness: Many people in India may not be fully aware of their rights and
responsibilities under the IT Act, which can lead to issues related to cybercrimes and digital
privacy. It's worth noting that there have been subsequent amendments and the introduction of
new laws and regulations to address some of these flaws and modernize India's legal framework
for the digital era. The Information Technology (Amendment) Act 2008 and the Personal Data
Protection Bill are examples of legislative efforts to address some of these concerns.
The Information Technology Act, 2000, is an Indian law that addresses issues related to
electronic commerce, digital signatures, and cybercrime in India. Here are some of the
key sections of the Information Technology Act, along with a brief description:
1. Section 1-2: Short title, extent, commencement, and application.
2. Section 3: Definitions, including definitions of terms related to electronic records,
communication, computer, and digital signatures.
3. Section 4: Legal recognition of electronic records, which ensures that electronic records
and digital signatures are recognized as equivalent to paper records and handwritten
signatures.
4. Section 5: Legal recognition of electronic signatures, establishing the validity of
electronic signatures in certain situations.
5. Section 43: Unauthorized access to computer systems, computer networks, or data.
6. Section 45: Residual powers to make rules to carry out the provisions of the Act.
7. Section 66: Computer-related offenses, including hacking.
8. Section 69: Power to issue directions for interception or monitoring or decryption of any
information through any computer resource.
9. Section 70: Protected systems, outlining the penalties for unauthorized access to
protected computer systems.
10. Section 71: Penalty for damage to computer, computer system, etc.
11. Section 72: Breach of confidentiality and privacy, protecting the privacy and
confidentiality of electronic communication.
12. Section 79: Intermediaries not to be liable in certain cases, providing safe harbor
provisions for online intermediaries.
13. Section 80: Power to make rules by the Central Government in consultation with
the Cyber Regulations Advisory Committee.
14. Section 81: Act to have overriding effect, specifying that the provisions of the Act
will have precedence over other conflicting laws.
These are just a few key sections of the Information Technology Act, 2000. The Act has
been amended over time to address emerging challenges in the digital space. For the
most current and detailed information, it's advisable to refer to the latest version of the
Information Technology Act or consult legal experts.
IT 2021:
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules,2021
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules,
2021, commonly known as the IT Rules 2021, are a set of regulations introduced by the Indian
government to govern the behavior of online intermediaries and digital media platforms
operating in India. These rules aim to address issues related to online content, user privacy, and
the responsibilities of online platforms.
Here are the key components of the IT Rules 2021:
1. Definition of Intermediaries: The rules define "intermediaries" to include social media
platforms, messaging services, search engines, and other online service providers that host and
publish user-generated content.
2. Appointment of Grievance Officer: Online intermediaries are required to appoint a
Grievance Officer who must be a resident of India. This officer is responsible for addressing
user complaints and government requests.
3. Content Removal and Blocking: Intermediaries are obligated to remove or disable access
to certain types of content, such as content that threatens the sovereignty and integrity of India,
public order, or decency and morality.
4. User Privacy: The rules place an emphasis on the protection of user privacy, requiring
intermediaries to establish privacy policies and disclose how user data is collected, stored, and
used.
5. Traceability of Messages: Messaging services with more than 5 million users must enable
traceability of the originator of a message to curb the spread of fake news and unlawful content.
6. Self-Regulation Mechanism: Digital news publishers and OTT (Over-The-Top) platforms
are required to establish a self-regulation mechanism and adhere to a Code of Ethics, which
includes provisions related to content classification, age-appropriate content, and more.
7. Compliance and Reporting: Online platforms are required to provide compliance reports to
the government, including details of complaints received and actions taken.
8. Takedown Timelines: Intermediaries must respond to government or court orders to remove
content within specific timeframes.
9. Blocking of Apps: The rules grant the government the authority to block mobile apps and
services if they are deemed to be involved in activities that may threaten national security.
10. Intermediary Liability: Online intermediaries may lose their safe harbor protections if they
do not comply with these rules.
Personal data protection Bill,2019:
The Personal Data Protection Bill, 2019 The Personal Data Protection Bill, 2019 was
introduced in the Lok Sabha (lower house of the Indian Parliament) in December 2019. The
main objective of this bill is to provide for the protection of personal data of individuals and to
establish a Data Protection Authority for the same.
Some of the key objectives of Personal Data Protection Bill, 2019 are:
1. To ensure that personal data of individuals is processed in a fair and transparent manner.
2. To provide individuals with control over their personal data.
3. To establish a regulatory framework for the processing of personal data.
4. To ensure that personal data is processed only for legitimate purposes and with the consent of
the individual.
5. To provide for the right to be forgotten, which allows individuals to restrict or prevent
continuing disclosure of their personal data.
6. To establish a Data Protection Authority to oversee and enforce the provisions of the bill.
Overall, the Personal Data Protection Bill, 2019 aims to protect the privacy and autonomy of
individuals with respect to their personal data in India.
DATA PROTECTION LAWS IN INDIA
The Parliament has approved the Digital Personal Data Protection Bill in 2023. How does it
differ from the earlier version? Where has it improved, and where may it still need
enhancements?
Digital personal data protection involves safeguarding people's personal information in the
digital world.
As technology and internet use continue to grow, individuals share a lot of personal data online,
including financial details and private messages. Keeping this data safe from unauthorized
access, breaches, and misuse is a significant concern in today's digital age.
Key Aspects of Personal Data Protection:
Around the world, countries have implemented data privacy laws governing the collection,
processing, storage, and sharing of personal data. These laws grant individuals control over
their data and impose responsibilities on organizations. These responsibilities include obtaining
informed consent before collecting personal data, implementing robust security measures,
offering clear information on data practices, and respecting individuals' rights to access, correct,
or delete their data.
The Digital Personal Data Protection Bill of 2023:
The journey towards a comprehensive data protection law in India commenced in 2017 with
the establishment of an expert committee. While the Data Protection Bill of 2021 marked a
significant milestone, it was retracted in 2022. The 2023 Bill addresses the handling of digital
personal data in India and introduces several notable provisions.
Highlights of the 2023 Bill:
1. This Bill applies to personal data collected online or digitized within India.
2. It mandates that data processing must align with lawful purposes and individual consent
3. Data fiduciaries are bound to maintain data accuracy and security and delete data once its
purpose is fulfilled.
4. The Bill bestows specific rights upon individuals, including the right to access information
and seek grievance redressal.
5. Certain exemptions are granted to government agencies for reasons such as national security.
Challenges with the 2023 Bill:
The provision for exemptions related to national security raises concerns of potential excessive
data processing.
The Bill lacks provisions regarding data portability and the right to be forgotten.
It permits the transfer of personal data abroad without stringent evaluation.
The short-term appointments of members to the Data Protection Board may impact the board's
independence.
The Need for Digital Data Protection in India:
India's data protection regulations must catch up with technological advancements and align
with global trends. The current legal framework is inconsistent, and new regulations are
necessary to address emerging challenges like spam, online transactions, and more.
Landmark Cases in Data Protection:
Several legal cases have played a pivotal role in emphasizing the significance of privacy and
the right to information in India.
1. State of Tamil Nadu v. Suhas Katti (2004): This case holds importance as it encouraged
citizens nationwide to report incidents of online abuse.
2. Amar Singh v. Union of India (2011): In this case, which considered Sections 69, 69A, and
69B of the IT Act, 2000, the court ruled that service providers must validate the legitimacy of
government orders for phone tapping, particularly when such orders contain significant errors.
To prevent unlawful call interception, the court mandated the central government to establish
specific directives and rules.
3. Shreya Singhal v. Union of India (2015): This landmark case saw the Supreme Court of
India declare Section 66A unconstitutional. The section aimed to protect against annoyance,
inconvenience, danger, obstruction, insult, injury, and criminal intimidation but was found to
exceed reasonable restrictions under Article 19(2) of the Indian Constitution.
4. Justice K.S. Puttaswamy (Retd) v. Union of India (2017): This case affirmed the right to
privacy as a constitutionally protected right in India.
5. Praveen Arimbrathodiyil v. Union of India (2021): In this case, various companies,
including WhatsApp, Quint, LiveLaw, and the Foundation for Independent Journalists, SIMS
contested regulations introduced in 2021. The judgment's outcomes are anticipated to shape the
future of Indian information technology law, and the petition is currently pending before the
Supreme Court for listing.
Looking Ahead:
Despite India's participation in international bodies and its commitment to data protection, the
country lacks a comprehensive data protection law. Such legislation is vital for the welfare of
the people and to ensure global peace and security. Digital personal data protection is a shared
responsibility among individuals, organizations, and governments, aiming to strike a balance
between data utilization and privacy while fostering trust in the digital landscape.
Indian Penal Code, 1860 (IPC):
If the IT Act is not sufficient to cover specific cyber crimes, law enforcement agencies can
apply the following IPC sections:
Section 292: The purpose of this section was to address the sale of obscene
materials, however, in this digital age, it has evolved to deal with various cyber
crimes as well.
Section 354C:In this provision, cyber crime is defined as taking or publishing
pictures of private parts or actions of a woman without her consent.
Section 354D: Stalking, including physical and cyberstalking, is described and punished
in this chapter. The tracking of a woman through electronic means, the internet, or
email or the attempt to contact her despite her disinterest amounts to cyber-stalking.
Section 420: This section talks about cheating and dishonestly inducing delivery of
property.
Section 379: The punishment involved under this section, for theft, can be up to three
years in addition to the fine.
Section 463: This section involves falsifying documents or records electronically.
Section 465: This provision typically deals with the punishment for forgery. Under this
section, offences such as the spoofing of email and the preparation of false documents
in cyberspace are dealt with and punished with imprisonment ranging up to two years,
or both.
Section 468: Fraud committed with the intention of cheating may result in a seven-
year prison sentence and a fine. This section also punishes email spoofing.
Cyber Jurisprudence
The term jurisprudence is derived from the Latin words “jus” and “prudence”. The common
English meaning is “knowledge of the law”.
Cyber jurisprudence is the legal study that concentrates on the logical structure, the meanings
and uses of its concepts, and the formal terms and modes of cyber law.
Definition:
To define cyber jurisprudence, it is a prerequisite to be aware of the definition of jurisprudence
in general. “It is a method of legal study that concentrates on the logical structure of law, the
meanings and uses of its concepts, and the formal terms and modes of its operation” according
to Black’s law dictionary.
Cyber Jurisprudence at Indian Level
In general, jurisprudence is the concept of law, an analysis of how social norms and changes
have contributed to the development of law. Thus, cyber jurisprudence might be defined as law
directly related to cybercrimes.
Since nurturing of society is the ultimate goal of jurisprudence, no matter whether it is virtual or
physical society. Hence the cyber jurisprudence is the legal study of the virtual infrastructure of
cyberspace, the meaning and root of the concept, nature of its pattern, meaning, and modes of
operations of cyber law.
Indian cyber law
“Legal order must be flexible as well as stable. Law must be overhauled continuously and
refitted continually to the change in social life which it is to govern” According to Roscoe
Pound, the law should change in accordance with social change. The misuse of cyber space has
paved the way for a gamut of new age crimes. The Indian parliament went about legislating the
Information and technology Act, 2000, exclusively for addressing cyber crimes. This Act came
into force on October 17, 2000, and an amendment was made in 2008. It penalizes criminal
activities taking place in cyberspace and also regulates such activities that may violate the rights
of the cyber community.
Cybercrimes could be categorized into two,
1. Crimes committed against the computer (target of crime) – the destruction of the available
information in a computer by hacking, virus attack, cyberpunk, Trojan horse, and so on.
2. When committed cybercrimes affect the real life of the users (computer a tool of crime) – cyber
violence, cyberbullying, financial losses, loss of intellectual property, using cyberspace as a
medium of communication for committing murder, fraud, or terrorist attacks.
Section 72- the penalty for breach of privacy and confidentiality
Punishment: 2 years imprisonment and/or fine of 1 lakh INR.
The Data Protection Act 2018 penalizes cyber-related offences like cyber trespass, leaking or
selling the victim’s personal data without consent, and so on. The cyber piracy of intellectual
property is punishable under the Copyright Design and Patent Act 1988. The Malicious
Communication Act 1988 and Communication Act 2003 make it an offence for a person who
sends obscene or indecent messages via a “public electronic communication network”. The
Obscene Publication (Amendment) Act, 1959, deals with the storage and sharing of such porn
related stuff.
Legal perspective of cybercrime in India
▪ In India, cybercrime is primarily governed by the Information Technology Act,
2000 (IT Act). This law was established to address various cyber offenses and
provide a legal framework for electronic transactions, digital signatures, and data
protection
. ▪ The purpose of the Indian IT Act(ITA) was to amend the Indian Penal
Code(IPC). Amendments and Updates
▪ The IT Act has undergone amendments over the years to address emerging cyber
threats and strengthen cybercrime provisions.
▪ For example, the Information Technology (Amendment) Act, 2008 introduced
additional provisions to tackle cyber terrorism, data privacy, and intermediary
liability.
▪ It is important to consult with legal professionals or refer to official sources for
comprehensive and up-to-date information on the legal aspects of cybercrime in
India
Organizations dealing with Cybercrime and Cyber security in India:
▪ In India, several organizations are involved in dealing with cybercrime and
cybersecurity at various levels, including law enforcement, regulatory bodies, and
agencies focused on awareness and prevention. ▪ Some prominent ones include:
1. National Cyber Security Coordinator (NCSC): The NCSC operates under the
Prime Minister's Office and is responsible for coordinating all cybersecurity
initiatives in the country
2. Computer Emergency Response Team-India (CERT-In): CERT-In is the
national nodal agency under the Ministry of Electronics and Information
Technology that deals with cybersecurity incidents, response, and related issues.
3. National Critical Information Infrastructure Protection Centre (NCIIPC):
NCIIPC is responsible for protecting critical information infrastructure in the
country and formulating policies and guidelines for securing these assets.
4. State Police Cyber Cells: Many states have established specialized cyber cells
within their police departments to investigate and handle cybercrimes at the state
level.
5. National Investigation Agency (NIA): NIA deals with investigating and
prosecuting offenses affecting the sovereignty, security, and integrity of India,
including cybercrimes with national implications.
6. Cyber Appellate Tribunal (CAT): It hears appeals against any order passed by
CERTIn or the Adjudicating Officer under the Information Technology Act, 2000.
7. Banks and Financial Institutions: Regulatory bodies like the Reserve Bank of
India (RBI) and Securities and Exchange Board of India (SEBI) have guidelines
and teams dedicated to cybersecurity in the financial sector.
8. Private Cybersecurity Firms: Several private cybersecurity companies operate
in India, offering services ranging from consulting and risk assessment to incident
response and security solutions.
▪ These organizations collaborate to address cyber threats, enforce cybersecurity
laws and regulations, provide guidelines and advisories, conduct awareness
programs, and investigate cybercrimes. They play a crucial role in safeguarding
digital infrastructure and combating cyber threats in India.
The important provisions of the Act
The IT Act is prominent in the entire Indian legal framework, as it directs the whole
investigation process for governing cyber crimes. Following are the appropriate sections:
Section 43: This section of the IT Act applies to individuals who indulge in cyber
crimes such as damaging the computers of the victim, without taking the due
permission of the victim. In such a situation, if a computer is damaged without the
owner’s consent, the owner is fully entitled to a refund for the complete damage.
Section 66: Applies to any conduct described in Section 43 that is dishonest or
fraudulent. There can be up to three years of imprisonment in such instances, or a fine
of up to Rs. 5 lakh.
Section 66B: This section describes the penalties for fraudulently receiving stolen
communication devices or computers, and confirms a possible three-year prison sentence.
Depending on the severity, a fine of up to Rs. 1 lakh may also be imposed.
Section 66C: The focus of this section is digital signatures, password hacking, and
other forms of identity theft. Thi section imposes imprisonment upto 3 years along
with one lakh rupees as a fine.
Section 66D: This section involves cheating by personation using computer Resources.
Punishment if found guilty can be imprisonment of up to three years and/or up-to Rs 1
lakh fine.
Section 66E: Taking pictures of private areas, publishing or transmitting them without
a person’s consent is punishable under this section. Penalties, if found guilty, can be
imprisonment of up to three years and/or up-to Rs 2 lakh fine.
Section 66F: Acts of cyber terrorism. An individual convicted of a crime can face
imprisonment of up to life. An example: When a threat email was sent to the Bombay
Stock Exchange and the National Stock Exchange, which challenged the security
forces to prevent a terror attack planned on these institutions. The criminal was
apprehended and charged under Section 66F of the IT Act.
Section 67: This involves electronically publishing obscenities. If convicted, the prison
term is up to five years and the fine is up to Rs 10 lakh.
If the IT Act is not sufficient to cover specific cyber crimes, law enforcement agencies can
apply the following IPC sections:
Section 292: The purpose of this section was to address the sale of obscene materials,
however, in this digital age, it has evolved to deal with various cyber crimes as well. A
manner in which obscene material or sexually explicit acts or exploits of children are
published or transmitted electronically is also governed by this provision. The penalty
for such acts is imprisonment and fines up to 2 years and Rs. 2000, respectively. The
punishment for any of the above crimes may be up to five years of imprisonment and a
fine of up to Rs. 5000 for repeat (second-time) offenders.
Section 354C: In this provision, cyber crime is defined as taking or publishing pictures
of private parts or actions of a woman without her consent. In this section, voyeurism
is discussed exclusively since it includes watching a woman’s sexual actions as a
crime. In the absence of the essential elements of this section, Section 292 of the IPC
and Section 66E of the IT Act are broad enough to include offences of an equivalent
nature. Depending on the offence, first-time offenders can face up to 3 years in prison,
and second-time offenders can serve up to 7 years in prison.
Section 354D: Stalking, including physical and cyberstalking, is described and
punished in this chapter. The tracking of a woman through electronic means, the
internet, or email or the attempt to contact her despite her disinterest amounts to cyber-
stalking. This offence is punished by imprisonment of up to 3 years for the first
offence and up to 5 years for the second offence, along with a fine in both cases.
Section 379: The punishment involved under this section, for theft, can be up to three
years in addition to the fine. The IPC Section comes into play in part because many
cyber crimes involve hijacked electronic devices, stolen data, or stolen computers.
Section 420: This section talks about cheating and dishonestly inducing delivery of
property. Seven-year imprisonment in addition to a fine is imposed under this section
on cybercriminals doing crimes like creating fake websites and cyber frauds. In this
section of the IPC, crimes related to password theft for fraud or the creation of
fraudulent websites are involved.
Section 463: This section involves falsifying documents or records electronically.
Spoofing emails is punishable by up to 7 years in prison and/or a fine under this
section.
Section 465: This provision typically deals with the punishment for forgery. Under this
section, offences such as the spoofing of email and the preparation of false documents
in cyberspace are dealt with and punished with imprisonment ranging up to two years,
or both. In Anil Kumar Srivastava v. Addl Director, MHFW (2005), the petitioner had
forged signed the signature of the AD and had then filed a case that made false
allegations against the same individual. Due to the fact that the petitioner also
attempted to pass it off as a genuine document, the Court held that the petitioner was
liable under Sections 465 and 471 of the IPC.
Section 468: Fraud committed with the intention of cheating may result in a seven-
year prison sentence and a fine. This section also punishes email spoofing.
Furthermore, there are many more sections of the IT Act and the Indian Penal Code, which
pertain to cyber crimes, in addition to the laws listed above.
5. Common Cyber-crime scenarios and Applicability of Legal Sections
Let us look into some common cyber-crime scenarios which can attract prosecution as per
the penalties and offences prescribed in IT Act 2000 (amended via 2008) Act.
Harassment via fake public profile on social networking site
A fake profile of a person is created on a social networking site with the correct
address, residential information or contact details but he/she is labelled as ‘prostitute’
or a person of ‘loose character’. This leads to harassment of the [Link]
Applicable:- Sections 66A, 67 of IT Act and Section 509 of the Indian Penal Code.
Online Hate Community
Online hate community is created inciting a religious group to act or pass
objectionable remarks against a country, national figures [Link] Applicable:
Section 66A of IT Act and 153A & 153B of the Indian Penal Code.
Email Account Hacking
If victim’s email account is hacked and obscene emails are sent to people in victim’s
address [Link] Applicable:- Sections 43, 66, 66A, 66C, 67, 67A and 67B of
IT Act.
Credit Card Fraud
Unsuspecting victims would use infected computers to make online
[Link] Applicable:- Sections 43, 66, 66C, 66D of IT Act and section
420 of the IPC.
Web Defacement
The homepage of a website is replaced with a pornographic or defamatory page.
Government sites generally face the wrath of hackers on symbolic [Link]
Applicable:- Sections 43 and 66 of IT Act and Sections 66F, 67 and 70 of IT Act also
apply in some cases.
Introducing Viruses, Worms, Backdoors, Rootkits, Trojans, Bugs
All of the above are some sort of malicious programs which are used to destroy or
gain access to some electronic [Link] Applicable:- Sections 43, 66,
66A of IT Act and Section 426 of Indian Penal Code.
Cyber Terrorism
Many terrorists are use virtual(GDrive, FTP sites) and physical storage
media(USB’s, hard drives) for hiding information and records of their illicit
[Link] Applicable: Conventional terrorism laws may apply along with
Section 69 of IT Act.
Online sale of illegal Articles
Where sale of narcotics, drugs weapons and wildlife is facilitated by the
InternetProvisions Applicable:- Generally conventional laws apply in these cases.
Cyber Pornography
Among the largest businesses on Internet. Pornography may not be illegal in many
countries, but child pornography [Link] Applicable:- Sections 67, 67A and
67B of the IT Act.
Phishing and Email Scams
Phishing involves fraudulently acquiring sensitive information through masquerading
a site as a trusted entity. (E.g. Passwords, credit card information)Provisions
Applicable:- Section 66, 66A and 66D of IT Act and Section 420 of IPC
Theft of Confidential Information
Many business organizations store their confidential information in computer
systems. This information is targeted by rivals, criminals and disgruntled
[Link] Applicable:- Sections 43, 66, 66B of IT Act and Section 426 of
Indian Penal Code.
Source Code Theft
A Source code generally is the most coveted and important “crown jewel” asset of a
[Link] applicable:- Sections 43, 66, 66B of IT Act and Section 63 of
Copyright Act.
Tax Evasion and Money Laundering
Money launderers and people doing illegal business activities hide their information
in virtual as well as physical [Link] Applicable: Income Tax Act and
Prevention of Money Laundering Act. IT Act may apply case-wise.
Online Share Trading Fraud
It has become mandatory for investors to have their demat accounts linked with their
online banking accounts which are generally accessed unauthorized, thereby leading
to share trading [Link] Applicable: Sections 43, 66, 66C, 66D of IT Act
and Section 420 of IPC