0% found this document useful (0 votes)
5 views37 pages

07 Chapter 3

The document discusses the legal framework for cyber crimes in Indian banking, highlighting the role of the Information Technology Act, 2000, and the Bharatiya Nyaya Sanhita in addressing issues like hacking, identity theft, and online fraud. It emphasizes the need for robust laws to protect customers and enhance trust in digital banking, while also critiquing existing legislation for its inadequacies in tackling modern cyber threats. The study aims to evaluate the effectiveness of current laws and suggest improvements to better combat cybercrime in the banking sector.

Uploaded by

2021382278.ankit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views37 pages

07 Chapter 3

The document discusses the legal framework for cyber crimes in Indian banking, highlighting the role of the Information Technology Act, 2000, and the Bharatiya Nyaya Sanhita in addressing issues like hacking, identity theft, and online fraud. It emphasizes the need for robust laws to protect customers and enhance trust in digital banking, while also critiquing existing legislation for its inadequacies in tackling modern cyber threats. The study aims to evaluate the effectiveness of current laws and suggest improvements to better combat cybercrime in the banking sector.

Uploaded by

2021382278.ankit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CHAPTER 3

LEGAL FRAMEWORK FOR CYBER CRIMES IN INDIAN


BANKING

3.1 INTRODUCTION
Cyber threats like phishing, hacking, identity theft, and unauthorised transactions
have escalated in tandem with the quick growth of internet banking. A robust legal
framework aids in defining offences, imposing punishments, and safeguarding
customers. It is mainly governed by the Bhartiya Nyaya Sanhita (BNS) and the
Information Technology Act, 2000 (IT Act). Additionally, it gives law enforcement
the authority to look into and bring charges against cybercriminals. Customers' trust in
digital banking is further increased by Reserve Bank of India (RBI) laws that require
banks to put strict cyber security safeguards in place. A safer banking environment is
promoted by effective law that not only discourages scammers but also guarantees
victims legal redress. An increasingly vital and required part of the Indian banking
sector is web technology. The global expansion of non-monetary dependant purchases
has aided in the continuous development of robust online payment systems. The
current study intends to assess the problems with cybercrimes in the e-banking sector
by addressing the numerous crimes that commonly occur in the Indian banking sector.
To create effective preventative measures, it is essential to assess the core of these
offences. (Kalpana & Mahalakshmi, 2020).

This Act is a first Act with certain restrictions, but it does contain provisions that
identify and impose penalties for cybercrimes. The biggest issue with the IT Act of
2000 in relation to electronic banking is that, despite the fact that negotiable
instruments are the mainstay of the banking sector overall, the entire Negotiable
Instrument Act is not covered by this act. The Negotiable Instrument Act was
amended in 2002 to address abbreviated and electronic checks; the Information
Technology Act of 2000 does not assist in combating cybercrimes. (Information
Technology Act, 2008).

52
Chapter-3

Table 3.1 Relevant Committees Formed for Banking Reforms


Name of Year Main Recommendation
[Link]. Chairman
Committee Constituted
Recommended reduction in SLR
Narasimham M. and CRR, recapitalization of
1 1991
Committee I Narasimham banks, and phased reduction of
public sector ownership.
Emphasized NPA reduction,
Narasimham M. creation of Asset Reconstruction
2 1998
Committee II Narasimham Funds, and greater autonomy for
public sector banks.
Identified seven types of
irregularities committed by banks
Janakiraman A. C.
3 1992 in the operation of the PMS
Committee Janakiraman
(Portfolio Management Scheme)
system.
Suggested precautions and
Committee on
enhancements in audit practices to
4 Internal Inspection A. Ghosh 2013
avoid fraud and malpractice in
and Audit
banks.
Expert Committee Proposed draft legislation to
5 on Legal Aspects N. L. Mitra 2001 address legal dimensions of bank
of Bank Frauds frauds –(Annexure-1).
RBI Committee Recommended the development
for Review of and publication of a “Customer
6 B. P. Kanungo 2022
Customer Service Service and Protection Index” by
Standards the Reserve Bank of India.
Fifty-Ninth Report Recommended creation of a
Jayant Sinha
on ‘Cyber Security centralized regulatory authority
(Chair);
and Rising for cyber security; establishment
7 Standing 2023
Incidence of of a Central Negative Registry.
Committee on
Cyber/White
Finance
Collar Crimes’
Parliamentary Reiterated the need for a
Committee on centralized overarching regulatory
‘Cyber Security authority focused on cyber
8 and Rising Jayant Sinha 2023 security, similar to aviation sector
Incidence of oversight bodies.
Cyber/White
Collar Crimes’
Standing Further evaluated the cyber/white
Committee on Bhartruhari collar crime landscape and
9 2024
Finance (2024 Mahtab endorsed prior committee
review) recommendations.

Regardless of regional boundaries, everything is now digitally recorded. Because of


these consequences, strict laws are needed to regulate illegal conduct in cyberspace
and protect technological advancement. These developments led to the passage of the

53
Chapter-3

E-Commerce Act of 1998. Two years after the previous law's passage, on October 17,
2000, the Indian parliament passed the "Information Technology Act, 2000". This
comprehensive regulation addressed technological advancements in online banking,
electronic governance, and electronic commerce as well as penalties and
consequences for cybercrime. The IT Act of 2000 was primarily passed in order to
impose severe penalties for various forms of online illegal conduct. The researcher
has tried to evaluate the effect of cybercrime on Indian e-banking in this study. There
is the Information and Technology Act of 2000, but it is flawed in many ways. The
Information Technology Act, 2000 (IT Act). Sections 43, 66, 66C, and 66D of the IT
Act prescribe penalties for offences like hacking, identity theft, phishing, and
unauthorised access to computer systems. The Reserve Bank of India (RBI) has also
given banks rules on cyber security and safeguarding customers from fraud. Through
local law enforcement agencies or the National Cyber Crime Reporting Portal, victims
can report cyber fraud. (Ministry of Home Affairs, 2023).

3.2 LEGAL FRAMEWORK FOR CYBER BANKING CRIMES IN INDIA


The rapid advancement of computer technology has given rise to a new type of
criminal conduct called cyber-attacks. This paper examines the Indian judicial system
in detail, paying particular attention to how it responds to the various problems
brought on by cybercrimes. India's rules against cybercrime are based on the
Information Technology Act of 2000. This study's main goals are to identify the
inherent difficulties and potential areas for the legal system to develop, as well as to
evaluate how well the current laws work to deter different types of cybercrimes,
including identity theft, online fraud, hacking, and data violations. The study critically
assesses how significant changes to the Information Technology Act, especially those
implemented in 2008, have affected cyber threats. The study highlights the difficulties
caused by the rapid progress of technology, which frequently falls short of legal
flexibility. In the contemporary digital world, the importance of data protection
cannot be overstated. Laws protecting personal information from theft, abuse, and
unauthorised access are becoming more and more necessary as more people utilise the
internet and other digital communication channels. These rules place a lot of emphasis

54
Chapter-3

on data protection, which is crucial for detecting violations related to using computer
networks and the internet.

These laws outline the guidelines, sanctions, and processes for handling online
offences. India has a number of important cyber legislation, such as:

The Information Technology Act, 2000


The Information Technology Act (IT Act), which was passed in 2000, is the main law
in India that addresses cybercrimes. It covers a wide range of offences related to
identity theft, hacking, illegal access, internet fraud, and information breaches. It
offers a thorough framework for managing activities and interactions online, as well
as for ensuring that digital documents and e-signatures are accepted legally. The
primary cybercrime law in India is the Information Technology Act of 2000. The Act
was enacted to create a legal basis for electronic transactions and to fight cybercrime.
The Act describes the consequences for several cybercrime-related offences,
including as hacking, phishing, and identity theft. Cybercrime charges under the
Information Technology Act of 2000 fall under three categories: data theft, computer
system damage or tampering, and illegal access to computer systems. The Act
outlines jail time and fines as sanctions for a number of cybercrimes. Other offences
covered by the law were sending abusive messages, uploading sexually explicit
material, and violating confidentiality. It also provided more effective means of
combating cybercrime and keeping up with rapidly evolving technologies. (Panwar
2023)

In order to facilitate e-commerce, it tackles a variety of cybercrimes, including


identity theft, hacking, and cyber terrorism. It also grants legal legitimacy to
electronic transactions.

Crucial components related to cyber fraud include:


Hacking of Computer Systems
Hacking is the act of destroying, altering, lowering the value, or decreasing the
usefulness of any data that is part of a computer resource, or utilising any other

55
Chapter-3

method to do so. Hacking of computer systems is forbidden by Section 66 of the


Information Technology (IT) Act of 2000 in India. However, there isn't a specific
section in the Act called Section 66. Instead, many sections of the IT Act deal with
hacking penalties. Section 66 of the Information Technology Act, which addresses the
crime of hacking, is one example. Depending on the applicable jurisdiction and
version of the law, Section 66's exact wording and provisions may vary.

According to Section 66 of the IT Act, it is generally unlawful to gain unauthorised


access to computer systems or networks with the intent to damage or disrupt them. It
could entail actions such as unauthorised computer access, hacking, or virus infection.
(The Information Technology Act, 2000)

Hacking
According to Sections 43 and 66 of the Act, "hacking" refers to a wide variety of
dishonest or fraudulent activities that are carried out without the owner's or owner's
representative's permission and that include system management. This encompasses
the previously mentioned region. The penalty for this offence is as follows:

Table 3.2 Penalty for Offences


Section Offence Penalty
66 Hacking a computer system with A punishment of up to Rs 500,000,
the knowledge or intention of three years in prison, or both.
causing unjustified loss
43 computer, computer system, etc. The impacted individual may receive
damage. compensation of up to Rs 1 crore.

Section 66: Identity Theft and Hacking


It is against the law to dishonestly or fraudulently hack a system or steal login
credentials. A fine of up to ₹5 lakh and/or three years in prison are the possible
punishments.

56
Chapter-3

Section 66C: Penalties for identity theft.


Fraudulent use of another person's password, digital signature, or unique identifying
feature (such an OTP or card number) is prohibited. Penalties include up to three
years in prison and a fine of up to ₹1 lakh.

Section 66D: Penalties for utilising computer resources to cheat by impersonation.


Personation-Based Cheating (Fraud and Phishing Calls) It is illegal for someone to
deceive by assuming the identity of another individual (for example, scammers posing
as bank officials to get OTPs). Penalties include a fine of up to ₹1 lakh and up to three
years in prison.

Section 72 & 72 A: Penalty for breach of confidentiality and privacy


If banks or their staff reveal client information without authorisation, they risk fines
and even jail time.

Section 43: Penalties for computer system damage. Penalty for Unauthorised Entry. A
person is responsible for compensating the impacted party if they gain unauthorised
access to a computer, download data, or cause harm and covers unauthorised fund
transfers in e-banking, hacking, and phishing. (Government of India, 2024)

The purpose of the 2008 Modified IT Act is to strengthen its provisions against
emerging cyber threats. It increased the punishments for some cybercrimes and
established new ones, including as e-terrorism, the dissemination of graphically
explicit material, and illegal digital eavesdropping.

IT Act, 2000 – Clause-by-Clause Critique


Section 43: Restitution for Computer System Damage
Section 43 is rarely used in cases of financial fraud, despite the fact that it offers
compensation for unauthorised access, data theft, or damage to computer systems,
including unauthorised fund transfers in e-banking. The heavy burden of proof and
the absence of an effective system for calculating damages are the main causes.

57
Chapter-3

Instead of filing civil claims under this clause, victims typically use RBI's cyber-fraud
grievance procedures to seek remedy.

Section 43A: Liability of Corporations


Section 43A, which holds body corporates accountable for failing to secure sensitive
personal data, is still ambiguous and not very well enforced. Although it calls for
evidence of carelessness, it is unclear what exactly qualifies as "reasonable security
practices." Banks and other financial intermediaries lack a standardised due diligence
norm, which results in uneven interpretation and little protection against corporate
data breaches.

Section 66: System Breach and Hacking


Despite punishing dishonest or fraudulent hacking, Section 66 is not very useful in the
financial industry. Proving intent and tracking down digital evidence across several
networks are difficult tasks for investigators. Consequently, despite an increase in
instances of unlawful digital access in financial systems, prosecution under this
section is rare.

Section 66C: Theft of Identity


Modern cyber-frauds like SIM-swap, QR code scams, and phishing are not adequately
covered by Section 66C, which addresses the fraudulent use of another person's
credentials, such as passwords, OTPs, or card numbers. In contrast to direct credential
misuse, which is not addressed in this section, these crimes take advantage of telecom
or app-level vulnerabilities. Its efficacy is further constrained by telecom and financial
operators' lack of intermediary liability.

Section 66D: Personation Cheating with Computer Resources


Phishing and vishing calls are examples of impersonation trickery that is punishable
under Section 66D. It does not, however, specifically include new crimes like
automated payment-link frauds, UPI-based frauds, or AI-driven impersonation. In
contrast to the intricacy of contemporary social engineering strategies, the statutory
terminology is restrictive and antiquated.

58
Chapter-3

Sections 72 and 72A: Violating Privacy and Confidentiality


Unauthorised disclosure of information acquired during service delivery or under the
Act is punishable under these provisions. They focus on individual wrongdoers rather
than institutional misbehaviour, despite having a good philosophical foundation.
There is no framework in place to define safe data-sharing procedures between
financial institutions or to regulate systematic privacy violations in digital banking.

An overview of the observation


The scope of the IT Act was broadened by the 2008 amendment, however there are
still large legislative loopholes. The Act is deficient in: specific crimes for automated
transfer manipulation, SIM-swap, and UPI fraud; sector-specific requirements for
banks' due diligence; and methods for international collaboration in the exchange of
cyber-evidence. As a result, while being a foundational law, the IT Act of 2000 is still
ill-prepared to handle the sophisticated, high-velocity nature of cyberbanking crimes
in India today.

Bharatiya Nyaya Sanhita 2023


Legal measures to address e-banking frauds are also provided under the BNS.
Theft: The crime of stealing is now covered under Sections 303 to 307 of the
Bharatiya Nyaya Sanhita, 2023 (BNS). Fraud involving e-banking is not particularly
covered in these sections. Theft occurs when money is fraudulently removed from a
bank account through internet means. Penalty: a fine, a maximum sentence of three
years in prison, or both. Section 304 of the BNS now covers (punishment for theft).
The Criminal Breach of Trust - A bank employee or other authorised individual may
face charges under these laws if they mishandle money entrusted to them. Penalty: A
fine, three years in jail, or both. Similar to the provisions under the IPC, this offence
carries a jail sentence and a fine under section 316 of the BNS.

Fraudulent Transactions and cheating


These categories include phishing, online fraud, ATM fraud, and impersonation fraud.
For instance, someone calling under false pretences as a bank employee requests

59
Chapter-3

OTPs in order to take out cash. Section 319 of the BNS now includes the definition
and rules pertaining to cheating.

Section 318 of the BNS includes a fine and up to seven years in jail. Sections 337 &
338 of BNS deal with forgery and Forgery occurs when a fraudster fabricates a digital
signature, bank document, or email in order to perpetrate fraud. Penalty: A fine, up to
two years in jail, or both. Section 316 provides Forgery with the Intent to cheat and it
is illegal to fake a card, document, or digital signature in order to conduct fraud.
Penalty: A fine and up to seven years in jail.

Using False Documents as Real under Section 319, BNS. A fraudster may face
consequences if they withdraw money using a phoney bank statement, ID, or email.
The same penalties as forgery apply, which include a fine and up to seven years in
jail.

Extortion (Threatening for Money) Section 302 in BNS, 2023. Sec 304 provides that a
person may be charged with extortion if they intimidate a bank employee or customer
to carry out a fraudulent transaction. Penalty: A fine and up to three years in jail.

Section 351 of the BNS is now used to punish criminal intimidation. The severity of
the threat dictates the penalty. The maximum penalty for general intimidation is two
years in prison, a fine, or both. The maximum penalty for threats of death, serious
offences, arson, or serious injury is seven years in prison, a fine, or both.

Fraudulent Attempt under Section 41 of the BNS, 202 provides that if someone's
attempt to engage in e-banking fraud fails, they could still be charged. Half of the
punishment for the planned offence is the penalty. (Ministry of Home Affairs, 2023).

Section 111(1) of the Bharatiya Nyaya Sanhita 2023 states that organised crime has
been added as a new offence. It includes crimes like kidnapping, extortion, and
cybercrime that are committed on behalf of a criminal organisation. (TaxMan, 2023).

60
Chapter-3

 Legal Recourse for E-Banking Fraud Victims. File a Complaint with the Bank:
According to RBI regulations, banks have ninety days to settle fraud complaints.
File a Complaint about Cybercrime: Go to [Link] or your local cyber
police station. Report the fraud to the authorities in accordance with BNS and IT
Act’s Sections 66C and 66D if the amount of the scam is substantial or involves
organised cybercrime. Go to the Banking Ombudsman: If the bank is not
answering, go to the RBI Banking Ombudsman and complain.

The Bharatiya Nagarik Suraksha Sanhita, 2023


Bharatiya Nagarik Suraksha Sanhita, 2023 regulates criminal activity is the Criminal
Procedure Code. It establishes how criminal offences, including cybercrime, would
be investigated, prosecuted, and punished. Rules for arrest, search, seizure, and bail
are also outlined. This new law aims to update criminal procedures and improve the
efficiency of the legal system.

The Bharatiya Nagarik Suraksha Sanhita (BNSS), 2023 provides key measures to
combat cyber frauds, particularly those that affect the banking sector:
 Electronic evidence is now formally recognised as admissible in court proceedings
by BNSS, 2023, which makes it easier to prosecute cybercrimes.
 Enhanced Investigative Measures: For the purposes of an investigation, inquiry, or
trial, the law allows the production of electronic communication devices that are
probably in possession of digital evidence. By strengthening the legal framework
against cyber frauds, these provisions hope to improve the efficiency of
investigations and prosecutions of crimes involving financial institutions and
banks. (Ministry of Home Affairs, 2023)
Bharatiya Sakshya Adhiniyam, 2023 (earlier known The Indian Evidence
Act,1872)
As part of the new legal changes the Indian government presented in 2023, the
Bharatiya Sakshya Adhiniyam, 2023 has replaced the Indian Evidence Act, [Link]
acknowledging electronic records and digital evidence as the main forms of proof in
court proceedings, this new law seeks to modernise the gathering of evidence,
particularly in the digital age. It also applies to charges of cybercrime. It lays out the
rules for allowing digital evidence like emails, chat logs, and social media to be

61
Chapter-3

included into criminal proceedings. The Act specifies the types of evidence that can
be used in court as well as how it must be presented and evaluated.

Banking related Legislations


Cyber fraud and e-banking schemes are not particularly addressed by the Banking
Regulation Act of 1949, which was passed long before the advent of digital banking.
However, some Indian rules and regulations combat e-banking frauds, such as:

Banking Regulation Act, 1949


Although the Act primarily governs banking operations, some of its provisions have a
tangential connection to preventing fraud:
Section 46: Penalties are imposed for bank officials who commit fraud.
Section 47A: Specifies penalties for failure to comply with RBI's cyber security and
e-banking directives. (Banking Regulation Act, 1949)

Consumer Protection Act of 2019


A comprehensive law shields customer from unfair business activities, including
those associated with e-banking scams. The pertinent sections and provisions are
listed below:

Service Deficiency (Section 2(11)) A deficit in service occurs when a bank does not
offer secure financial services, such as insufficient fraud prevention, slow response
times, or failure to reimburse unauthorised transactions. Customers have the right to
protest about banks for cyber security lapses, such as insufficient security measures
that allow for illegal activities. Example: A bank may be held accountable for a
service failure if it neglects to send out OTPs or notifications for questionable
transactions and fraud happens.

Injustice in Trade (Section 2(47) It may be deemed an unfair trade conduct if banks
deceitfully advertise their fraud prevention measures or mislead customers regarding
the security of online banking services. If banks don't inform clients about fraud
concerns, phishing, or new security measures, they could be liable.

62
Chapter-3

Example: A bank makes a misleading assurance that their net banking system is 100%
secure against fraud, but phishing attempts cause consumers to lose money. If the
bank provides false information, customers may file a lawsuit.

Digital Banking Platform Product Liability (Chapter VI, Sections 83-87) A bank may
be held liable for product responsibility if an e-banking app or digital payment service
has security holes that allow for fraud or hacking. covers instances in which users lose
money as a result of software flaws in UPI or mobile banking apps. For instance, if a
bank's mobile app has security flaws that hackers take advantage of to make illegal
withdrawals, the bank may be held accountable. Mechanisms for Consumer
Complaints (Sections 34, 47, 58) The National Consumer Helpline
([Link] allows consumers to register concerns online.
Depending on the amount lost, cases may be submitted to the National, State, or
District Consumer Commissions.

Jurisdiction Predicated on Loss:


a) Up to 1 crore rupees for the District Commission
b) ₹1 crore to ₹10 crore for the State Commission
c) Over ₹10 crores for the National Commission

Settlement for Online Banking Frauds: Customers are entitled to reimbursements,


damages, and emotional pain recompense. According to RBI's "Customer Liability in
Unauthorized Transactions" (2017), the bank is required to return the entire amount if
a fraud is notified within three days.
Example: A phishing fraud costs a consumer ₹50,000. The bank must return the entire
sum if the complaint is made within three days. Liability is limited if the report is
made within seven days but after three days. (Ministry of consumer affairs, food &
public distribution, 2025).

The Payment and Settlement Systems Act, 2007


The Payment and Settlement Systems Act, 2007 (PSS Act, 2007) was created in order
to regulate internet banking.

63
Chapter-3

The Regulation of Electronic Payment Systems, Sections 4 and 5 Digital wallets,


NEFT, RTGS, UPI, mobile banking, and internet banking are just a few of the
electronic payment technologies that the RBI has the authority to regulate and
manage. Banks and other financial institutions require RBI approval prior to
implementing a payment system. For example, any bank that launches a new e-
banking service, such as a mobile wallet or quick transfer system, is required by the
PSS Act to follow RBI guidelines.

Section 10: RBI's Authority to Issue Directives and Guidelines: To guarantee the
safety, effectiveness, and stability of electronic transactions, the RBI has the authority
to impose legally enforceable rules on banks. Data protection, cyber security
procedures, encryption, and fraud detection are all included in the guidelines. For
instance, e-banking users are guaranteed improved security banks to the RBI's
directive on two-factor authentication (2FA) for online payments.

Sections 17 and 18: Liability in E-Banking Fraud Cases: The RBI has the authority to
act against bankers or payment system providers for failing to comply with security
standards if a customer loses money as a result of fraudulent online transactions. If a
payment system doesn't stop fraud or doesn't follow the guidelines, the RBI can also
suspend or cancel its authorisation. For instance, the RBI has the authority to punish a
bank and cancel its payment service license if an online banking system is
compromised because of inadequate security.
Consumer Protection in Online Transactions, Sections 23 and 25: Procedure for
settling disagreements: Banks and payment service providers must provide a
grievance redressal process for problems involving online transactions. If there are
fraudulent transactions, customers are entitled to compensation. For example, the
bank must reverse the transaction in compliance with RBI requirements if a customer
reports an illegal debit transaction within three days.

Section 26-30: Penalties for Non-Compliance: Any bank or payment processor that
violates the Act may be subject to: Penalties of up to ₹5 lakh daily License revocation

64
Chapter-3

or suspension. Legal action for transactions that were false. For instance, the RBI may
limit a bank's digital payment services until security flaws are addressed in the event
of a significant online fraud. (Government of India, 2007).

By giving the RBI the authority to control payment systems, maintain cyber security,
and shield customers from fraud, the PSS Act of 2007 is essential to the security of e-
banking transactions. It provides a legal foundation for safe and effective digital
banking in India, working in tandem with other laws such as the Consumer Protection
Act of 2019 and the IT Act of 2000. (Fatima, 2016).

Prevention of Money Laundering Act (PMLA), 2002


Its primary objective is to prevent money laundering, terrorism financing, and
fraudulent transactions via banking systems.

Regulation of Suspicious Transactions (Sections 12 and 12A): It is mandatory for


banks and other financial institutions to report any suspicious banking activity to the
Financial Intelligence Unit-India (FIU-IND). Any suspicious or suspicious e-banking
transaction should be reported and investigated further.

For instance, banks are required by PMLA regulations to notify FIU-IND whenever a
fraudster uses credentials they have stolen to withdraw substantial amounts of money
through internet banking.
Know Your Customer (KYC) and Due Diligence for Customers (Sections 2 and 9):
All bank accounts must comply with KYC, which prevents fraudsters from creating
fictitious accounts in order to commit cybercrime. Before enabling UPI, mobile
banking, or internet banking, banks must confirm the identity of their clients.
Example: To launder money through online transfers, a fraudster attempts to register
an account using fictitious documentation. Under PMLA, the bank operates KYC
verification and block suspicious account.

Reporting E-Banking and Cyber Frauds (Sections 13 and 17): Banks are required to
notify law enforcement of any significant or suspicious e-banking transactions. FIU-

65
Chapter-3

IND and the Enforcement Directorate (ED) have the authority to look into money
trails in phishing, hacking, and card skimming frauds and freeze fraudulent bank
accounts. For instance, under the PMLA, the ED may confiscate and look into a
customer's bank account if it is used in a phishing scheme.

Monitoring Digital Payments to Stop Money Laundering (Sections 3 and 4): Banks
are required to monitor and report transactions connected to cybercrime networks and
online financial transfers. Illicit transactions done using crypto currency, digital
wallets, or online banking can be tracked by law enforcement. For instance, a hacker
uses an online banking breach to steal ₹10 lakhs and distribute it among several
accounts. Authorities can trace and freeze under PMLA.

Sections 4 and 8: Penalties and Punishment for E-Banking Fraudsters: Those who
commit cybercrimes, bank frauds, or digital payment scams are subject to the
following under PMLA: Three to seven years behind bars penalties (as much as the
money was laundered) Asset and bank account seizure. Banks that neglect to disclose
e-banking crimes risk fines as well. For instance, a scammer may exploit fraudulent
internet transactions to launder money overseas. Authorities are able to arrest,
prosecute, and take the accused's assets under the PMLA. (Ministry of finance, Govt
of India, 2002).

Legislations related to cyber security


Digital Personal Data Protection Act, 2023
Section 3(b) of the recently enacted Digital Personal Data Protection Act 2023
(DPDPA) states that the Act expressly addresses the handling of electronic personal
data outside of India. It contains particular guidelines for event reporting as well as
penalties for breaking those guidelines.

The Digital India Act, which would handle privacy, trust, and oversight, as well as
open internet rules and control the usage of cutting-edge developments like block
chain and artificial intelligence, is presently being worked on by the government to

66
Chapter-3

replace the IT Act. The DPDP Act has the following implications for Indian e-
banking:

Data Processing Based on Consent (Sections 5 and 6)


 Before collecting and processing consumer financial data, banks and fintech
companies must: Obtain express consent.
 Provide consent forms for digital banking services that are easy to comprehend
and unambiguous.
 Permit users to revoke their consent at any moment for the processing of their
data.
For instance, a bank needs your consent before sharing your transaction history
with a credit bureau or third-party loan app.

Limiting Purpose and Minimising Data (Sections 5 and 7)


 Only banks and financial service providers are able to: Gather the bare minimum
of information needed for a particular banking function.
 Data should only be processed and stored for as long as necessary; it should not be
kept forever.
 After the goal is achieved, delete the data (e.g., cancelling an inactive bank
account). For instance, a lending app cannot gather your contact information or
images in order to offer you a personal loan.

Bank and Fintech Data Breach Penalties


 A bank, fintech business, or digital payment provider that breaches the DPDP Act
may be subject to: A fine of up to ₹250 crore might be imposed for each
infraction.
 License Cancellation: If digital lenders or payment providers violate privacy
regulations, the RBI has the authority to cancel their licenses.
 Legal Action: Consumers who believe that banks have violated their privacy may
register complaints.

67
Chapter-3

For instance, a digital wallet app may be subject to severe fines and suspension under
RBI restrictions if it divulges user UPI information. (Ministry of Law and Justice,
2023). Banks, NBFCs, and fintech businesses are guaranteed to safeguard consumer
data, stop fraud, and offer transparency in digital banking by the DPDP Act of 2023.
In order to protect user privacy and rebuild confidence in India's digital financial
ecosystem, it enforces severe fines and regulatory obligations.

The Copyright Act of 1957


It safeguards artistic creations, especially copyright-protected electronic works. It
covers topics like online plagiarism, illicit copying and distribution of classified
works, and digital piracy. It safeguards confidential data, particularly copyright-
protected digital works. It covers topics like online plagiarism, illicit copying and
dissemination of protected works, and digital theft.

National Cyber Security Policy of 2013


Although this policy does not become law in and of itself, it does describe the Indian
government's plans to address cyber dangers and increase cyber security protections.
It highlights how important it is to protect vital information infrastructure and increase
public knowledge about cyber security.

The Companies Act of 2013


Members of the business community consider the Companies Act of 2013 to be the
fundamental legal basis for streamlining day-to-day operations. Companies who
violate this Act run the danger of facing legal consequences because it outlines the
necessary techno-legal regulations. Under the 2013 Firms Act, the Serious Frauds
Investigation Office (SFIO) was empowered to file lawsuits against Indian companies
and their directors.

Observance of NIST: The "NIST Digital Strategy" contains all of the comparisons,
best practices, and recommendations for managing cyber-related risks successfully.
(Ram, 2023)

68
Chapter-3

The IT Act of 2008, RBI regulations provide prohibitions to ensure a strong legal
framework against e-banking frauds. Victims should report frauds immediately and
pursue a lawsuit under Sections 43, 66, 66C, 66D, and 72A in order to protect
themselves and recover their losses. The Reserve Bank of India's (RBI) June 2016
Cyber Security Framework in Banks contained several significant guidelines for
dealing with and preventing cyber frauds. The framework emphasised a proactive,
risk-based approach to cyber security and fraud prevention, especially in relation to e-
banking crimes. The following is a list of the key provisions concerning cyber scams:

3.3 POLICY FRAMEWORK


Cyber Security Framework in Banks (June 2016 Policies)
Card purchases, mobile banking, and online banking all require multi-factor
authentication (MFA) putting in place risk-based transaction monitoring tools to
quickly identify fraudulent activity. Sensitive information (passwords, OTPs, and
client credentials) should be encrypted to avoid unwanted access.

Fraud Detection and Reporting in Real: Time To spot questionable e-banking


transactions, banks need to implement AI/ML-based fraud detection systems. High-
value transactions, odd login habits, and repeated unsuccessful authentication
attempts are examples of anomalies that need to set off notifications right away.
Major Cyber fraud events must be reported to the RBI's Cyber Security and IT
Examination Cell (CSITE) within the allotted time frame.
Awareness & Protection of Customers: All e-banking transactions must have real-
time transaction alerts (email, SMS) implemented by banks. Using self-service
portals, provide consumers the option to restrict or prevent online transactions.
Frequent attempts to educate users of e-banking about malware, phishing, and vishing
risks.

Secure Payment Methods & Security of Mobile Banking enhancing security for
mobile banking, RTGS, NEFT, IMPS, and UPI transactions. Card data is tokenised to
stop illegal card use. Geo location tracking is being used to detect odd login attempts
from various locations.

69
Chapter-3

Risk Management for Vendors and Third Parties: The RBI's cyber security standards
must be followed by third-party service providers managing e-banking infrastructure,
according to banks rigorous due diligence and frequent audits of payment gateways
and fintech partners. Incorporating fraud analysis techniques into payment systems
used by third parties.

Response & Remediation for Cyber Fraud: Create a Cyber Crisis Management Plan
(CCMP) to address instances of e-banking fraud. Establish a specialised fraud
response team to examine and lessen monetary losses. Tool for resolving customer
complaints with quick turnaround times.

Prevention and Mitigation Strategies for Cyber Fraud (2016 Guidelines)


Risk Assessment and Monitoring for Cyber Fraud. Banks had to use cutting-edge
technologies like AI/ML to set up a real-time fraud monitoring system. It was advised
to use transaction anomaly detection systems (TADS) to spot questionable activity in
online banking. Banks were required to regularly evaluate the risk of their payment
infrastructures and IT systems.

Reporting and Reaction Mechanism. Every case of cyber fraud required to be


reported to the RBI. A system for real-time fraud detection and response was
proposed in order to prevent monetary losses.
Awareness & Protection of Customers In order to avoid fraud, online banking
transactions were required to use multi-factor authentication (MFA). In order to detect
anomalous transactions, banks have to put in place consumer alert systems.
Customers have to be informed about phishing, vishing, and other cyber fraud tactics
through periodic awareness programs.

Ecosystem for Secure Digital Payments. Bolstering UPI, IMPS, and NEFT
transaction fraud detection systems in real time. Sensitive consumer data is encrypted
and tokenised to stop financial fraud. (Reserve Bank of India, 2016)

70
Chapter-3

RBI Guidelines – Limitations


Non-enforceable nature: Digital Payment Security (2021) and Cyber Security (2016)
RBI circulars are compliance recommendations rather than criminal statutes. They
don't establish enforceable rights or offences, and they don't have statutory force.
Implementation gap: Because banks view these rules as procedural compliance, they
are not consistently enforced, and their deterrent power is limited.

Customers are only protected under the Customer Liability Framework (2017) if
illegal transactions are detected as soon as possible (within three working days).
Financial responsibility is transferred to the client when reporting is delayed.

Evaluation: places the onus of proof and accountability on customers rather than
institutions. violates the rules of consumer protection since buyers are frequently
ignorant or lack technological skills. No enforcement of penalties or refund for banks
that refuse or postpone payments. In conclusion, RBI guidelines provide little
consumer protection while being progressive because they are not laws and are not
strictly enforced.

Additional Strengthening Following 2016, the RBI reinforced these safeguards with
new guidelines and circulars: Fraud reporting had to be done within 24 hours,
according to the Fraud Risk Management Guidelines (2017, 2019, 2021).
Strict security regulations for digital transactions were implemented under the Digital
Payment Security Controls (2021). For financial organisations, the Cyber Resilience
Framework (2023) added more security tiers.

3.4 JUDICIAL PERSPECTIVE


The Indian Supreme Court has voiced worries on a few times over the security of the
nation's banking sector.

1. Reserve Bank of India v. Jayantilal N. Mistry (2016) 3 SCC 525 In this case, the
Indian Supreme Court ruled that banks must safeguard the privacy of their customers'

71
Chapter-3

information and actions. The judge also noted that the RBI can regulate and oversee
banks' internet security measures. Consequently, it was determined that RBI was
required to comply with the provisions of the RTI Act and furnish the sought data.

2. K. Sputnik v. Union of India and Others (2018)


In this instance, the security of mobile banking transactions was in question.
According to the Supreme Court, banks must ensure that their mobile banking apps
are secure and that their customers are shielded from online fraud and counterfeiting.

3. K.S. Puttaswamy (Retd.) and Others v. Union of India (2017) 10 SCC 1, AIR
2017 SC 4161
People have the fundamental right to privacy and the right to protect their personal
information from internet threats, according to the Supreme Court. The Court
determined that the freedoms safeguarded by other fundamental rights depended on
the right to privacy.
Analysis: Financial data is covered by the Supreme Court's recognition of privacy as a
fundamental right. As a result, banks are required by the constitution to preserve
consumer information, and careless treatment may constitute a privacy breach.

4. Jayantilal N. Mistry v. India's LIC (2015)


The importance of the insurance sector implementing cyber security measures was
underlined by the Supreme Court. The court underlined how crucial it is for financial
institutions, like insurance companies, to safeguard the privacy and security of their
customers' data. It constituted a basic element of dignity, autonomy, and liberty.
(Shukla, 2023)

5. Subhash Chand Bansal v. ICICI Bank Ltd. (2006) AIR 2006 SC 3127
Problem: Negligent financial security and unauthorised transactions.
Held: Before handling online transactions, banks have an obligation to make sure that
the right security measures are in place and to confirm the identity of the consumer.
The significance of multi-layered security protocols in online banking was
underscored by the court.

72
Chapter-3

6. Naresh Kumar v. Axis Bank Ltd. (2013) 2 DLT 127


Problem: Phishing attempt resulting in unauthorised money withdrawal.
Held: If banks don't put strong security measures in place or teach their clients how to
avoid cyber fraud, they could be held accountable for losses brought on by phishing
attempts.
Analysis: The Court ruled that banks had an obligation to protect internet
infrastructure and consumer accounts. Even in the absence of evidence of direct
negligence, failure to maintain sufficient precautions constitutes a fault in service. The
decision established that if system controls are poor, banks cannot use client error as
an excuse to avoid accountability.

7. Ajay Kumar Aggarwal v. SBI AIR 2017 Del 233.


Problem: unauthorized use of online banking to access a customer's account.
Held: The bank was found to have been negligent in failing to identify questionable
transactions and notify the account holder in a timely manner, which resulted in the
bank being held accountable for the losses sustained.

8. State of Maharashtra v. N.N. Global Mercantile Pvt. Ltd. (2021) 4 SCC 379
Problem: Online banking cybercrime and contractual duties. Held: The Supreme
Court made it clear that banks have fiduciary obligations to safeguard the interests of
their clients, particularly in the rapidly changing world of online banking.

Indian courts have repeatedly held that banks have an increased responsibility to
safeguard their clients from online fraud. Bank liability frequently results from
inadequate security infrastructure or from failing to notify clients of questionable
activity.

9. Tarun chowdhury v. Branch manager, State bank of India, Chandannagar


branch Order 14 (09/02/2016)
In this instance, the complainant lacked an internet banking password and failed to
reveal the password for his ATM card. Unauthorised transactions nevertheless took

73
Chapter-3

place. The court emphasised the bank's obligation to safeguard client accounts against
fraudulent activity by holding the bank accountable for the unlawful payment transfer.
(casmine, 2016)

10. Pallabh Bhowmick and four others v. State Bank of India (13.09. 2024)
The Supreme Court orders SBI to reimburse the consumer, citing the need for banks
to be on the lookout for fraudulent activity. (Indian Kanoon, 2002).

Zero Customer Liability: In the event of an unauthorised transaction, a customer has


the following rights related to zero liability: (i) The bank's involvement in fraud,
carelessness, or error (whether or not the customer reports the transaction). (ii) When
a consumer notifies the bank of an unauthorised transaction within three business days
of getting notification from the bank, and the deficiency is found elsewhere in the
system rather than with the bank or the client, this is known as a third-party breach.
(Reserve Bank of India, 2017).

India has a serious threat from cybercrime, so the government has acted by enacting
numerous laws to tackle it. The primary cybercrime law in India is the Information
Technology Act of 2000. Other laws, such as the Indian Evidence Act, the Criminal
Procedure Code, and the Indian Penal Code, also apply to cybercrime proceedings.
These regulations address a wide range of behaviours, such as phishing, hacking, and
online harassment and stalking. These rules must be properly applied in order to
prevent cybercrime and protect the interests of Indian citizens and businesses.
(Panwar, 2023).

11. The Punjab National Bank scam of 2018: One of the largest banking scams in
India has resulted in the loss of over INR 11,000 crores through fraudulent
transactions. The scam was executed using illegal letters of undertaking (LOUs)
droughted by bank employees, highlighting the need for robust cyber security
protections and the flaws in control systems.

74
Chapter-3

12. Cosmos Bank cyber-attack, (2018) hackers used malware to gain login to the
bank's computers and stole INR 94 crores. The incident demonstrated the importance
of real-time threat detection and detection systems and exposed the bank's internet
privacy flaws.
Analysis: The 94-crore malware-based SWIFT assault revealed significant
weaknesses in international cooperation, interbank coordination, and cyber-security. It
emphasised the shortcomings of the IT Act of 2000, which does not include
provisions for mandatory cyber-incident reporting for banks or cross-border inquiry.

13. Phishing Scams at Yes Bank (2020): Several phishing schemes exploited Yes
Bank customers, resulting in significant financial losses. Through the use of phoney
emails and messages to trick victims into divulging their banking information, the
scams highlighted the need for increased public awareness and education on cyber
security. (Anil Kumar, 2024)

14. HDFC Bank Ltd. v. Nikhil Kothari (2020): The District Consumer Forum in
Mumbai found HDFC Bank accountable under Section 43A of the IT Act for its
failure to put appropriate security measures in place, which resulted in illegal access
and monetary loss for the client. The court's role in upholding cyber security
standards was highlighted when the bank was ordered to reimburse the client.

15. ICICI Bank Ltd. v. Reserve Bank of India (2019): the court maintained the
RBI's right to impose fines on ICICI Bank for failing to adhere to its cyber security
policies. The ruling reaffirmed the RBI's Cyber Security Framework's legal authority
for financial institutions and underlined how crucial it is to follow sector-specific
cyber security guidelines in order to maintain systemic security and regulatory
compliance. (Indian Kanoon, 2002)

16. A.M. Shah & Others v. Cognizant Technology Solutions India Pvt. Ltd., 2018
SCC Mad 24901 (Madras High Court)
In this instance, former Cognisant workers were found guilty of identity theft and
utilising credentials they had acquired to gain unauthorised access to private company
information. Important legal provisions were applied by the court, including: Identity

75
Chapter-3

theft under Section 66C of the IT Act Section 66D of the IT Act: Using computer
resources to cheat by impersonation IPC Sections 419 and 420: Personation fraud and
dishonestly obtaining property delivery. The Madras High Court maintained their
conviction, reaffirming the significance of cyber law provisions in safeguarding
business data integrity and digital identity.

17. State of Maharashtra v. Amit Jani, 2018 Bombay High Court (Nagpur
Bench) SCC
According to Section 72A of the material Technology Act of 2000, the appellant,
Amit Jani, was charged in this instance with violating confidentiality by allegedly
obtaining private and sensitive material without authorisation. The court underlined
that such infractions carry criminal penalties of up to three years in prison, fines of up
to ₹5 lakh, or both. This decision emphasised the need of upholding confidentiality
requirements and reaffirmed the legal repercussions of neglecting to secure personal
data. (Indian Kanoon, 2002)

The Court's Perspective on Liability and Negligence


When there are insufficient precautions or delays, courts typically hold banks
accountable; customers are only held accountable when egregious negligence (such as
distributing OTPs) is demonstrated. Unless there is demonstrable misconduct,
intermediaries are rarely held accountable. Although varied verdicts underscore the
need for a clear regulatory framework defining cyber carelessness and accountability
in digital banking, Indian courts often see cyber fraud as the consequence of
institutional failure.

3.5 MISCELLANEOUS
The Indian cyber-crime coordination(I4C)
The Indian Cybercrime Coordination Centre plan was approved on October 5, 2018.
Its goal since the beginning has been to increase the nation's overall ability to fight
cybercrimes and promote effective collaboration amongst law enforcement. On
January 10, 2020, the Hon. Home Minister dedicated the I4C to the country. Beyond
national boundaries, cyberspace oversees Fighting cybercrime requires coordination

76
Chapter-3

at all levels among several parties in different jurisdictions. Cybercrime is one of the
forms of international crime that is growing at the quickest rate. The increase in
internet usage and the quick development of new technology have led to an
exponential rise in cybercrime globally.

In order to address this problem, MHA formed an Expert Group to investigate the
weaknesses and challenges, develop a strategy for effectively addressing cybercrime
in the country, and offer relevant guidance on all facets of cybercrime. After
recognising the shortcomings and challenges in the current strategy, the Expert Group
developed specific recommendations to address cybercrime in the country. The
Expert Group recommended the creation of the Indian Cybercrime Coordination
Centre (I4C) as a means of strengthening the entire security framework in the fight
against cybercrime.

To act as the centre of the country's initiatives to combat cybercrime. Make it easy to
report cybercrime and identify trends and patterns in the crime. help prevent and
identify cybercrime by acting as a proactive early warning system for law
enforcement. educating the public on the need of stopping cybercrime (Government
of India, Ministry of Home affairs, 2025)

NCRP, or the National Cybercrime Reporting Portal: The NCRP was introduced
on August 30, 2019, and it allows citizens to report financial frauds and other
cybercrimes online. The appropriate State or Union Territory receives complaints
automatically and takes appropriate action.

CERT-In, the Indian Computer Emergency Response Team


Reports on vulnerabilities, warnings, and cyber security alerts are issued by the
Ministry of Electronics & IT's national nodal agency (MeitY).

It offers incident response services for security breaches and cyber-attacks. (Ministry
of electronics & Information Technology government of India, 2025)
Cyber Swachhta Kendra (Centre for Malware Analysis and Botnet Cleaning)

77
Chapter-3

It provides free antivirus software to eliminate malware from compromised systems


and helps individuals and companies detect and eliminate malware. This facility
collaborates closely with product/antivirus companies and Internet vendors. This
website offers users information and tools to help protect their systems and devices. In
compliance with Section 70B of the Information Technology Act of 2000, this
organisation is managed by the Indian Computer Emergency Response Team (CERT-
In). (Ministry of Electronics and Information Technology of India, 2025).

Cybercrime Helpline Number: By contacting the specialised helpline at 1930,


citizens can report financial scams and receive timely support and action.
(Government of India, Ministry of Finance, 2024)

Consumer Helpline: National Consumer Helpline (NCH) Telephone: 1800-11-


4000 (Toll-Free) Website: [Link] For complaints: Against
financial service providers, digital wallets, or banks.

Cybercrime Cell or Local Police Visit:


Regular police station or the closest cybercrime police station. For serious financial
fraud cases, filing a formal complaint is crucial. Speak with the Cyber Crime Cell in
your city; these are found in major cities such as Delhi, Mumbai, Bangalore,
Hyderabad, and others.

Suspect Repository Facility: This function helps prevent fraud by enabling users to
cross-reference suspicious URLs, email addresses, account numbers, and cell numbers
with a database of known cybercriminals.

Cyber Awareness Initiatives: In order to educate the public about potential cyber
threats and protective measures, I4C places a strong emphasis on issuing alerts, safety
advice, and awareness campaigns. (Government, Ministry of Home affairs, 2024).

Additionally, the Reserve Bank of India (RBI) has recommended that banks
implement robust cyber security monitoring and robust measures to prevent online
fraud. In January 2025, the RBI emphasised the importance of stricter regulation of

78
Chapter-3

third-party service providers in order to mitigate associated risks. (Mukherjee, 2025)


'[Link]' for banking organisations and '[Link]' for non-banking financial
organisations are exclusive domain names that the RBI announced in February 2025
to counteract fraudulent online activity. By giving reputable financial institutions a
distinct online persona, this effort seeks to lower the likelihood of phishing and other
online frauds. (Nayak, 2025).

Additionally, cooperative initiatives like Google's 2023 launch of DigiKavach


complement I4C and the 1930 Cyber Crime Helpline to offer victims of financial
fraud information and assistance while guaranteeing a prompt reaction to new threats.
Building on DigiKavach, its anti-fraud program, Google plans to launch its Safety
Engineering System by 2025. Sections 43(c) and 43(e) of the Information Technology
(Amendment) Act, 2008, provide legal redress. The legal punishment for "spreading
viruses" includes bail requirements and compounding with the approval of the court
prosecuting the case. The case may be heard in any court.

RBI Guidelines on Information Security, Electronic Banking, Technology Risk


Management, and Cyber Frauds
Strong information security and efficient technological risk management are essential
in today's quickly changing digital banking landscape. Through its Cyber Security
Framework in Banks (2016) and Master Directions on Information Technology
Framework for NBFCs (2017), the Reserve Bank of India (RBI) requires banks to put
in place thorough cyber security measures like data encryption, multi-factor
authentication, and recurring IT audits.

To fortify banks' digital infrastructure and guard against growing cyber threats, the
Reserve Bank of India (RBI) has released a number of instructions. While
guaranteeing the safe provision of electronic banking services, these principles seek to
improve the availability, confidentiality, and integrity of banking systems and
consumer data.
The RBI instructed all banks to create a board-approved cyber security strategy,
establish Security Operations Centres (SOCs), carry out vulnerability assessments,

79
Chapter-3

and promptly notify the RBI of any cyber events in its "Cyber Security Framework in
Banks" (2016) (RBI, 2016). The framework highlights the necessity of data
encryption, real-time threat monitoring, and restricted access to vital systems.

Standards for two-factor authentication, transaction monitoring, and consumer


protection in digital channels are outlined in the RBI's "Guidelines on Internet
Banking" (2001) and the "Master Directions on Digital Payment Security Controls"
(2021) for electronic banking. Additionally, these standards encourage banks to
inform their clients about QR code scams, phishing, and vishing.

These rules serve as the cornerstone of RBI's dedication to maintaining a safe and
robust digital financial system in India. (Reserve Bank of India, 2016) (Reserve Bank
of India, 2017).

The Reserve Bank of India's (RBI) 2023–2024 Report on Currency and Finance
(RCF) has been made public. The difficulties brought about by the banking sector's
quick embrace of digital technologies are highlighted in the research. According to
the paper, although technology has greatly expanded competitiveness and enhanced
bank efficiency in India, there are also considerable hazards associated with it.
According to the report, the average cost of data breaches in India increased by 28%
from 2020 to $2.18 in 2023. Cybercrime is predicted to cost the world $13.82 trillion
by 2028, up from $8.15 trillion in 2023. In India, phishing accounts for 22% of
cyber-attacks, while credentials that have been stolen or compromised account for
16%. (Anshul & Singh, 2024).

India has become a global leader in the digital space


With an astounding 936 million Internet users, India has become a global leader in the
digital space and one of the most connected countries in the world. Known as
"Digital Nagriks," Indians are progressively incorporating the internet into their daily
life and depending on it for basic necessities including financial transactions,
education, business dealings, and digital access to government services.
The Indian government has been putting strong regulations in place to protect its large
internet community because it understands how important a safe online environment

80
Chapter-3

is. In light of the increasing frequency of cyber threats and attacks in the linked world
of today, these steps are intended to guarantee a safe, trustworthy, and secure
cyberspace.

The Indian Computer Emergency Response Team (CERT-In), which was created as
the country's incident response agency under Section 70B of the Information
Technology Act of 2000, is essential to protecting India's online environment. CERT-
In guarantees prompt responses to reported cyber security incidents by running a 24-
hour incident response help desk. To improve cyber security across the country, the
organisation provides Security Quality Management Services in addition to complete
Incident Prevention and Response services. (PIB Delhi, 2024)

RBI’s New Guidelines to Prevent Online Frauds (Notification dated January 17,
2025)
1. Objective: To improve security and lessen the growing danger of online payment
scams, particularly those connected to improper usage of mobile numbers.
2. Mobile Number Monitoring: In order to identify any odd changes that might point
to possible fraud, banks and other financial institutions are required to update and
keep an eye on their customers' mobile numbers on a regular basis.
3. Real-time Alerts: Enhanced systems for informing clients in real-time of any
transactions or modifications to important account information.
4. Checks for SIM swapping and porting: Required verification procedures to detect
SIM swapping or porting activity before to authorising high-risk online
transactions. (RBI, 2025)

RBI & TRAI Guidelines to Prevent Online Frauds (2025)


1. Revocation List for Mobile Numbers (MNRL)
In order to identify deactivated mobile numbers used in fraudulent activities, banks
must use MNRL through the Digital Intelligence Platform (DIP).
SOPs are necessary for frequent database upgrades and integration.
2. Confirmed Customer Service Phone Numbers

81
Chapter-3

To increase transparency, banks will provide DIP with verified hotline numbers for
Sanchar Saathi publication.

3. Series of Dedicated Numbers


For service or transactional calls, use '1600xx'; for promotional calls, use '140xx'.
helps consumers spot phoney calls and steer clear of fraud.

TRAI Guidelines: In order to send calls or SMS, DLT registration is required.


Number series ('140' for promotions, '160' for transactions) and pre-approved
templates are the only ones permitted.

Penalties or disconnection for a maximum of two years may result from misuse.
Regional languages are being used for pre-call scam alerts. (RBI, 2025).

Protecting digital personal data is crucial for online banking, or e-banking. Privacy is
one of the most affected areas of modern technology. Privacy and contemporary
technology have always been at odds. In the nineteenth century, worries about the
growth of the mass media, notably newspapers, led to the establishment of legal
protections against the abuse of the public's right to know specific facts and the illegal
use of names. Radio transmissions were restricted by 20th-century laws against
eavesdropping, and these laws did not always keep up with the technological
advancements of modern digital services.

Summary List of the different kinds of e-banking frauds with the pertinent
statutes
The following lists the different kinds of cyber frauds involving e-banking in India
along with the pertinent statutes found in Indian law:

82
Chapter-3

Table 3.3 E-Banking Frauds and Relevant Statutory Provision


Type of Cyber Description Relevant Laws in India
Fraud
Phishing To get private information, scammers pose as Sections 43, 66C, and 66D of
banks or other financial organisations using the IT Act of 2000 and Sections
emails, messages, or phoney websites. 316(2) & 317 of BNS 2023

Vishing (Voice In order to obtain private banking information, Section 66D of the IT Act of
Phishing) scammers phone and pose as bank employees. 2000 and Sec 316(2) & 317 of
BNS 2023

Smishing (SMS Phishing SMS messages that request personal Sections 43, 66C, and 66D of
Phishing) banking information or contain harmful links the IT Act of 2000 and Section
317 of BNS 2023
Card Skimming To steal card information, scammers install Section 66 of the IT Act of
skimming devices on POS or ATM machines. 2000 and Sections 304 and 317
of BNS 2023
SIM Swap Fraud To get around OTP-based verification and gain Sections 66, 66C, and 66D of
access to accounts, scammers acquire a the IT Act of 2000 and Sec
duplicate SIM card. 316(2) & 317 of BNS 2023
Online Banking Using malware or hackers to get unauthorised IT Act2000 (Sections 43, 66,
Fraud access to bank accounts in order to carry out 72) (Sections 304, 317) BNS,
fraudulent transactions. 2023
UPI Fraud Unapproved UPI transactions through Sections 66C and 66D of the IT
phishing scams, phoney apps, or QR codes. Act of 2000 and Section 317 of
the BNS of 2023
Fake Loan Apps Through mobile apps, scammers provide BNS,2023 (Sections 317, 351)
Fraud phoney loan proposals, and then threaten and IT Act, 2000 (Sections
borrowers to extract money. 66D, 67)
Ransomware Cybercriminals demand ransom to unlock BNS, 2023 (Sections 302) and
Attacks personal accounts or banking systems. IT Act, 2000 (Sections 66, 66F)

The new normal seems to be data theft. They accept email addresses and passwords
along with other private data. Sensitive information on a person, group, or other entity
is made public through a data breach and may be misused in a number of ways. Name
theft is one method of obtaining someone else's personal information for financial
gain. (Toit, 2018). Regardless of the company's size or location, marketing and

83
Chapter-3

commerce should place a high priority on safeguarding digital personal data. Data
clusters are now an analytical part of any business operation. In the 21st-century cyber
world, where the digital economy is still thriving, data is a big financial asset. Despite
its efficacy and the importance of data security, it is challenging to convince the
market to protect data on its own. The inability of payments to increase their security
knowledge in order to stay up with computer and technical advancements is one of the
primary issues with electronic commerce. (Todt, 2019).

Integration with BNS/IPC & Contract Law


Integration of Contract Law and BNS
BNS Provisions Fraudulent solicitation to transfer funds or data (such as phishing or
phoney loans) is covered under Section 318, Cheating. Section 319: Personation-
Based Cheating: Fraudulent impersonation (e.g., vishing, phoney bank calls). Forgery
is defined in Sections 336–341 as the falsification of electronic documents,
statements, or counterfeit cards. Section 316: Criminal Breach of Trust: When banks,
staff, or middlemen misuse entrusted assets or information. (BNS, 2023)

Consumer and Contract Law


Contract Act, 1872: Safeguarding client cash is a fundamental duty; provisions that
absolve banks from carelessness are unenforceable. The Consumer Protection Act of
2019 states that consumers are the victims of cyber fraud, and that a lack of
compensation or inadequate security constitutes a service deficiency that takes
precedence over biased disclaimers. (Ministry of consumer affairs, food & public
distribution, 2025)

Integrated Insight
Fraud, impersonation, and breach of trust are covered by BNS, while the IT Act
2000's loopholes are filled by Contract and Consumer Law, which guarantees civil
accountability and consumer protection.

84
Chapter-3

In recent years, the number of clients utilising digital banking technology has grown
within the banking sector. They can transmit money, make purchases online, and
settle their obligations. According to the most recent World Retail Financial Services
Report, 57% of consumers choose digital (online) banking over traditional branch
banking. Additionally, 55% of customers now prefer to use mobile banking apps to
handle their accounts, which is a 47% rise from pre-epidemic levels. The primary
concern is the protection of private data, as the financial services sector is one of the
leading contributors to data breaches.

This information must be kept secure and confidential. Computer mishaps should
worry all organisations, but the accounting and finance sector is particularly
vulnerable since it deals with sensitive data. As the risk of fraud, data breaches, and
related extortion in organisations increases, organisations are putting more importance
on updating their knowledge security strategies.

Comparative Legal Context

• India is not a party to Budapest Convention


India's capacity to participate in international collaboration for cybercrime
investigations is hampered by its non-participation in the Budapest Convention on
Cybercrime. India is unable to take use of the Convention's framework for expedited
access to electronic evidence and mutual legal assistance because it is not a signatory.
Due to this restriction, Indian authorities are frequently forced to rely on ad hoc or
bilateral agreements, which can be less effective and have unclear legal status.
(Baghel, 2024)
 India has particular cybercrime laws that target banking scams, in contrast to
the US, which has the Computer Fraud and Abuse Act (CFAA), and the UK, which
enforces the Computer Misuse Act.
Although broad cyber offences are covered under the IT Act of 2000 and its revisions,
complex financial frauds are not specifically covered by any legal framework, which
leaves regulatory and enforcement gaps in the detection, prosecution, and prevention
of computer-enabled banking crimes. This makes it more difficult for Indian
authorities to react quickly to new cyberthreats in the financial industry.

85
Chapter-3

 The following would be a clear statutory recommendation:


It is suggested that India either pass a special "Banking Cybersecurity Act" or, as a
stopgap, add banking-related clauses to the Information Technology Act of 2000.
Such laws ought to:
1. Give a clear definition of cyberbanking frauds and associated offences.
2. Give banks responsibilities on data security, cybersecurity requirements, and
incident reporting.
3. Increase the severity of the sanctions for financial system attacks.
4. Facilitate the exchange of evidence across borders and collaboration with
international authorities.
5. Require banks and customers to share accountability and implement customer
awareness initiatives.
This would increase enforcement against complex cyber-enabled financial crimes,
close current legal gaps, and bring India into line with global best practices like the
US CFAA and UK Computer Misuse Act.

3.6 SUM-UP
In the financial sector, data privacy is essential, especially when it comes to internet
banking and digital financial services. Data security and privacy are required by a
number of laws and regulations that are pertinent to the banking sector. These rules
show financial organisations' commitment to protecting the security and privacy of
customer data in addition to being required by law. (Team AMLEGALS, 2023).

Thanks to advancements in technology, privacy has become a concern for everyone,


with data security receiving special attention. Since these people's freedoms are
threatened by outside intrusions, individual freedom is a crucial aspect of data
protection. Stopping the stranger's activity is necessary, regardless of how it happens.
The constitution can be used to confirm the fundamental legal requirements of any
new phenomena. According to the Indian constitution, rights come before obligations.
Data protection is prioritised since it is a right-based policy. Given that India is a
developing nation, it will take some time for the new legal area to be implemented or
become effective.

86
Chapter-3

The Indian Penal Code, National Security, Intellectual Property, Corporate Affairs,
Consumer, Right to Privacy, and Right to Information are the primary areas of
interest. One of the objectives of the study is to examine India's current legal
framework on data protection and privacy as a matter of right. In recent years, the
importance of data security and privacy constitutionality has increased. It is necessary
to grant a special position inside the legal system. To provide a high degree of privacy
protection, the effectiveness of the current legal system must be assessed. (Ghosh &
Shankar, 2016).

In the current digital context, cybercrime can be a violation of human rights. A


person's right to privacy can be seriously violated by cybercrimes including hacking,
data breaches, and internet eavesdropping, to name a few examples. Cybercrime
includes privacy violations and the stealing of private data and information. When
hackers steal someone's proprietary data, the confidentiality of that information is
compromised. The consequences for privacy violations are covered in Section 66E 28
of the IT Act of 2000. Cybercriminals face consequences for violating someone's
privacy online. (Shireen, 2022).

These two- or three-step procedures are used to verify electronic payments. Biometric
transaction technology and the OTP encryption mechanism. Cybercrime may be
decreased by utilising a technology known as block chain, which stops transaction
records from being altered. It is important to educate clients about the many kinds of
bank frauds and safeguarding practices to prevent them from becoming the next
victim of cybercrime.
It's critical to educate clients on the guidelines governing online banking. You can put
it on the financial institution's website, print it in a newspaper, run advertisements,
send SMS warnings, make instructional posters, and more. The RBI requires banks to
send letters to their clients informing them of any new regulations or modifications
that all banks must follow. In light of changes to the RBI's laws and guidelines, the
information communications should be updated promptly. (Totade, et al., 2022)

87
Chapter-3

Despite being India's initial attempt to criminalise cybercrimes, the Information


Technology Act 2000's measures are still insufficient to combat financial frauds.
Modern frauds like UPI fraud, QR code manipulation, and SIM swap assaults are not
specifically covered under Sections 66C and 66D, which deal with identity theft and
impersonation cheating. Similar to this, Section 43A offers compensation in cases
when a corporate entity fails to protect sensitive data, but it does not specify what
constitutes "reasonable security practices." Without explicit statutory standards,
enforcement is still uneven. RBI guidelines on customer liability (2017) and
cybersecurity (2016, 2021) try to close this gap, but they are still merely quasi-
regulatory tools with no legal standing. As a result, banks usually use disclaimers in
contracts to escape responsibility, which leaves clients with insufficient protection.
The urgent necessity for specific changes to the IT Act 2000 or a new "Banking
Cybersecurity Act" is highlighted by this doctrinal gap.

88

You might also like