By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
Your Instagram — or Facebook, X or Gmail — now shows a different email and phone, and the in-app “forgot password” loop fails because the recovery path has been replaced. This is not a help-desk ticket alone; under the Information Technology Act, 2000 it is commonly identity theft and personation (Sections 66C and 66D, plus 66), and under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended 10 Feb 2026 (in force 20 Feb 2026) the platform has time-bound grievance and takedown duties — including a 2-hour path where the hijack is used for impersonation. Two tracks filed together — platform grievance + police complaint — recover more accounts than either alone.
Which provisions actually govern an account hijack?
| Track | Provision | What it does | Clock |
|---|---|---|---|
| Crime | IT Act Sec 66C (identity theft) | Fraudulent/dishonest use of your electronic signature, password or any other unique identification feature | FIR → investigation by Inspector+ (Sec 78) |
| IT Act Sec 66D (cheating by personation using computer resource) | Cheating by personation using a computer resource — the hacker posting as you | Up to 3 years + ₹1 lakh, cognizable, bailable | |
| IT Act Sec 66 (computer-related offence via 43) | Dishonest access/damage to your computer resource (the account) | Up to 3 years / ₹5 lakh | |
| BNS Sec 308, 318, 351 | Extortion, cheating and intimidation where ransom or fraud follows the hijack | 308: up to 7 years | |
| Platform | IT Rules 2021 Rule 3(2) — grievance | Resident Grievance Officer: general 7 days, unlawful-content 36 hours, impersonation/morphed/nudity 2 hours (post-Feb 2026) | From your grievance |
| Rule 3(1)(d) — takedown on actual knowledge | 3 hours for unlawful content from actual knowledge via court order or authorised government notification | From order/notification, not from grievance | |
| Rule 4 — SSMI duties (>50 lakh users) | Significant social media intermediaries (Meta, X, Google) must publish monthly transparency reports, enable voluntary user verification, and act faster on impersonation — the route that makes the 2-hour path credible | Continuous |
Section 79 IT Act safe harbour for intermediaries depends on due diligence — Rule 3 compliance is that due diligence.
How should you file the platform grievance so it triggers the 2-hour track?
Where the hijack is used to impersonate you (posting from your account, DM-ing your contacts), frame the grievance explicitly as impersonation under Rule 3(2)(b) / Rule 4 — that engages the 2-hour user-grievance path. Include:
- Account identification: Exact handle/URL (
https://instagram.com/your.handle), account creation email/phone, and your government ID proof. - Hijack timeline: Date/time you lost access, the new recovery email/phone showing replacement, and the first impersonation post or DM with URL (not just screenshot).
- Label the category: Write “Complaint under Rule 3(2) and Rule 4 — impersonation / unauthorised access to user account (IT Rules 2021 as amended 10 Feb 2026) — request 2-hour handling as impersonation.” Citing the rule and the time track is not advocacy — it is the correct head for prioritisation.
- Preserve for Section 63 BSA: Export the impersonation post’s URL and metadata; keep the original-device export with hash — see Section 63 BSA guide.
- File in two places: The platform’s grievance form + email to the published Resident Grievance Officer (every SSMI must publish name and contact), and — where the hack is part of a fraud — a parallel government-notified track (police or MeitY-authorised agency) is what starts the Rule 3(1)(d) 3-hour clock. Your grievance alone does not trigger 3(1)(d).
A common failure: reporting via the in-app “Report a problem” with no URL, no impersonation label, and no grievance-officer email — the ticket is then triaged as low priority and the 2-hour path is never engaged.
How does the police complaint fit — and where do you file it in Kerala?
File a written, signed complaint at the district Cyber Police Station (every Kerala revenue district has one) or the station whose cyber cell covers the account, citing IT Act 66C/66D/66 and — where ransom or impersonation harm is made out — BNS 308/319/351 (and POCSO where a minor’s intimate image is involved). Attach: account URL, timeline, the impersonation post URLs, the hijack email/phone change screenshot, and the platform grievance acknowledgement. Request an FIR under Section 173 BNSS where cognizable ingredients are disclosed — Lalita Kumari remains the mandatory-FIR rule — and, if the account is used to freeze others’ money, note the Section 106 BNSS / 503 BNSS implications for lien.
For escalation where a filed NCRP/1930 reference draws no FIR, use the chain in the NCRP escalation guide — SP/CP written representation → CPGRAMS → Magistrate direction under Section 175(3) BNSS.
What about accounts used to impersonate you rather than hijack yours?
Where a different account clones your name and photo to scam your contacts, the same Rule 3(2)(b) 2-hour impersonation and Rule 3(1)(d) 3-hour tracks apply, and the crime sections shift emphasis to 66D (personation) and 319 BNS (cheating by personation), plus 66E / 67 / 351 where morphed images are used. File both the platform impersonation report (with both URLs — yours and the fake) and the police complaint. Courts in Kerala and the Delhi High Court have granted John Doe / Ashok Kumar injunctions and disclosure of subscriber data where impersonation is used for fraud — the written grievance with URLs is the pre-condition for that route.
What reduces recovery time — a short checklist
- Enable two-factor authentication (TOTP app, not SMS alone) before hijack, and keep a backup code offline.
- Do not click recovery links sent by the impersonator — they phish the replacement credentials.
- Keep the original-device proof — the date your recovery email changed, as recorded on the device and by the platform’s security email, is the best timestamp for the investigation.
- Do not transfer money to the hijacker for “return” of the account — use the police + government-notified takedown track instead.
Primary sources
- IT Act, 2000 — Sections 43, 66, 66C, 66D, 69A, 78, 79
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended 10 Feb 2026 (in force 20 Feb 2026) — Rules 3(1)(d), 3(2), 4
- BNSS, 2023 — Sections 35, 94, 173, 175, 193; BSA, 2023 — Section 63
- BNS, 2023 — Sections 308, 318, 319, 351
FAQ
