Cyber & IT Act

IT Act offences, explained simply: Sections 65 to 67 and what they mean

By Adv. K J Muhammed Aslam · Advocate, High Court of Kerala

Published 16 August 2026 · Last reviewed 16 August 2026

The Information Technology Act, 2000 punishes cyber offences through Sections 65 to 67B, 72 and 72A — covering source-code tampering, hacking, identity theft, online impersonation, privacy-violating images and obscene content — and most of these offences carry a maximum of three years’ imprisonment, making them cognizable but bailable under Section 77B. The Act also runs a separate civil track: Sections 43 and 43A give victims monetary compensation without any criminal trial. Section 66A, once the most invoked provision, no longer exists — the Supreme Court struck it down in 2015. This article walks through each section in plain language, with the exact punishments and how the sections combine with the Bharatiya Nyaya Sanhita in real FIRs.

Is the IT Act civil or criminal? What is the difference between Section 43 and Section 66?

Both. The IT Act, 2000 has two parallel tracks, and understanding the split explains most of its architecture.

The civil track is Chapter IX. Section 43 lists ten kinds of harm to a computer — unauthorised access, downloading data, introducing a virus, causing damage, denying access, and so on — and makes the wrongdoer liable to pay compensation to the victim. No police, no jail: the remedy is money. Claims up to five crore rupees go to the Adjudicating Officer appointed under Section 46 (usually the State IT Secretary); larger claims go to the competent civil court.

Section 43A makes a company that negligently fails to protect “sensitive personal data” liable to compensate the person harmed. It remains in force today, but it is scheduled to be omitted when Section 44(2) of the Digital Personal Data Protection Act, 2023 takes effect on 14 May 2027 — the date the DPDP regime’s core obligations become enforceable. Businesses tracking that transition can see the DPDP compliance timeline.

The criminal track is Chapter XI. Section 66 converts the civil wrongs of Section 43 into crimes — but only where the act was done dishonestly or fraudulently, terms borrowed from the Indian Penal Code and now defined in Sections 2(7) and 2(9) of the Bharatiya Nyaya Sanhita, 2023. The same hack can therefore produce both a compensation claim under Section 43 and a prosecution under Section 66. Section 77 of the Act says one does not bar the other.

What does each offence section of the IT Act actually cover?

Here is each provision of Chapter XI in the order it appears, with the punishment fixed by the statute. Section numbers and amounts below are taken from the consolidated text of the Act.

Section 65 — Tampering with computer source documents

Knowingly concealing, destroying or altering computer source code that the law requires to be kept or maintained. It is a narrow offence — the source code must be one required by law to be maintained, which is why it appears mostly in cases involving licensed software, telecom equipment or government systems. Punishment: up to three years’ imprisonment, or fine up to two lakh rupees, or both.

The general hacking provision. Any Section 43 act — unauthorised access, data theft, virus insertion, damage, denial of service, account manipulation — done dishonestly or fraudulently. Punishment: up to three years, or fine up to five lakh rupees, or both.

Section 66B — Dishonestly receiving stolen computer resource

Receiving or retaining a stolen computer resource or communication device, knowing or having reason to believe it is stolen. It reaches the buyer of a stolen phone or laptop, and investigators sometimes add it against those holding devices or SIM cards traced to a fraud. Punishment: up to three years, or fine up to one lakh rupees, or both.

Section 66C — Identity theft

Fraudulently or dishonestly using another person’s electronic signature, password or “any other unique identification feature”. In practice this is the OTP-and-credentials section: phished banking passwords, misused OTPs, SIM-swap frauds, cloned biometrics. Punishment: up to three years’ imprisonment and fine up to one lakh rupees.

Section 66D — Cheating by personation using a computer resource

Cheating by pretending to be someone else through any communication device or computer resource. This is the workhorse of Indian cyber-fraud FIRs: phishing sites, fake customer-care numbers, fake matrimonial and social-media profiles, “digital arrest” calls impersonating police or customs, fraudulent investment platforms. Punishment: up to three years and fine up to one lakh rupees. Victims of payment frauds under this section should act within hours — the steps are set out in how to complain about UPI fraud and recover money.

Section 66E — Violation of privacy

Intentionally capturing, publishing or transmitting an image of a person’s private area without consent, in circumstances where privacy is reasonably expected. It covers hidden-camera images and non-consensual sharing of intimate images. Punishment: up to three years, or fine up to two lakh rupees, or both. It is almost always paired with voyeurism under Section 77 of the BNS (formerly Section 354C IPC).

Section 66F — Cyber terrorism

The gravest offence in the Act: unauthorised access or denial-of-service attacks intended to threaten the unity, integrity, security or sovereignty of India or to strike terror, or accessing data restricted for reasons of State security. Punishment: imprisonment which may extend to imprisonment for life. It is rarely and cautiously invoked; ordinary hacking does not meet its threshold.

Sections 67, 67A and 67B — The obscenity cluster

  • Section 67 punishes publishing or transmitting obscene material in electronic form: first conviction up to three years and fine up to five lakh rupees; a repeat conviction up to five years and fine up to ten lakh rupees.
  • Section 67A covers material containing a sexually explicit act: five years and ten lakh rupees on first conviction, seven years and ten lakh rupees on repeat.
  • Section 67B covers material depicting children in sexually explicit acts — creating, browsing, downloading, exchanging or facilitating it: five years and ten lakh rupees on first conviction, seven years on repeat. It operates alongside Sections 13 to 15 of the POCSO Act, 2012.

These three sections, usually with extortion under Section 308 of the BNS (formerly Sections 383–384 IPC), form the charge structure in sextortion cases. Sections 67 to 67B carry a public-good exception for scientific, literary, artistic or heritage material.

Sections 72 and 72A — Breach of confidentiality

Section 72 punishes officials who obtained access to records using powers under the IT Act and then disclose them without consent: up to two years, or fine up to one lakh rupees, or both. Section 72A is broader and more practical: any person — including an intermediary or service provider — who obtained personal information under a lawful contract and discloses it without consent, intending or knowing it will cause wrongful loss or gain, faces up to three years, or fine up to five lakh rupees, or both.

Is Section 66A still in force? Can an FIR be registered under it?

No. The Supreme Court struck down Section 66A in its entirety in Shreya Singhal v. Union of India, (2015) 5 SCC 1, by judgment dated 24 March 2015, holding that its vague terms — “grossly offensive”, “annoyance”, “inconvenience” — violated Article 19(1)(a) and were not saved by Article 19(2).

A struck-down provision is void; no FIR, charge sheet or conviction can rest on it. Because police stations kept invoking it anyway, the Supreme Court in People’s Union for Civil Liberties v. Union of India (order dated 12 October 2022) directed all states and police forces to stop registering 66A cases and to delete the section from pending prosecutions. If an FIR today cites Section 66A, that is a ground to seek deletion of the charge, and if the FIR rests on 66A alone, to seek quashing — the route is explained in filing a writ petition before the High Court of Kerala.

Note what Shreya Singhal did not do: it upheld the website-blocking power under Section 69A and read down intermediary liability under Section 79. Only 66A fell.

Which IT Act offences are cognizable and which are bailable?

Section 77B of the Act sets the rule: offences punishable with imprisonment of three years and above are cognizable (police can register an FIR and arrest without a warrant), and offences punishable with three years are bailable (bail is a right, granted at the police station or by the Magistrate). The practical result — most IT Act offences are both.

Section What it punishes Maximum punishment Bailable?
65 Tampering with source code 3 years or ₹2 lakh or both Yes
66 Hacking, data theft (s.43 acts done dishonestly) 3 years or ₹5 lakh or both Yes
66B Receiving stolen computer resource/device 3 years or ₹1 lakh or both Yes
66C Identity theft (passwords, OTPs, signatures) 3 years and ₹1 lakh Yes
66D Cheating by personation online 3 years and ₹1 lakh Yes
66E Privacy-violating images 3 years or ₹2 lakh or both Yes
66F Cyber terrorism Up to life imprisonment No
67 Obscene electronic material 3 years + ₹5 lakh (first conviction) Yes (first conviction)
67A Sexually explicit material 5 years + ₹10 lakh (first conviction) No
67B Child sexual abuse material 5 years + ₹10 lakh (first conviction) No
72 Breach of confidentiality by officials 2 years or ₹1 lakh or both Yes
72A Disclosure of personal data in breach of contract 3 years or ₹5 lakh or both Yes

Two further procedural rules matter. Under Section 78, only a police officer of the rank of Inspector or above may investigate an IT Act offence — in Kerala that typically means the Cyber Police Station of the district or an Inspector at the local station. And under Section 75, the Act applies to offences committed outside India, by any person of any nationality, if the computer or network involved is located in India.

Can IT Act offences be compounded or settled?

Yes, within limits. Section 77A allows a competent court to compound any IT Act offence except those punishable with life imprisonment or with a term exceeding three years. Three further bars apply: no compounding where a previous conviction exposes the accused to enhanced punishment, where the offence affects the socio-economic conditions of the country, or where it was committed against a child below 18 or against a woman.

So a first-time Section 66 or 66C case between business rivals may realistically end in compounding, while Sections 66F, 67A and 67B never can, and a 66E case against a woman victim cannot either. The accused applies in the trial court under Section 77A(2), which adopts the plea-bargaining procedure of Sections 265B and 265C CrPC — provisions now carried into Sections 289 to 300 of the BNSS.

How do IT Act sections pair with BNS offences in a real FIR?

Cyber-crime FIRs almost never cite the IT Act alone. Since 1 July 2024, offences are charged under the Bharatiya Nyaya Sanhita, 2023 rather than the IPC, and the pairings run to a pattern:

Situation IT Act section BNS section (old IPC)
Online payment fraud, phishing 66C, 66D 318(4) — cheating (420 IPC); 319(2) — cheating by personation (419 IPC)
Sextortion, threats to leak images 67, 67A, 66E 308 — extortion (383–384 IPC); 351 — criminal intimidation (503/506 IPC)
Fake profiles, morphed images 66D, 67 356 — defamation (499/500 IPC); 336 — forgery of electronic record (463/465 IPC)
Hidden camera, image capture 66E 77 — voyeurism (354C IPC)
Persistent online harassment of a woman 66E, 67 78 — stalking (354D IPC); 79 — insulting the modesty of a woman (509 IPC)

The BNS sections matter for the accused because they can change the bail picture: cheating under Section 318(4) BNS carries up to seven years, so an FIR pairing 66D with 318(4) is effectively non-bailable even though 66D alone is bailable. They matter for victims because property traced under them can be seized and accounts frozen under Section 106 of the BNSS (formerly Section 102 CrPC) — the mechanism behind most frozen-account notices, explained in what to do when a cyber cell freezes your bank account.

How is electronic evidence proved in an IT Act case?

Every screenshot, server log, CDR and CCTV clip in these cases is an electronic record, and its admissibility is governed by Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, which replaced Section 65B of the Indian Evidence Act on 1 July 2024.

Section 63(4) requires a certificate identifying the record, describing how it was produced, and confirming the device was working properly. The BSA tightened the old rule: the certificate must now be signed both by the person in charge of the device or activity and by an expert, in the form prescribed in the Schedule to the Adhiniyam, with a hash report of the record enclosed. The Supreme Court held in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1, that the certificate is mandatory unless the original device itself is produced — reasoning that continues to govern Section 63. In practice, a prosecution or complaint that skips the certificate risks its core evidence being ruled inadmissible at trial.

What should a complainant or an accused do first?

For a victim, speed beats paperwork:

  1. For financial fraud, call the national helpline 1930 immediately — within the first few hours banks can freeze the fraudster’s receiving accounts.
  2. File a complaint on the National Cyber Crime Reporting Portal with transaction IDs, screenshots and numbers used.
  3. Follow up with a written FIR at the local or Cyber Police Station. Under Section 173 of the BNSS (formerly Section 154 CrPC), the FIR can be given at any station regardless of where the offence occurred, and even by electronic communication.
  4. Preserve original devices and records — they will be needed for the Section 63 BSA certificate.

For a person accused or named in a notice: do not delete accounts, chats or data — that can become a separate offence and destroys exculpatory material too. Check which sections the FIR actually cites, since bailability turns on them, and verify no struck-down provision like 66A appears. Respond to police notices in writing and take legal advice promptly; an advocate can assess whether the case is one for bail, compounding under Section 77A, or quashing. An overview of how these cases progress is at cyber crime practice.

Primary sources

FAQ

Common questions

Is Section 66A of the IT Act still valid?
No. Section 66A was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India, (2015) 5 SCC 1, on 24 March 2015. Any FIR or charge sheet invoking Section 66A after that date is invalid, and in October 2022 the Supreme Court directed all states to close pending 66A prosecutions. If you see 66A in an FIR, point this out to the police or the court immediately.
What is the punishment under Section 66C of the IT Act?
Section 66C punishes identity theft — fraudulently or dishonestly using another person's password, electronic signature or any other unique identification feature, which in practice covers OTPs, banking credentials and biometric identifiers. The punishment is imprisonment up to three years and a fine up to one lakh rupees. The offence is cognizable and bailable under Section 77B.
What is the difference between Section 66C and Section 66D of the IT Act?
Section 66C targets the misuse of someone's credentials — passwords, OTPs, electronic signatures or other unique identifiers. Section 66D targets cheating by pretending to be someone else through a computer or phone — fake profiles, phishing calls, impersonating officials or companies. Most online frauds involve both: the fraudster impersonates (66D) to extract credentials, then uses them (66C). Police commonly invoke both sections together with cheating under Section 318(4) of the BNS.
Are IT Act offences bailable?
Most are. Under Section 77B, offences punishable with three years' imprisonment — Sections 65, 66, 66B, 66C, 66D, 66E and 67 (first conviction) — are bailable, though cognizable, so police can register an FIR and arrest without a warrant. Sections 67A and 67B (five years or more) and Section 66F (cyber terrorism, up to life) are non-bailable.
Can an IT Act case be settled or compounded out of court?
Partly. Section 77A lets a court compound IT Act offences except those punishable with life imprisonment or a term exceeding three years. Compounding is barred where the accused faces enhanced punishment due to a previous conviction, where the offence affects the socio-economic conditions of the country, or where it was committed against a woman or a child below 18. So a first-time Section 66 or 66C case may be compounded, but Sections 67A, 67B and 66F cannot.
Who investigates IT Act offences?
Under Section 78 of the IT Act, only a police officer of the rank of Inspector or above may investigate an IT Act offence. In Kerala, complaints typically go to the local police station, the district Cyber Police Station, or online through the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the 1930 helpline for financial frauds.

Get in touch

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. As required by the Bar Council of India, this website only provides information about Adv. K J Muhammed Aslam to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.