Cyber Laws Identity theft -€“ Sec.66C

July 7, 2017

Section 66C of the Information Technology Act 2008 penalizes identity theft in India, making it a criminal offense to fraudulently or dishonestly use another person's electronic signature, password, or unique biometric identifier. Offenders face imprisonment for up to three years, financial penalties up to one lakh rupees, or both.

Legal Scope and Essential Ingredients of Section 66C

Digital identity theft occurs when an unauthorized entity appropriates personal credentials to access accounts, execute financial transactions, or misrepresent identity. Under Section 66C, criminal liability arises from two primary mental states: fraudulent intention or dishonest intention. Fraudulent intent requires an purpose to deceive and cause injury or loss, whereas dishonest intent involves causing wrongful gain to one person or wrongful loss to another.

The statutory language explicitly protects electronic signatures, user passwords, digital authentication tokens, and unique identification features such as Aadhaar numbers or biometric data. As digital banking and remote authentication expand across commercial systems, maintaining a verified cyber law compliance audit framework helps organizations detect credential vulnerability before fraudulent exploitation happens.

Offenses Covered Under Electronic Identity Theft

Electronic identity theft encompasses multiple technical vectors. Common methods include phishing schemes designed to extract passwords, unauthorized access to computer databases, spoofing electronic signatures, and credential harvesting via malware. When an attacker steals internet banking credentials or impersonates an account holder online, Section 66C provides the primary statutory mechanism for criminal prosecution.

  • Password Stealing and Credential Misuse: Unauthorized login using stolen passwords or PINs to access private communication or financial services.
  • Electronic Signature Misappropriation: Unlawful application of digital signature certificates to authenticate legal documents or corporate filings.
  • Biometric and Unique Identity Fraud: Theft or unauthorized cloning of biometric identifiers and unique national identity markers for illegal impersonation.

Penalties, Enforcement, and Judicial Precedents

A conviction under Section 66C triggers a term of imprisonment extending up to three years, alongside a fine up to one lakh rupees. The offense is classified as cognizable, compoundable, and bailable under Indian cyber jurisprudence. Law enforcement agencies inspect digital logs, IP address traces, and server access records to establish chain of custody during investigations.

Judicial interpretations, such as the rulings in Manishkumar Arjanbhai Patel Vs. Saurashtra Gramin Bank, highlight the importance of bank liability and electronic evidence verification when unauthorized digital transactions occur. Courts demand precise forensic proof demonstrating that the accused possessed and utilized the unique identification feature without legal authority.

Reporting Identity Theft and Preventive Measures

Victims of electronic identity theft must take immediate legal and technical action. Prompt reporting to the National Cyber Crime Reporting Portal and local cyber crime police stations creates an official record required for blocking compromised accounts and pursuing criminal charges.

  1. Preserve digital evidence, including email headers, login logs, transaction alerts, and screenshots of unauthorized activity.
  2. File a formal complaint specifying the stolen credential features and suspected loss under Section 66C of the IT Act.
  3. Notify relevant banking institutions and service providers to freeze compromised access credentials.

Proactive security measures, such as adopting multi-factor authentication, enforcing strong password hygiene, and routinely inspecting account activity logs, significantly reduce the risk of credential compromise. Organizations managing user data should implement robust encryption and access controls to safeguard client credentials against digital theft.

Found this helpful?

Share this page with others