Section 84C of the Information Technology Act, 2000 prescribes punishment for attempting to commit cyber offences or causing such offences to be committed. Where no express penalty is provided elsewhere in the Act, an attempt is punishable with imprisonment up to one-half of the longest term provided for the offence, the prescribed fine, or both.
Legislative Framework of Section 84C Information Technology Act
Inchoate offences represent actions taken toward committing a crime that is either interrupted or fails to achieve its intended outcome. Prior to the Information Technology (Amendment) Act of 2008, prosecuting incomplete digital crimes required relying on general provisions under Section 511 of the Indian Penal Code. Parliament enacted Section 84C to establish a specialized statutory provision penalizing attempt to commit cyber offences directly within the Information Technology Act.
Section 84C applies whenever an individual attempts an offence or causes an offence to be committed, and in such attempt performs an overt act towards its commission. This ensures that cyber criminals who deploy malware, attempt unauthorized data breaches, or initiate digital extortion do not escape liability merely because automated defenses thwarted their final objectives.
Legal Distinctions: Attempt vs Preparation in Cyber Law
Under established Indian criminal jurisprudence, the commission of a crime progresses through four distinct stages: intention, preparation, attempt, and completion. While mere intention and preparation are generally not punishable (except in limited state security offences), an attempt crosses the legal threshold into criminal culpability.
In the digital context, distinguishing attempt vs preparation in cyber law requires examining technical actions:
- Mere Preparation: Downloading open-source port scanners, researching vulnerabilities in a target web application, or purchasing domain names similar to a bank without active deployment.
- Criminal Attempt (Overt Act): Transmitting malicious SQL injection payloads to a database server, executing brute-force credential stuffing attacks against authentication endpoints, or injecting malware into a network firewall where execution fails due to security patches.
- Culpability Standard: As soon as the actor executes a command intended to breach security or cause data damage, an overt act is established, triggering liability under Section 84C.
Sentencing Rules and Half Term Imprisonment for Attempt
Section 84C outlines a clear mathematical formula for calculating punishment for cyber crime attempts. Where no express punishment is designated for the attempt itself, the court may impose:
- Imprisonment: A term extending up to one-half of the maximum imprisonment period prescribed for the completed offence. For example, an attempt to commit hacking under Section 66 (carrying a maximum of 3 years) is punishable with up to 1.5 years imprisonment.
- Fine: The full fine provided for the completed substantive offence, or both imprisonment and fine.
- Severe Offences: An attempt to commit cyber terrorism under Section 66F (punishable with life imprisonment) carries half term imprisonment for attempt extending up to ten years or more under applicable penal interpretations.
The Locus Poenitentiae Principle in Cyber Crime Attempts
In criminal jurisprudence, the doctrine of locus poenitentiae (opportunity to repent) defines the boundary where an individual voluntarily withdraws from committing a crime before taking the final irrevocable step. In cyber law, determining if an actor abandoned the attempt or was thwarted by external security controls is a vital factual inquiry.
If a person writes a malicious script or scans a server but voluntarily deletes the code and terminates network connections prior to transmitting hostile packets, the defense of voluntary abandonment may be raised. However, if the perpetrator launched the attack payload, and the transmission was blocked solely by a web application firewall or intrusion prevention system, the opportunity for repentance has expired, and liability under Section 84C is legally complete.
Interplay with Abetment and Specific Cyber Offences
Section 84C operates alongside other inchoate liability provisions in the Information Technology Act. It closely complements the punishment for abetment of offences under Section 84B, which holds conspirators, facilitators, and digital accomplices liable to the same penalty as the primary offender.
Similarly, an unconsummated attempt to alter protected software code is penalized under Section 84C read with provisions prohibiting tampering with computer source documents under Section 65. Organizations and individuals witnessing attempted cyber attacks or thwarted breaches can lodge formal incident reports on the National Cyber Crime Reporting Portal to facilitate early law enforcement tracking.
Digital Forensics and Proving Criminal Attempt
Prosecuting an attempt under Section 84C relies heavily on technical evidence establishing overt acts and specific criminal intent. Key evidentiary elements include web server access logs showing payload submissions, firewall intrusion logs, packet captures, and compromised user session tokens. Digital forensic examiners must preserve these electronic records under strict chain of custody protocols to ensure admissibility under Section 65B of the Indian Evidence Act, proving beyond reasonable doubt that the accused performed the acts towards committing the cyber crime.
Forensic investigators must also establish the timeline of execution steps to demonstrate uninterrupted criminal intent. Correlating network connection timestamps with endpoint process creation logs proves that the accused initiated the cyber intrusion attempt willfully. In enterprise investigations, audit trails from multi-factor authentication servers and VPN gateways provide crucial corroboration when establishing criminal liability under Section 84C.
Corporate Incident Response and Threat Mitigation Strategies
Organizations detecting attempted intrusions should immediately invoke containment procedures without altering primary log repositories. Isolate affected subnets, capture volatile memory snapshots, and export syslog feeds to immutable storage. Legal counsel should review preserved audit trails to confirm statutory overt acts before presenting complaints to state cyber crime cells. Early forensic coordination ensures strong legal positioning under Section 84C Information Technology Act while safeguarding corporate intellectual property from persistent unauthorized access attempts.
By demonstrating both specific technical intent and verifiable execution steps, prosecutors can secure convictions under Section 84C even when digital security countermeasures successfully prevented actual system compromise.
