Cyber Crimes in India: IT Act + BSA 2023 — The Digital Offences Playbook (2026)
Your client's bank account has been hacked. Or someone has created a fake profile and posted defamatory content. Or an employee has leaked confidential office data. You need to file a cyber crime case — but which section applies? IT Act or BSA? Both?
Since 2024, a dual regime operates — IT Act 2000 (substantive cyber offences) + Bharatiya Sakshya Adhiniyam 2023 (digital evidence rules). Getting the section mapping wrong means either filing under a struck-down provision (66A — still happens in 2026) or missing the correct evidence certification (BSA 63 — formerly IEA 65B).
This guide maps the entire framework for practitioners handling cyber crime cases on either side. NyayaVeda AI provides instant citation-verified research on IT Act section mapping, BSA 63 compliance, and digital evidence admissibility.
What Are Cyber Crimes under the IT Act and BSA?
Cyber crimes in India are offences committed using computer systems or digital networks, prosecuted under the Information Technology Act, 2000 for substantive cyber offences (Sections 43, 66, 66C, 66D, 67, 79) and the Bharatiya Nyaya Sanhita for general criminal conduct. The Bharatiya Sakshya Adhiniyam, 2023 governs the admissibility of electronic evidence through the certificate requirement under Section 63.
The Dual Regime: IT Act + BNS + BSA
Cyber crimes in India are governed by three overlapping statutes:
| Statute | What It Covers | Key Sections |
|---|---|---|
| IT Act 2000 | Substantive cyber offences (hacking, identity theft, data breach, obscenity) | Sections 43, 66, 66C, 66D, 66E, 67, 67A, 67B, 72, 79 |
| BNS 2023 | General criminal offences committed via digital means (cheating, defamation, forgery) | Sections 318(4), 336, 351, 356 |
| BSA 2023 | Admissibility and procedure for electronic evidence | Sections 63, 65 (primary evidence), 86 (presumption for electronic records) |
The critical rule: When a cyber crime falls under BOTH the IT Act and BNS — charge under both. IT Act provides the cyber-specific offence; BNS provides the general criminal offence. This gives the prosecution maximum leverage and the court maximum sentencing options.
IT Act Section Mapping: Every Section You Need
Offences Against Computer Systems
| Section | Offence | Punishment | Real-World Example |
|---|---|---|---|
| 43 + 66 | Hacking — unauthorised access to computer system | 3 years + Rs 5 lakhs fine | Employee accessing ex-employer's server after termination |
| 66B | Dishonestly receiving stolen computer resource | 3 years + Rs 1 lakh fine | Buying a stolen laptop knowing it is stolen |
| 66C | Identity theft — using another person's electronic signature/password | 3 years + Rs 1 lakh fine | Using someone's Aadhaar/PAN to open bank account |
| 66D | Cheating by personation using computer resource | 3 years + Rs 1 lakh fine | Creating fake Facebook profile to defraud |
| 66E | Privacy violation — capturing/publishing private images | 3 years + Rs 2 lakhs fine | Non-consensual sharing of intimate photos |
| 66F | Cyber terrorism | Life imprisonment | Attack on critical information infrastructure |
Content-Related Offences
| Section | Offence | Punishment | Note |
|---|---|---|---|
| 67 | Publishing obscene material electronically | 5 years + Rs 10 lakhs (2nd offence) | Websites, social media, messaging |
| 67A | Publishing sexually explicit material | 7 years + Rs 10 lakhs (2nd offence) | More severe than 67 |
| 67B | Publishing child sexual abuse material | 7 years + Rs 10 lakhs (2nd offence) | POCSO Act also applies — charge under both |
⚠️ Section 66A: STRUCK DOWN — Do NOT Charge
Shreya Singhal v. Union of India (2015, SC) struck down Section 66A (sending offensive messages) as unconstitutional — violating Article 19(1)(a). Despite this, police across India continue to file FIRs under 66A in 2026. Any FIR citing 66A is void ab initio.
If your client is charged under 66A: File immediate quashing under BNSS 528. Cite Shreya Singhal. The charge is legally non-existent. Some courts have imposed costs on IOs who continue to invoke struck-down provisions.
BSA Section 63: Digital Evidence Admissibility
The most important evidentiary provision for any cyber crime case — previously IEA 65B, now BSA Section 63:
When Is a Certificate Required?
| Evidence Type | Certificate Required? | How to Certify |
|---|---|---|
| Original device (phone, laptop, server) | No — primary evidence under BSA 62 | Produce the device itself |
| Printout/screenshot from device | YES — secondary evidence | Person who operated the device must sign BSA 63(2) certificate |
| Email from server | YES | System administrator certifies |
| WhatsApp messages (screenshot) | YES | Phone owner signs certificate + hash value |
| CCTV footage (copy) | YES | CCTV operator/premises owner certifies |
| CDR (Call Detail Records) | YES | Nodal officer of telecom company certifies |
| Bank transaction records | YES | Bank's designated officer certifies |
The Arjun Panditrao Rule (2020 SC)
Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020, 3-Judge Bench) settled the law:
- 2BSA 63 certificate is MANDATORY for secondary electronic evidence — no exception
- 4Oral evidence CANNOT substitute for the certificate
- 6The certificate must be signed by a person who was in charge of the computer/device during the relevant period
- 8Hash value preservation is strongly recommended (ensures integrity — document has not been tampered)
Defence Strategy: In every cyber crime trial, the FIRST thing to check is: does the prosecution have valid BSA 63 certificates for every piece of electronic evidence? If not, file an application to exclude the evidence. Without certificates, screenshots, printouts, CDRs, and emails are inadmissible. This alone can collapse the prosecution's case.
Filing a Cyber Crime FIR: The Complete Process
Where to File
| Method | When to Use |
|---|---|
| Local police station | Any cyber crime — Zero FIR applies (BNSS 173) |
| Cyber Crime Cell | Dedicated cyber police station (available in all districts) |
| cybercrime.gov.in (NCRP portal) | Online reporting — especially useful for financial fraud, social media crimes |
| Bank's fraud desk | If financial fraud — bank files SAR to RBI, assists police |
Evidence to Preserve BEFORE Filing
- 2Screenshots — with URL bar visible, timestamps
- 4Device preservation — do NOT delete messages, do NOT factory reset
- 6Bank statements — showing fraudulent transactions
- 8Email headers — full header (not just sender name) shows IP address
- 10CDR request — through police to telecom company
- 12Social media preservation — report + download data before the content is deleted
- 14Hash value — compute MD5/SHA-256 hash of digital files immediately
Critical: Digital evidence degrades fast. WhatsApp messages can be deleted. Social media posts can be taken down. Server logs are typically retained for only 90-180 days. Preserve evidence within 24 hours of discovering the offence.
Intermediary Liability: Section 79 IT Act
The Safe Harbour Rule
Section 79 provides that intermediaries (platforms, ISPs, hosting providers) are NOT liable for third-party content — provided they:
- 2Act as a mere conduit (do not initiate or modify the content)
- 4Exercise due diligence (comply with government guidelines)
- 6Remove content expeditiously upon receiving actual knowledge or court/government order
When Safe Harbour Fails
The intermediary loses protection when:
- It has actual knowledge of illegal content and fails to remove (Google India v. Visakha Industries, 2020)
- It modifies or curates the content (editorial control → not a mere intermediary)
- It fails to comply with the IT Rules 2021 (grievance officer, compliance report, content takedown)
For the complainant: If the platform refuses to remove content — file complaint with the platform's Grievance Officer first (mandatory under IT Rules). If unresolved in 15 days → approach the Grievance Appellate Committee. Simultaneously file FIR + seek court direction for takedown.
For the platform/accused: Demonstrate due diligence compliance. Produce the grievance officer's response log. Show that content was removed upon receiving knowledge. Section 79 is your shield — but only if you can prove due diligence.
Parallel Charging: IT Act + BNS
For maximum prosecution impact, charge under both statutes:
| Cyber Crime | IT Act Section | BNS Section | Combined Effect |
|---|---|---|---|
| Online fraud | 66D (personation) | 318(4) (cheating) | 3 years IT + 7 years BNS |
| Identity theft | 66C | 336 (forgery) | 3 years IT + 7 years BNS |
| Cyber stalking | 66A (STRUCK DOWN) → use 67 if obscene | 351 (criminal intimidation) | IT + BNS applicable |
| Data theft | 43 + 66 | 316 (CBT) if entrusted data | 3 years IT + 7 years BNS |
| Online defamation | 67 (if obscene) | 356 (defamation) | IT + BNS |
| Revenge pornography | 66E + 67A | 77 (voyeurism) | 3 years IT + 7 years BNS |
| Cyber terrorism | 66F | 113 (terrorist act BNS) | Life imprisonment both |
Always dual-charge: IT Act (specific cyber offence) + BNS (general criminal offence) for maximum impact.
Defence Strategy in Cyber Crime Cases
The 5 Attack Vectors
1. BSA 63 Certificate Challenge "My Lord, the prosecution relies on 47 printouts of WhatsApp messages. Not a single printout has a BSA Section 63 certificate. Under Arjun Panditrao (2020, 3-Judge Bench), these are inadmissible as evidence. Without these messages, the prosecution has no case."
2. IP Address ≠ Identity An IP address traces to a device or network — not a person. If the alleged offence was committed from a shared WiFi network, office computer, or cyber cafe — argue that IP alone does not establish identity.
3. Chain of Custody Digital evidence is fragile. If the device was not sealed at the scene, if there was a gap between seizure and forensic analysis, if the hash value was not computed at seizure — argue contamination.
4. Section 66A Ghost Charge If ANY section in the FIR is 66A — seek immediate quashing of that section. Use this as leverage: "The IO's fundamental legal knowledge is suspect — they charged under a provision struck down 11 years ago."
5. Jurisdiction Challenge Cyber crimes can involve victims, accused, and servers in different jurisdictions. Challenge jurisdiction if the FIR is filed in an inconvenient or incorrect location. However, post-BNSS 173 (Zero FIR), this argument is weaker for FIR registration — but remains valid for trial jurisdiction.
Landmark Judgments
| Case | Year | Ratio | When to Cite |
|---|---|---|---|
| Shreya Singhal v. Union of India | 2015 SC | Section 66A struck down as unconstitutional — violates Art 19(1)(a) | Any FIR citing 66A |
| Arjun Panditrao Khotkar v. Kailash | 2020 SC (3-Judge) | BSA 63 (IEA 65B) certificate mandatory — oral evidence cannot substitute | Challenging electronic evidence |
| Shafhi Mohammad v. State of HP | 2018 SC (3-Judge) | Referred 65B certificate question to larger bench — resolved by Arjun Panditrao | Historical context |
| Google India v. Visakha Industries | 2020 SC | Intermediary loses safe harbour on actual knowledge of illegal content | Platform liability cases |
| K.N. Govindacharya v. Union of India | 2022 Delhi HC | Social media platforms must disclose first originator of illegal content | Tracing anonymous offenders |
Frequently Asked Questions
Can cyber crime FIR be filed at any police station?
Yes — Zero FIR under BNSS 173 applies. You can file at any police station regardless of where the offence occurred. The receiving station will transfer to the jurisdictional Cyber Crime Cell. Additionally, you can file online at cybercrime.gov.in — the NCRP portal routes complaints to the appropriate state police.
WhatsApp messages are my primary evidence. How do I make them admissible?
Three steps are required. (1) Take screenshots with the contact info, timestamps, and your phone's date/time visible. (2) Compute hash value (MD5/SHA-256) of the screenshot files immediately. (3) Prepare a BSA Section 63(2) certificate signed by you (the phone owner). Without this certificate, screenshots are inadmissible under Arjun Panditrao (2020).
Section 66A was struck down. But I have been charged under it. What do I do?
File an immediate quashing application under BNSS 528. Cite Shreya Singhal v. Union of India (2015). The charge is void ab initio. If the entire FIR is based solely on 66A — the entire FIR is quashed. The remaining charges (if any) under other sections can continue.
Can a company be held liable for an employee's cyber crime?
Yes, under Section 85 IT Act, if the offence was committed with the company's consent or due to the company's negligence. Directors and officers "in charge of and responsible for the company's conduct" can be personally prosecuted. The defence: show the company had adequate cyber security policies and the employee acted in violation of company policy.
Is online defamation a criminal offence in India?
Yes — under BNS Section 356 (replacing IPC 499/500), defamation remains a criminal offence punishable with up to 2 years imprisonment. Online defamation is treated the same as offline. The 10 exceptions to defamation apply equally. Section 66A cannot be used for online defamation — it is struck down. Verify this analysis using NyayaVeda AI's source-verified research platform.
Quick Reference Card
⚖️ CYBER CRIME — PRACTITIONER'S QUICK REFERENCE
DUAL REGIME:
- IT Act 2000 → substantive cyber offences
- BNS 2023 → general criminal offences via digital means
- BSA 2023 → electronic evidence admissibility
⚠️ SECTION 66A = STRUCK DOWN (Shreya Singhal 2015) Do NOT charge. Do NOT accept. Quash immediately.
BSA 63 (ELECTRONIC EVIDENCE): Certificate MANDATORY for secondary evidence (printouts, screenshots) Oral evidence CANNOT substitute (Arjun Panditrao 2020)
DUAL CHARGING: Always charge IT Act + BNS for maximum sentencing
EVIDENCE PRESERVATION: 24-hour window — screenshots, hash values, device seizure
KEY CASES:
- Shreya Singhal (2015) — 66A struck down
- Arjun Panditrao (2020) — BSA 63 certificate mandatory
- Google India v Visakha (2020) — intermediary liability
Research Cyber Crime Law Instantly with NyayaVeda AI
Handling a cyber crime case and need the exact IT Act section mapping, BSA 63 compliance requirements, or intermediary liability precedents? NyayaVeda AI delivers source-verified citations in under 12 seconds.
- IT Act + BSA provision cross-referencing
- Digital evidence admissibility case law
- Cyber crime jurisdiction orders from your state
- Hindi + English — research in your preferred language
🔒 Advocate Privacy Shield Concerned about client confidentiality? NyayaVeda AI is DPDP Act 2023 compliant. Automatic Aadhaar/PAN/Phone masking. Your data is never stored or used for training. Client privacy is our responsibility.
Corpus Status: NyayaVeda AI has completely ingested the statutory framework and 43K+ Supreme Court precedents. Our massive 17.8M High Court pipeline is processing at Phase 2 to guarantee absolute zero-hallucination standards.
Disclaimer: This article is for informational and educational purposes only. It does not constitute legal advice. For specific legal matters, consult a qualified advocate registered with the Bar Council of India.
Last Updated: August 2026 | Author: NyayaVeda Legal Research Team
Research these topics in 5 seconds — not 5 hours
858 Central Acts · 1.2 crore+ SC & HC judgments · BNS/BNSS/BSA auto-concordance · Citation-verified · Hindi supported
Related Guides from Other Practice Areas
Disclaimer: This article is for informational and educational purposes only. It does not constitute legal advice. For specific legal matters, consult a qualified advocate registered with the Bar Council of India. NyayaVeda AI is an AI-powered research tool, not a law firm, and does not establish any advocate-client relationship.
