Cyber Laws Cheating by personation by using computer resource – Sec.66D

July 8, 2017

Section 66D of the Information Technology Act, 2000 prescribes criminal punishment of imprisonment up to three years and fine up to one lakh rupees for anyone who cheats by personation using any communication device or computer resource, establishing a specialized statutory mechanism to prosecute digital identity theft, email spoofing, phishing, and online financial fraud across India.

Statutory Text of Section 66D of the Information Technology Act, 2000

Section 66D was inserted into the Information Technology Act, 2000 by the Information Technology (Amendment) Act, 2008 (Act 10 of 2009) with effect from October 27, 2009. The statutory provision reads as follows:

Section 66D. Punishment for cheating by personation by using computer resource: Whoever, by means of any communication device or computer resource cheats by personation, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupees.

Essential Ingredients of the Offence Under Section 66D

To establish a criminal charge under Section 66D of the Information Technology Act, the prosecution must prove the following foundational elements beyond reasonable doubt:

  • Use of Electronic Medium: The accused must have utilized a computer resource (such as a server, desktop, laptop, or cloud platform) or a communication device (such as a mobile phone, tablet, or wireless device).
  • Act of Cheating: The conduct of the accused must satisfy the definition of cheating as conceptualized in criminal jurisprudence, involving fraudulent or dishonest inducement of a victim to deliver property, consent to retention of property, or do or omit to do an act causing harm to body, mind, reputation, or property.
  • Personation (Impersonation): The cheating must be executed by pretending to be someone else, whether a real living person, a deceased individual, an artificial legal entity, a bank representative, a corporate executive, or a fictional persona.
  • Dishonest Intention: Mens rea or dishonest intent must be present at the inception of the electronic interaction.

Interplay Between Section 66D IT Act and Sections 416, 419, and 420 IPC

A frequent question in criminal proceedings is whether Section 66D of the IT Act overrides or operates concurrently with the cheating provisions of the Indian Penal Code (IPC). The statutory relationship is structured as follows:

1. Section 416 and Section 419 IPC (Cheating by Personation)

Section 416 IPC defines cheating by personation generally, while Section 419 IPC provides punishment extending up to three years imprisonment or fine. When personation is carried out through digital media, electronic communications, fake social media profiles, or spoofed email addresses, Section 66D of the IT Act specifically addresses the technological instrumentality used in the crime.

2. Section 420 IPC (Cheating and Dishonestly Inducing Delivery of Property)

Section 420 IPC is an aggravated form of cheating where valuable property or money is dishonestly transferred, carrying a punishment of up to seven years imprisonment. In online financial scams, investigating agencies routinely invoke both Section 66D IT Act and Section 420 IPC simultaneously because the ingredients of both provisions can coexist. Victims navigating financial fraud and corporate recovery should consult the statutory cyber law framework in India to understand jurisdictional thresholds and reporting protocols before state cyber cells.

Common Modalities of Digital Personation and Cyber Fraud

The proliferation of digital transactions and cloud communication has led to various forms of deception penalized under Section 66D:

  • Phishing and Spoofing: Perpetrators create fraudulent websites, SMS links, or emails mimicking legitimate banking portals, government departments, or payment gateways to extract login credentials and one-time passwords (OTPs).
  • Business Email Compromise (BEC): Fraudsters impersonate senior company executives or regular vendors using lookalike email domains, dishonestly directing accounting staff to transfer funds into unauthorized bank accounts.
  • Social Media Impersonation: Creating fake accounts using another person's photograph and name to solicit money or defame the victim.
  • Fake Job and Investment Portals: Posing as recruitment agents or representatives of multinational corporations to deceive job seekers into paying advance processing fees. Organizations seeking preventative risk audits or incident response strategies can seek specialized data protection and cyber security legal consultation to insulate corporate digital infrastructure against unauthorized intrusions.

Evidentiary Requirements and Digital Forensics

Proving an offence under Section 66D requires strict adherence to electronic evidence collection protocols:

  • Electronic Records and Mandatory Certification: Digital evidence such as server access logs, email headers, IP address allocation logs, and WhatsApp chat exports must be accompanied by a mandatory certificate under Section 65B of the Indian Evidence Act, 1872 (or Section 63 of the Bharatiya Sakshya Adhiniyam, 2023) to be admissible in court.
  • IP Address Tracking and CDR Analysis: Investigating officers must secure Internet Protocol Detail Records (IPDR) and Call Detail Records (CDR) from Telecom and Internet Service Providers (TSPs/ISPs) connecting the suspect device with the fraudulent transmission.
  • Device Seizure and Hash Value Integrity: Mobile phones, laptops, and hard drives seized during investigation must be imaged with verified cryptographic hash values (such as SHA-256 or MD5) before transmission to a notified Cyber Forensic Laboratory.

Judicial Precedents and Interpretation of Digital Cheating

Constitutional and appellate courts in India have repeatedly reinforced that the technological means used in cyber impersonation do not alter the fundamental requirements of criminal culpability. In various landmark rulings on cyber jurisprudence, courts have clarified that Section 66D was specifically introduced to bridge statutory gaps where traditional property concepts struggled to accommodate intangible digital credentials, data streams, and virtual identities.

In practice, trial courts are mandated to ensure that the technical chain of custody remains unbroken from the moment of device recovery until the forensic analyst submits their report, ensuring that digital manipulation or evidence tampering is definitively excluded.

Bail, Cognizability, and Trial Procedure

Under Section 77B of the Information Technology Act, offences punishable with imprisonment up to three years are cognizable and bailable. However, when Section 66D is charged alongside Section 420 IPC or Section 468/471 IPC (forgery for the purpose of cheating), the composite offence becomes non-bailable, requiring the accused to seek regular bail or anticipatory bail before the Sessions Court or High Court.

The trial is conducted by a Judicial Magistrate First Class or Metropolitan Magistrate, and the investigation must be conducted by an officer not below the rank of Inspector of Police, as mandated by Section 78 of the Information Technology Act.

Found this helpful?

Share this page with others