Cyber Laws Hacking with computer systems, Data Alteration – Sec.66 (IT Act)

July 4, 2017

Section 66 of the Information Technology Act, 2000 provides the principal penal mechanism in Indian cyber jurisprudence for prosecuting hacking, unauthorized data alteration, and computer-related offences, prescribing rigorous imprisonment up to three years, a fine up to five lakh rupees, or both for acts committed with dishonest or fraudulent intent.

Legislative Evolution and Objective of Section 66

In its original enactment in 2000, Section 66 specifically bore the heading "Hacking with Computer System" and penalized individuals who caused wrongful loss or damage by deleting, altering, or diminishing the utility of information residing inside computer resources. Following the comprehensive Information Technology (Amendment) Act, 2008, the Parliament restructured the provision into an overarching penal mechanism titled "Computer Related Offences". This amendment expanded the scope beyond narrow definitions of hacking to encompass every contravention enumerated under Section 43 when performed with requisite criminal intent within the broader statutory framework of cyber laws in India.

Interplay Between Section 43 (Civil Remedy) and Section 66 (Criminal Offence)

The architecture of the Information Technology Act establishes a clear bifurcated regime between civil damages and criminal prosecution. Section 43 defines civil contraventions for unauthorized access, data downloading, virus introduction, denial of service, and system disruption, holding the wrongdoer liable to pay compensation to the affected party. Conversely, section 66 information technology act transforms these very same physical acts into cognizable criminal offences when accompanied by criminal intention.

To sustain a conviction under Section 66, the prosecution must establish the twin mental states of mens rea in cyber offences section 43, namely acting "dishonestly" or "fraudulently" as defined under Sections 24 and 25 of the Indian Penal Code, 1860 (now Bharatiya Nyaya Sanhita, 2023). In the absence of fraudulent or dishonest intent, the conduct remains exclusively a civil wrong remediable before the Adjudicating Officer under Section 46.

Essential Ingredients of Computer Related Offences

A successful prosecution under Section 66 necessitates strict proof of the following essential ingredients:

  • Unauthorized Physical or Virtual Act: The accused must have performed one or more acts specified in clauses (a) through (j) of Section 43, including unauthorized access, downloading, extraction, virus insertion, or data alteration computer offences india.
  • Targeting a Computer Resource: The target must satisfy the statutory definition of a computer, computer system, computer network, or electronic data repository.
  • Dishonest or Fraudulent Mens Rea: The act must have been executed with the intention of causing wrongful gain to one person or wrongful loss to another, or with the intent to defraud.
  • Direct Causation: A demonstrable nexus must link the unauthorized electronic interference to the resulting data corruption, unauthorized extraction, or system downtime.

Sub-Categories of Hacking and Specialized Offence Sections

While Section 66 serves as the umbrella provision for hacking with computer systems it act, the 2008 amendments introduced specific standalone sections (66A through 66F) to address nuanced categories of cyber infractions. These include Section 66B (dishonestly receiving stolen computer resources), Section 66C (punishment for identity theft and electronic signature theft), Section 66D (cheating by personation using computer resources), Section 66E (violation of privacy), and Section 66F (cyber terrorism). Navigating these specialized provisions frequently requires expert guidance from a cyber security and data protection lawyer to ensure proper legal defense or prosecution strategies.

Corporate Liability and Vicarious Responsibility under Section 85

Section 85 of the Information Technology Act extends liability for offences under Section 66 to companies, corporate entities, and partnerships. When a cyber offence is committed by a corporate body, every person who was in charge of and responsible for the conduct of the business at the time of the contravention is deemed guilty alongside the entity itself. Corporations must implement comprehensive technical safeguards, access control matrices, employee confidentiality undertakings, and incident response protocols to mitigate the risk of corporate data theft and regulatory non-compliance.

Comparative Analysis: Civil vs. Criminal Liability

Legal DimensionSection 43 (Civil Liability)Section 66 (Criminal Offence)
Nature of RemedyCompensation and damages by way of penaltyPenal sanctions (imprisonment and criminal fine)
Mental State (Mens Rea)Unauthorized act without requisite fraudulent intentDishonest or fraudulent intention mandatory
Adjudicating ForumAdjudicating Officer (IT Secretary / Cyber Appellate)Chief Judicial Magistrate / Court of Sessions
Maximum PunishmentFinancial compensation to victim up to statutory limitsImprisonment up to 3 years and/or fine up to Rs. 5 Lakh
Standard of ProofPreponderance of probabilitiesProof beyond reasonable doubt

Investigation Procedures and Digital Forensics Compliance

The prosecution of cybercrimes under Section 66 relies heavily on electronic evidence and digital forensic preservation. Investigating officers must secure digital hash values, maintain strict chain of custody for seized hard drives and mobile devices, and obtain mandatory statutory certification under Section 65B of the Indian Evidence Act, 1872 (now Section 63 of Bharatiya Sakshya Adhiniyam, 2023). Failure to comply with electronic evidence certification standards often undermines the prosecution case during criminal trials.

Bail Provisions and Cognizability under Section 77B

Under Section 77B of the Information Technology Act, offences punishable with imprisonment of three years and above are cognizable, while offences with imprisonment up to three years are generally bailable. Section 66 falls within the bailable category, permitting the accused to seek bail as a matter of entitlement before the jurisdictional magistrate, provided conditions preventing tampering with digital logs or witness intimidation are scrupulously observed.

Landmark Precedents and Practical Safeguards

Judicial trends in India demonstrate an increasing intolerance towards unauthorized database intrusions, source code theft, and intellectual property exfiltration. In prominent decisions rendered by High Courts across the country, courts have consistently emphasized that commercial competitors who recruit employees to exfiltrate proprietary customer data face direct prosecution under Section 66 alongside criminal breach of trust under the general penal law.

Statutory Penalties and Final Enforcement Perspective

The statutory punishment for hacking in india under Section 66 reflects the severity with which the legal system views intentional interference with digital infrastructure. Indian courts enforce rigorous bail conditions and custodial sentences in corporate data espionage, ransomware deployments, and unauthorized banking database breaches, underscoring the critical necessity for robust cybersecurity compliance across modern enterprises.

Found this helpful?

Share this page with others