Cyber Laws Identity theft – Sec.66C

July 7, 2017

Section 66C of the Information Technology Act, 2000 defines and penalizes identity theft in India, prescribing imprisonment of up to three years and a fine of up to one lakh rupees for fraudulently or dishonestly using another person's electronic signature, password, or unique identification feature. This statutory provision forms a cornerstone of Indian cyber jurisprudence against unauthorized digital impersonation, credential misappropriation, and electronic account hijacking.

Statutory Definition and Legal Elements of Section 66C

Introduced into the Information Technology Act, 2000 through the Information Technology (Amendment) Act, 2008, Section 66C establishes clear criminal liability for identity theft. The exact statutory text provides as follows:

Section 66C. Punishment for identity theft: Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.

To secure a conviction under Section 66C, the prosecution must establish three foundational ingredients beyond reasonable doubt:

  • Mens Rea (Guilty Mind): The perpetrator must act either fraudulently (defined under Section 25 of the Indian Penal Code as acting with intent to defraud) or dishonestly (defined under Section 24 of the IPC as acting with the intention of causing wrongful gain to one person or wrongful loss to another person).
  • Actus Reus (Unlawful Act): The accused must actively "make use of" protected electronic identification attributes belonging to another natural person, corporate body, or public entity without legal authorization.
  • Protected Identifiers: The misappropriated asset must constitute an electronic signature, digital signature certificate (DSC), password, access code, biometric identifier (such as facial geometry, fingerprint, or iris scan), or any other unique electronic identification feature (such as an Aadhaar number, PAN, or cryptographic token).

Distinction Between Section 66C and Related Cyber Offenses

The Information Technology Act contains several interconnected provisions addressing different types of computer-related fraud. It is vital to distinguish Section 66C from neighboring statutory sections:

  • Section 66C vs. Section 66D (Cheating by Personation): While Section 66C penalizes the fraudulent or dishonest use of identification credentials (identity theft), Section 66D punishes cheating by personation using a computer resource. Section 66C focuses on credential misappropriation, whereas Section 66D requires the completed offense of cheating under Section 415 IPC.
  • Section 66C vs. Section 43/66 (Hacking and Data Theft): Section 43 read with Section 66 penalizes unauthorized access, downloading, damage, or extraction of computer data. Section 66C specifically targets the active exploitation and unauthorized application of personal identification parameters.
  • Section 66C vs. IPC Provisions (Sections 419, 468, and 471): Traditional criminal law penalizes forgery and personation. Under the doctrine of special law overriding general law, Section 66C applies specifically to electronic identification features, though charges are frequently framed concurrently under both statutes.

For a detailed analysis of how digital crimes are classified and prosecuted under statutory regulations, explore our guide on the complete statutory framework of cyber laws in India, which covers procedural and substantive IT Act mechanisms.

Investigation Procedures and Digital Forensics Under Section 66C

Investigating identity theft requires structured technical and forensic methodologies to trace electronic evidence from the point of credential compromise to the final unauthorized transaction. Key forensic stages include:

  1. Log Extraction and IP Attribution: Investigating officers extract server access logs, authentication timestamps, and IP addresses to identify the geographic origin and ISP of the unauthorized session.
  2. Device Seizure and Forensic Imaging: Suspect hardware is seized following strict chain-of-custody protocols, creating bit-stream forensic images to preserve volatile metadata without altering original files.
  3. Evidence Certification Under Section 65B: All digital evidence, including log files, email headers, network captures, and database extracts, must be accompanied by a mandatory certificate under Section 65B of the Indian Evidence Act, 1872 (or Section 63 of the Bharatiya Sakshya Adhiniyam, 2023) to be admissible in judicial proceedings.

Summary Matrix: Elements, Penalties, and Procedural Nature

ParameterStatutory ProvisionPractical Legal Effect
Maximum PunishmentImprisonment up to 3 years and fine up to Rs. 1,00,000Sentencing considers quantum of financial harm caused
Cognizability and BailCognizable and bailable under Section 77B of IT ActPolice may arrest without warrant; bail available as matter of right
Investigating AuthorityPolice officer not below the rank of Inspector (Section 78)Investigation by sub-inspector invalid unless specifically empowered
Compounding of OffenseCompoundable under Section 77A of IT ActMay be settled between victim and offender with court permission

Judicial Trends and Landmark Case Rulings

Indian courts have progressively expanded the judicial interpretation of identity theft in digital environments. In Syed Asifuddin v. The State of Andhra Pradesh (2006 Cri LJ 4314), the Andhra Pradesh High Court held that altering the electronic serial number (ESN) of a mobile phone constitutes source code tampering and identity theft under the IT Act. Similarly, courts have applied Section 66C in cases involving phishing schemes, social media account hijacking, and unauthorized SIM swap attacks, establishing that any digital token enabling access to personal data falls within the ambit of unique identification features.

Furthermore, in financial fraud prosecutions, magistrates frequently evaluate the simultaneous invocation of Section 66C alongside Section 420 of the IPC to penalize unauthorized credit card cloning, biometric ATM skimming, and unauthorized corporate email compromise. These judicial precedents demonstrate that electronic identity protection extends across consumer, banking, and enterprise digital ecosystems.

Victim Remedies and Compliance Guidelines

Victims of digital identity theft should act promptly to minimize financial and legal harm. Immediate remedial measures include filing a formal complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in), notifying relevant banking and service intermediaries to freeze compromised accounts, and obtaining forensic preservation of electronic communication records.

Organizations handling sensitive user information must establish multi-factor authentication (MFA), role-based access control, cryptographic key management, and data protection governance. For guidance on regulatory compliance, consult with specialized counsel providing data protection and cyber security advisory to safeguard organizational digital infrastructure.

Found this helpful?

Share this page with others