Punishment for attempt to commit offences – Sec.84C

July 29, 2017

Section 84C of the Information Technology Act 2000 establishes criminal liability for any individual who attempts to commit a cyber crime or causes such an offence to be committed. Under Section 84C Information Technology Act, whenever an offender takes an overt step toward executing an offence punishable under the Act, the person faces imprisonment for up to one-half of the longest term provided for that offence, fine, or both. This statutory provision ensures that unsuccessful or interrupted digital crimes do not escape prosecution simply because the unlawful outcome was averted.

Legislative Background and Statutory Text

The penal framework of the original Information Technology Act 2000 lacked an overarching inchoate liability clause specific to digital crimes. Recognizing that modern cyber threats frequently involve multi-stage execution paths where malicious actors are intercepted before achieving their final objective, Parliament introduced Section 84C through the Information Technology Amendment Act 2008.

The exact statutory wording of Section 84C reads as follows:

"Whoever attempts to commit an offence punishable by this Act or causes such an offence to be committed, and in such an attempt does any act towards the commission of the offence, shall, where no express provision is made for the punishment of such attempt, be punished with imprisonment of any description provided for the offence, for a term which may extend to one-half of the longest term of imprisonment provided for that offence, or with such fine as is provided for the offence or with both."

Essential Ingredients of an Attempt Under the Act

To secure a conviction for an attempt under Section 84C, the prosecution must establish three fundamental ingredients:

  • Intention or Knowledge: The accused must possess the specific guilty mind (mens rea) to commit a substantive offence defined and penalized under Chapter XI or other operative sections of the Information Technology Act.
  • Overt Act Towards Commission: The perpetrator must perform an act moving beyond mere preparation, directly pointing toward the execution of the crime.
  • Absence of Express Alternative Provision: Section 84C operates as a residual penal clause, applying wherever the specific substantive section does not separately prescribe a distinct penalty for the attempt.

Distinguishing Preparation from Attempt in Cyberspace

Criminal jurisprudence divides the development of a crime into four stages: intention, preparation, attempt, and completed execution. While mere intention and preparation remain generally non-punishable in ordinary criminal law, an attempt marks the threshold where criminal liability attaches.

In digital environments, distinguishing preparation from attempt requires careful technical analysis:

  • Preparation Stage: Gathering open-source intelligence, researching target IP addresses, or downloading standard network testing software does not by itself constitute an attempt.
  • Attempt Stage: Injecting malicious payloads into a web application, sending deceptive spear-phishing messages with credential-harvesting links, or deploying automated password-cracking scripts against a protected server represents an attempt to commit cyber offences because the actor has initiated an overt act directly targeted at compromising the system.

Scope of Substantive Offences Covered

Section 84C applies broadly across numerous offences outlined in the Information Technology Act, providing a calibrated punishment for cyber crime attempts. Key areas of application include:

  • Hacking and System Damage (Section 66): Attempting to access, modify, or destroy computer data without authorization, even if firewall rules or intrusion prevention systems block the intrusion.
  • Identity Theft (Section 66C): Attempting to capture or fraudulently use another person's digital signature, password, or biometric identification.
  • Cheating by Personation (Section 66D): Setting up deceptive portals or transmitting fraudulent emails to deceive victims into transferring funds.
  • Violation of Privacy (Section 66E): Attempting to capture, transmit, or publish images of private areas of an individual without consent.
  • Cyber Terrorism (Section 66F): Attempting to disrupt critical information infrastructure or access classified electronic data threatening national security. Because Section 66F carries potential life imprisonment, an attempt under Section 84C can lead to extensive prison sentences.
  • Transmission of Obscene or Sexually Explicit Material (Sections 67, 67A, and 67B): Attempting to publish or transmit prohibited digital content.

Quantum of Punishment and Sentencing Principles

The sentencing formula prescribed in Section 84C mirrors the general principle found in Section 511 of the Indian Penal Code 1860, while tailoring it to the digital regulatory architecture. Where the substantive offence carries a maximum term of three years imprisonment (such as Sections 66, 66C, or 66D), an attempt under Section 84C is punishable with imprisonment for up to one year and six months, fine, or both.

For more severe crimes, such as second convictions under Section 67A (which carry a maximum term of seven years imprisonment), an attempt is punishable with imprisonment for up to three and a half years. This graduated approach ensures that the punishment remains strictly proportional to the gravity of the underlying offence.

Digital Forensics and Evidentiary Requirements

Proving liability for inchoate cyber offences in a court of law relies heavily on digital forensics and contemporaneous server logging. Because the substantive harm was not fully consummated, the prosecution must present objective digital evidence proving the suspect's intentional progression toward the crime.

Essential forensic artifacts include web server access logs, firewall connection attempts, command-line history on seized endpoints, keystroke logs, and cryptographic hashes of intercepted malware payloads. Compliance with Section 65B of the Indian Evidence Act 1872 is mandatory when tendering electronic records to ensure admissible electronic evidence before trial courts.

Practical Takeaways for Legal and Security Professionals

The insertion of Section 84C by the Information Technology Amendment Act 2008 filled a critical gap in India's cyber law framework. Organizations and incident response teams must document interrupted intrusion attempts systematically, as failed breach attempts provide valid grounds for lodging formal police complaints under Section 84C.

Security administrators should preserve raw firewall logs and system audit trails during suspicious activity, enabling law enforcement agencies to establish the necessary overt act and prosecute malicious actors before severe data loss or system disruption occurs.

Found this helpful?

Share this page with others