Act to apply for cyber offence or cyber contraventions committed outside India - Sec.75

Section 75 IT Act establishes India's jurisdiction over cybercrimes committed abroad that target Indian computer networks. Learn how the law protects your assets from international threats.

May 21, 2012

Section 75 of the Information Technology Act 2000 extends India's legal jurisdiction over any cyber offence or contravention committed outside Indian territory by any person, regardless of nationality, provided the conduct involves a computer, computer system, or computer network located in India.

The Doctrine of Extraterritorial Jurisdiction in Cyber Space

The internet operates without physical boundaries, allowing threat actors located in one country to launch destructive attacks against critical digital infrastructure in another. To prevent international borders from serving as a shield for cyber criminals, Section 75 of the Information Technology Act 2000 establishes a clear statutory doctrine of extraterritorial jurisdiction.

By anchoring legal authority to the location of the targeted digital infrastructure rather than the physical location of the attacker, Section 75 empowers Indian courts and law enforcement agencies to take cognizance of cyber crimes originating anywhere in the world. This extraterritorial mandate is an essential pillar of cyber law in India, ensuring that domestic enterprises and critical government systems receive strong statutory protection against foreign cyber adversaries.

Without extraterritorial reach, international hacking groups, offshore ransomware syndicates, and foreign botnet operators could target Indian financial networks with complete impunity. Section 75 removes this jurisdictional gap by making the domestic location of the computer resource the deciding factor.

Statutory Scope and Essential Conditions Under Section 75

For Indian courts to exercise extraterritorial jurisdiction under Section 75, two fundamental statutory criteria must be satisfied:

  • Universal Subject Applicability: The provisions of the IT Act apply to any person, irrespective of their citizenship, nationality, or physical residence at the time of the offence.
  • Target Nexus in India: The act or conduct constituting the offence or contravention must involve a computer, computer system, or computer network located within the territory of India.

This target-based territorial nexus covers international ransomware attacks, unauthorized database access, distributed denial of service campaigns, and cross-border financial scams that touch Indian servers, cloud instances, or endpoint networks.

The statutory definition of a computer resource in India encompasses cloud instances hosted within Indian data regions, local branch office networks, edge computing nodes, and mobile devices operating on domestic telecommunication infrastructure. If an offshore attacker injects malicious code or steals proprietary databases from an Indian resource, the jurisdictional test under Section 75 is fully satisfied.

Corporate Liability and Attempt Provisions in Cross-Border Attacks

Extraterritorial application extends not only to individual hackers but also to foreign corporate entities and organized syndicates. When overseas companies engage in unlawful data harvesting or unauthorized interception of Indian communications, they face statutory liability under the Act.

In complex cross-border cases, Section 75 operates in synergy with offences by companies under Section 85 of the IT Act, holding corporate executives accountable when offences are committed with their consent or neglect. Additionally, foreign actors who initiate unsuccessful infiltration attempts remain punishable under punishment for attempt under Section 84C, ensuring complete legal coverage from initial probe to full breach.

This extensive liability framework prevents foreign corporate entities from delegating illicit electronic surveillance or unauthorized web scraping to offshore subsidiaries while claiming immunity under domestic laws.

Practical Challenges in Cross-Border Enforcement and MLAT Protocols

While Section 75 provides detailed jurisdictional authority, cross-border law enforcement involves complex international procedural workflows. Extraditing foreign suspects and securing offshore server evidence requires structured cooperation between sovereign nations.

Indian law enforcement agencies employ Mutual Legal Assistance Treaties (MLAT), Letters Rogatory (LR) issued through judicial channels, and Interpol Red Notices to track international offenders. Establishing formal FIR registration under Section 75 serves as the mandatory legal foundation required to trigger these international cooperation treaties and compel foreign service providers to preserve volatile electronic records.

Additionally, diplomatic channels and international cyber defense pacts enable Indian investigators to coordinate with foreign computer emergency response teams and cross-border cyber task forces to freeze illicit financial flows before funds leave international banking networks.

Defending Critical Digital Assets with Proactive Security Controls

Because cross-border legal resolution takes time, Indian organizations must deploy resilient defensive measures to mitigate international cyber threats before catastrophic damage occurs. Key security controls include:

  • Geographic IP Filtering: Blocking network traffic and API requests originating from untrusted international regions that have no legitimate business nexus with your services.
  • Resilient Threat Monitoring: Partnering with continuous managed security providers to maintain 24/7 security operations center (SOC) surveillance against advanced persistent threats.
  • Distributed Infrastructure Redundancy: Deploying multi-region failover and distributed cloud defenses to absorb offshore DDoS attacks.
  • Strict Access Segmentation: Isolating internal database networks from public internet facing endpoints to prevent lateral movement.
  • Continuous Threat Intelligence: Ingesting global cyber threat feeds to identify emerging attack signatures and malicious foreign IP ranges before exploitation attempts occur.

Digital Forensics for Cross-Border Evidence Admissibility

Securing convictions and civil compensation in cross-border cases demands rigorous digital forensic evidence demonstrating that foreign network traffic directly targeted an Indian computer resource. Investigators must establish an unbroken cryptographic chain of custody.

Utilizing accredited digital forensics methodologies, analysts reconstruct attack vectors, unmask proxy nodes and VPN exit points, capture malicious payload signatures, and preserve routing logs. This technical proof is certified under Section 65B of the Indian Evidence Act, ensuring admissibility before Indian courts and international judicial tribunals.

Strategic Response When Overseas Actors Target Indian Systems

If your enterprise infrastructure or confidential data is targeted by an international cyber attack, take the following strategic response measures:

  1. Isolate compromised systems immediately to prevent further exfiltration while keeping memory states intact for forensic preservation.
  2. Report the breach to the Indian Computer Emergency Response Team (CERT-In) in compliance with mandatory reporting timelines.
  3. File a formal cyber crime FIR invoking Section 75 to initiate international investigation mechanisms.
  4. Consult our cyber law specialists to coordinate incident response, manage regulatory disclosures, and pursue cross-border legal remedies.

Found this helpful?

Share this page with others