Bogus websites, Cyber Frauds - Sec.420 IPC

Section 420 IPC is the primary weapon against bogus websites and online cheating. Learn how phishing scams induce victims into delivery of property and the legal risks for fraudsters.

May 21, 2012

Section 420 of the Indian Penal Code covers cheating and dishonestly inducing the delivery of property through fake websites, phishing domains, and online financial scams. Operating a bogus site to deceive victims into transferring money or sensitive credentials is a cognizable, non-bailable offence carrying up to seven years of imprisonment.

Mechanics of Digital Cheating and Fraud Under Section 420 IPC

Section 420 IPC applies to offences where a person cheats and dishonestly induces the victim to deliver any property to any person, or to make, alter, or destroy the whole or any part of a valuable security. In the digital ecosystem, property encompasses monetary funds, banking credentials, intellectual property, personal identity data, and digital assets transferred under false pretenses.

Online cyber fraud relies on technological deception to trick users into believing they are interacting with genuine financial institutions, government portals, or commercial brands. Perpetrators establish fraudulent web applications that mirror authentic login panels, payment gateways, or customer service portals. Organizations seeking to safeguard their digital infrastructure against unauthorized domain clones implement application security controls to prevent web spoofing and data interception. Structured security controls should be aligned with cyber incident response planning best practices.

Cheating is defined under Section 415 IPC as fraudulently or dishonestly deceiving any person to deliver property or consent to retain property. Section 420 IPC serves as the aggravated statutory form of cheating where delivery of property actually occurs as a direct result of the fraudulent deception.

In digital cheating cases, prosecutors present technical proof showing that the accused registered the fraudulent domain name, configured deceptive DNS records, and directed incoming victim traffic to private bank accounts controlled by the fraud ring.

Common Types of Bogus Website Scams and Typosquatting Schemes

Cybercriminals utilize diverse technical schemes to execute Section 420 IPC offences in digital environments:

  • Typosquatting and Lookalike Domains: Registering domain names that closely resemble established brands to deceive unsuspecting consumers.
  • Credential Harvesting Portals: Building cloned login screens to capture corporate credentials, payment card details, and multi-factor authentication tokens.
  • Fake E-Commerce Stores: Operating counterfeit storefronts that collect customer payments without fulfilling orders or delivering goods.
  • Investment and Crypto Scams: Devising fraudulent online trading dashboards promising unsupportable financial returns to investors.

Identifying vulnerabilities across web applications and corporate perimeter controls requires periodic penetration testing to ensure external threat actors cannot exploit system weaknesses to launch fake domain campaigns. Legal proceedings are further governed by the statutory provisions of the Information Technology Act statutory framework.

Threat actors often deploy automated scripts and offshore hosting servers to rapidly generate hundreds of lookalike domains during phishing campaigns. Coordinated legal takedown strategies targeting domain registrars and DNS providers remain critical to curtailing active fraud infrastructure.

Proving Dishonest Inducement in Online Financial Crimes

To secure conviction under Section 420 IPC in bogus website prosecutions, law enforcement must establish specific evidentiary benchmarks:

A crucial legal distinction in Section 420 prosecutions is demonstrating dishonest intention from the very inception of the scheme. In online fraud cases, creating fake branding, registering domains using false WHOIS data, and setting up shell merchant accounts provide undeniable proof of fraudulent intent from inception.

Digital forensic analysts examine web server access logs, payment gateway callbacks, and TLS certificate registration records to establish the connection between the suspect and the fraudulent domain infrastructure.

Legal ElementDigital Proof RequirementStatutory Weight
Deception / MisrepresentationCloned website source code, fake logos, misleading domain namesEstablishes fraudulent initial inducement
Dishonest Intention from InceptionServer logs, fake bank account creation records, anonymous hosting registrationDifferentiates criminal fraud from breach of contract
Delivery of PropertyBank transaction records, payment gateway receipts, crypto wallet ledger dataCompletes statutory requirements of Section 420

Accessing the Section 420 IPC statutory terms on Indian Kanoon provides exact statutory phrasing and jurisprudence on cheating offences.

Penalties, Asset Recovery, and Criminal Complaints

Section 420 IPC carries a maximum penalty of seven years of rigorous imprisonment along with a mandatory fine. Because it is a cognizable and non-bailable offence, police officers have the authority to arrest accused individuals without a warrant upon registering an FIR. Cyber Crime Cells coordinate with financial intermediaries and domain registrars to freeze fraudulent bank accounts and lock malicious domain names during active investigations.

Where bogus websites defraud multiple victims across different states, law enforcement agencies coordinate through multi-jurisdictional cyber crime units to pool digital evidence and freeze illicit financial assets across banking channels.

Under Indian criminal procedure, courts can order the attachment of bank accounts and properties acquired through proceeds of cyber crime. Victims of online financial fraud can file applications under Section 451 CrPC for the interim release of recovered funds during trial proceedings.

Proactive Corporate Defense Against Brand Imitation Scams

Organizations must establish aggressive countermeasures to protect corporate brand identity and shield clients from bogus website frauds:

  1. Continuous Brand Monitoring: Implement automated domain monitoring tools to detect newly registered domain names targeting brand trademarks.
  2. Immediate Abuse Reporting: Submit takedown notices to domain registrars, hosting providers, and search engines citing trademark infringement and cyber fraud.
  3. Lodge Police Complaints: File formal complaints under Section 420 IPC and Section 66D IT Act with law enforcement authorities.
  4. Issue Public Security Advisories: Notify customers regarding verified official domain URLs and warn against fraudulent lookalike websites.
  5. Enforce SSL/TLS Certificate Revocation: Report fraudulent SSL/TLS certificates issued for lookalike domains to Certificate Authorities.

Contact our cybersecurity team for a rapid audit of your digital presence and to initiate a legal and technical offensive against the fraudsters.

Found this helpful?

Share this page with others