Cheating by personation by using computer resource - Sec.66D

Section 66D of the IT Act addresses cheating by personation via computer resources. Understand where impersonation ends and fraud begins, and learn how to defend your organization against phishing and social engineering.

May 21, 2012

Section 66D of the Information Technology Act, 2000 penalizes cheating by personation using computer resources or communication devices. Targeting online impersonation, phishing scams, and business email compromise, the statute imposes imprisonment up to three years and a fine up to one lakh rupees upon conviction.

Understanding Cheating by Personation in Digital Environments

Section 66D translates the traditional offence of cheating by personation into modern networked ecosystems. In legal terms, cheating by personation occurs when a person pretends to be another individual, represents that they are a person who they are not, or knowingly substitutes one individual for another to deceive a victim into parting with property or valuable security.

The distinguishing feature of Section 66D is the statutory requirement that the deceptive act must be executed using a communication device or computer resource. This covers a broad spectrum of digital misconduct, ranging from creating fake social media profiles and spoofing executive email accounts to operating cloned banking web portals. The statute operates alongside general criminal provisions governing forgery for the purpose of cheating under Section 468, enabling law enforcement to charge both electronic deception and underlying fraud.

Common Attack Patterns and Business Email Compromise Schemes

Digital impersonation has evolved from crude email messages into highly coordinated financial fraud schemes targeting enterprises, legal practices, and public institutions. Attackers employ sophisticated technical and psychological strategies:

  • Business Email Compromise (BEC): Attackers impersonate senior corporate executives or trusted legal counsel to instruct finance personnel to transfer urgent funds to fraudulent bank accounts.
  • Vendor Invoice Spoofing: Intercepting email threads between companies and legitimate suppliers, inserting slightly altered bank payment details on counterfeit invoices.
  • Domain Typosquatting: Registering web domains that look visually identical to a target company's domain, misleading customers and partners.
  • Social Media Executive Impersonation: Establishing unauthorized executive profiles to solicit fraudulent investments, extract sensitive corporate data, or damage public reputation.
  • Vishing and Deepfake Audio: Utilizing synthesized voice cloning or spoofed caller ID systems to impersonate bank officials or senior managers over the phone.

In corporate wire fraud cases, fraudsters often conduct weeks of covert reconnaissance inside a compromised email tenant to study invoice approval cadences before striking.

Statutory Penalties and Procedural Requirements

Section 66D prescribes imprisonment extending up to three years and a fine up to one lakh rupees. The offence is cognizable and bailable, triable by a Judicial Magistrate of the First Class. In addition to statutory penal terms, criminal courts frequently order restitution of defrauded funds and confiscation of devices utilized during the commission of the offence.

Because fraudulent funds move rapidly through multiple intermediate bank accounts and cryptocurrency wallets, swift legal intervention is paramount. Complainants must register formal complaints on the National Cyber Crime Reporting Portal and serve immediate statutory notices on banking intermediaries to freeze beneficiary accounts before funds are withdrawn.

Evidentiary Rigor and Digital Forensic Investigation

Establishing proof of digital personation requires tracing electronic communications back to the specific physical individual behind the screen. Defense strategies often argue that open Wi-Fi networks were hijacked, or that malware executed the fraudulent transactions without human knowledge.

Building an irrefutable legal case requires thorough digital forensics:

  • Raw Email Header Analysis: Preserving original message headers to evaluate SPF, DKIM, and DMARC authentication failures and identify originating IP addresses.
  • Forensic Email Recovery: Applying certified forensic email recovery techniques to extract complete server message stores and unedited mailbox logs.
  • ISP Subscriber Attribution: Obtaining court-sanctioned subpoenas to compel Internet Service Providers to disclose dynamic IP assignment logs, subscriber identities, and physical installation addresses.
  • Intermediary Log Preservation: Serving preservation notices on domain registrars, cloud hosting providers, and communication platforms to preserve server access logs before standard retention schedules expire.

Conducting an organized cyber crime investigation ensures that all technical evidence satisfies the strict certificate requirements of Section 65B of the Indian Evidence Act.

Enterprise Incident Recovery and Cyber Insurance Coordination

Following a business email compromise or executive impersonation incident, corporate risk management teams must engage their cyber insurance carriers immediately. Most commercial cyber insurance policies provide coverage for digital fraud, fund transfer fraud, and forensic investigation expenses, provided formal notice is submitted within specified policy notification windows.

Coordinating forensic findings with legal counsel, specialized digital investigators, and cyber insurance claims adjusters facilitates rapid claim settlement and ensures that evidence submitted to insurance adjusters matches the technical filings submitted to law enforcement agencies.

International Jurisdiction and Cross-Border Wire Fraud Recovery

Digital impersonation and business email compromise schemes frequently operate across multiple sovereign jurisdictions. Fraudsters located outside India routinely register spoofed domain names using offshore bulletproof hosting providers and funnel misappropriated funds through international cryptocurrency exchanges.

Indian law enforcement agencies collaborate with international bodies through Mutual Legal Assistance Treaties (MLAT), Interpol Purple Notices, and the Budapest Convention framework where applicable. Corporate legal teams handling cross-border fraud must coordinate simultaneously with local cyber crime cells, the Financial Intelligence Unit (FIU-IND), and corresponding overseas law enforcement agencies to issue emergency stop-payment orders and preserve foreign server infrastructure records.

Preventative Controls and Enterprise Brand Protection

Preventing digital impersonation requires combining technical safeguards with strict procedural payment verification controls. Organizations should deploy DMARC enforcement policies with reject settings to prevent unauthorized third parties from sending spoofed emails using the corporate domain. Web applications and client portals should be hardened through continuous application security assessments.

When an attacker launches a malicious impersonation campaign targeting your corporate brand, engaging in structured online reputation management and following a disciplined ORM process ensures rapid takedown of fraudulent web assets and social profiles.

If your organization has suffered financial loss from business email compromise, or if bad actors are actively impersonating your brand online, contact our cyber response team for immediate technical investigation and legal enforcement.

Found this helpful?

Share this page with others