Dishonestly receiving stolen computer resource or communication device - Sec.66B

Section 66B of the IT Act targets the dishonest receipt or retention of stolen computer resources. This post explains the legal implications, the definition of "dishonest," and how businesses can protect themselves from hardware-related fraud.

May 21, 2012

Section 66B of the Information Technology Act, 2000 penalizes dishonestly receiving or retaining stolen computer resources or communication devices. Designed to curb illicit hardware trafficking, the statute prescribes imprisonment up to three years, a fine reaching one lakh rupees, or both upon conviction.

Legal Scope and Statutory Elements of Section 66B

Section 66B extends established penal principles regarding the possession of stolen goods into the domain of modern information technology. To establish a criminal charge under Section 66B, the prosecution must prove three statutory elements: the property in question meets the legal definition of a computer resource or communication device; the asset was obtained by committing theft or misappropriation; and the accused received or retained the asset dishonestly, possessing knowledge or reasonable grounds to believe it was stolen.

The statutory definition of computer resources and communication devices is broad under the IT Act. A computer resource includes mainframe servers, personal workstations, cloud storage volumes, database clusters, microprocessors, and internal software components. Communication devices encompass mobile smartphones, network switches, hardware security modules (HSMs), and specialized telecommunication routers. This detailed statutory coverage links general criminal offences such as the theft of computer hardware under Section 378 with specialized computer crimes, including unauthorized data alteration provisions under Section 66.

Understanding Dishonest Intent and the Standard of Reason to Believe

The legal boundary between a bona fide purchaser of secondary IT equipment and a criminal offender under Section 66B rests upon mens rea. Under Indian criminal law, a person acts dishonestly when their intent is to cause wrongful gain or wrongful loss. The phrase 'reason to believe' denotes sufficient knowledge of facts that would lead an ordinary, reasonable person to conclude that the goods were stolen or unlawfully acquired.

In commercial and corporate litigation, courts consider several practical indicators when evaluating whether a buyer possessed reason to believe hardware was stolen:

  • Grossly Sub-Market Pricing: Purchasing enterprise networking gear, servers, or high-end laptops at steep discounts without legitimate liquidation documentation.
  • Omission of Commercial Chain of Custody: Failing to obtain genuine tax invoices, bills of sale, or asset disposal authorizations from previous corporate owners.
  • Altered or Defaced Physical Identifiers: Retaining hardware where serial numbers, asset tags, barcode labels, or MAC addresses have been scratched, painted over, or reprogrammed.
  • Intact Proprietary Data Residue: Possessing storage media that retains active corporate directories, unencrypted customer records, or proprietary source code belonging to another entity.

Ignorance of commercial provenance is rarely accepted as a legal defense when corporate purchasers neglect standard due diligence procedures during secondary hardware transactions.

Corporate Exposure in Secondary Market IT Procurement

Enterprises frequently update data center infrastructure by procuring refurbished equipment or disposing of decommissioned systems. When corporate procurement teams bypass vendor verification processes, companies risk acquiring hardware misappropriated from other corporate networks. This exposes the enterprise to sudden police seizure of mission-critical production servers, breach of contract claims, and criminal liability under Section 66B.

Beyond statutory legal risks, unverified secondary hardware poses severe cybersecurity threats. Stolen equipment may contain malicious firmware modifications, hardware implants, or covert rootkits installed by threat actors. Integrating an enterprise managed security architecture ensures that all procured network components undergo rigorous quarantine, firmware validation, and configuration scanning prior to production integration.

Digital Forensics and Hardware Provenance Verification

When an enterprise discovers stolen hardware within its inventory or recovers misappropriated internal assets, technical verification must precede administrative action. Forensic examiners must extract immutable hardware identifiers and audit drive partitions without modifying the underlying data structures.

Specialists apply structured digital forensics methodologies to analyze motherboard firmware signatures, internal solid-state drive controller serials, and operating system boot logs. If corporate devices were unlawfully removed by former employees or subcontractors, initiating an objective cyber crime investigation provides the technical documentation necessary to establish lawful ownership and support law enforcement recovery.

Forensic disk imaging captures partition tables, deleted volume headers, and cryptographic volume signatures, creating an unassailable digital chain of custody that complies with Indian statutory standards for courtroom evidence.

Supply Chain Vulnerabilities and Regulatory Compliance Standards

Global technology supply chains introduce subtle risks that extend beyond direct physical theft. High-technology enterprises frequently encounter counterfeit or grey-market networking components routed through intermediary brokers. When components originate from compromised supply lines, companies face severe compliance sanctions under regulatory directives issued by the Indian Computer Emergency Response Team (CERT-In) and sector-specific bodies such as the Reserve Bank of India (RBI) or the Securities and Exchange Board of India (SEBI).

Regulated financial entities and critical information infrastructure (CII) operators are legally required to maintain authenticated equipment provenance logs. Failure to verify hardware chain of title can trigger administrative fines, operational suspension, and mandatory disclosure obligations under national cybersecurity directives. Documenting hardware procurement through formal vendor agreements containing explicit indemnification and asset title guarantees shields enterprises from inadvertent statutory exposure.

Enterprise Governance and Asset Protection Frameworks

Protecting an organization from the legal and operational liabilities of Section 66B requires end-to-end hardware lifecycle management. Organizations should implement structured asset controls across all operational departments:

  • Approved Vendor Channels: Procure secondary and refurbished hardware exclusively from certified original equipment manufacturer partners that provide authenticated chains of title.
  • Centralized Asset Tracking: Maintain an automated Configuration Management Database (CMDB) recording serial numbers, MAC addresses, physical locations, and assigned employee custodians.
  • Certified Media Sanitization: Mandate NIST SP 800-88 compliant cryptographic wiping or physical degaussing for all decommissioned storage devices, backed by tamper-evident destruction certificates.
  • Endpoint Security and Remote Tracking: Deploy mobile device management solutions configured for automatic geofencing, remote cryptographic lock, and device wipe capabilities.

If your organization requires a security audit of secondary market equipment, assistance with asset tracking investigations, or forensic evidence collection for stolen hardware recovery, contact our security audit team for specialized enterprise support.

Found this helpful?

Share this page with others