Hacking with computer systems, Data Alteration - Sec.66 (IT Act)

Section 66 of the IT Act (often explained as hacking) focuses on intentional acts that cause wrongful loss or damage by destroying, deleting, or altering data in a computer resource.

May 21, 2012

Section 66 of the Information Technology Act, 2000 is India's principal criminal provision penalizing computer hacking, unauthorized system access, and fraudulent data alteration. Anyone committing unauthorized acts under Section 43 with dishonest intent faces up to three years imprisonment or fines reaching five lakh rupees.

Understanding Section 66 and Its Connection to Section 43

Section 66 operates by converting the civil contraventions listed under Section 43 into cognizable criminal offences whenever dishonest or fraudulent intent is established. Section 43 outlines ten specific categories of unauthorized digital actions, including accessing computer systems without consent, downloading or copying proprietary data, introducing destructive computer contaminants, damaging hardware or software assets, disrupting network availability, denying authorized user access, and assisting unauthorized entry. While Section 43 provides a civil adjudication pathway for financial compensation before the State Adjudicating Officer, Section 66 triggers criminal prosecution through police investigation and formal trial before a Judicial Magistrate.

The statutory threshold for criminal culpability under Section 66 requires strict proof of mens rea. Under Indian criminal jurisprudence, an act is performed dishonestly when it is executed with the intention of causing wrongful gain to one party or wrongful loss to another. An act is done fraudulently when it involves deliberate deceit coupled with injury or economic harm. Consequently, accidental data entry errors, unintentional system crashes, or standard administrative oversights do not constitute criminal offences under Section 66. The prosecution bears the burden of proving deliberate malicious intent through technical telemetry and documentary records.

Specific Categories of Data Alteration and Hacking Offences

Modern cyber incidents prosecuted under Section 66 span diverse operational environments. In enterprise and commercial ecosystems, the statute covers several common attack vectors:

  • Database Modification and Record Manipulation: Altering customer balances, modifying enterprise resource planning (ERP) records, or deleting transactional entries to obscure financial misappropriation.
  • System Configuration and Security Policy Tampering: Altering firewall rules, disabling endpoint detection agents, or weakening password complexity requirements to establish persistent unauthorized access.
  • Event Log Deletion and Audit Trail Tampering: Clearing Windows security event logs, truncating Linux authentication journals, or disabling cloud logging services to hide forensic footprints.
  • Malware and Ransomware Deployment: Injecting cryptographic ransomware that locks enterprise volumes or deploying backdoors that transmit intellectual property to external command-and-control servers.
  • Unauthorized Source Code Modification: Altering software repositories, injecting malicious dependencies into build pipelines, or modifying payment gateway integration endpoints.

Courts evaluate whether the action diminished the utility, value, or integrity of the targeted computer resource. Even temporary disruptions that interrupt normal business operations satisfy the criteria for system damage under Indian law. When malicious actors modify file permissions or alter routing tables, the resulting downtime creates actionable civil damage and criminal liability.

Penalties, Cognizance, and Judicial Proceedings Under Indian Law

A conviction under Section 66 carries imprisonment for a term extending up to three years, a fine up to five lakh rupees, or both. Offences under this section are classified as cognizable and bailable, tried before a Judicial Magistrate of the First Class. The formal criminal process commences with filing a detailed complaint or First Information Report (FIR) at the specialized Cyber Crime Police Station having territorial jurisdiction.

Establishing territorial jurisdiction in cyber crime disputes often presents complex procedural questions because attacks frequently originate from remote cloud servers, distributed botnets, or cross-border infrastructure. Indian courts recognize jurisdiction based on the physical location of the affected server, the corporate registered office where the financial injury occurred, or the physical location of the victim. Understanding how Section 66 interacts with broader statutory provisions is critical for organizations navigating cyber law in India.

During trial proceedings, defense counsel often scrutinizes whether the investigating officer possessed the statutory rank mandated by Section 78 of the IT Act, which requires investigations to be conducted by an officer not below the rank of Inspector. Demonstrating procedural compliance during search, seizure, and device imaging is mandatory for the prosecution to maintain the integrity of its case.

Digital Forensics and Evidentiary Standards Under Section 65B

Securing a conviction or mounting a credible defense in Section 66 litigation depends directly on the integrity of digital evidence. Indian courts apply strict admissibility standards to electronic records under Section 65B of the Indian Evidence Act (and Section 63 of the Bharatiya Sakshya Adhiniyam). Informal email printouts or unverified screenshots are routinely rejected during trial if chain of custody is broken.

A legally defensible digital investigation requires capturing and verifying primary technical artifacts:

  • Authentication and Access Logs: Centralized active directory records, virtual private network (VPN) session logs, multi-factor authentication tokens, and dynamic host configuration protocol (DHCP) lease allocations.
  • Forensic Disk and Memory Images: Bit-stream disk images of compromised endpoints created with write-blocking hardware, accompanied by volatile RAM dumps captured before system shutdown.
  • File System Timelines: Master File Table ($MFT) analysis, $LogFile entries, shellbags, and operating system registry modifications demonstrating precise user actions.
  • Network Traffic Capture: Lawfully collected network monitoring records captured through statutory frameworks, including traffic data monitoring under Section 69B.

Enterprise Incident Response and Preventative Security Protocols

When an enterprise discovers an unauthorized intrusion or data alteration event, immediate response decisions determine whether the organization successfully mitigates operational loss or invalidates critical legal evidence. Rushing to format machines or restore backups without capturing volatile system state destroys essential forensic proofs needed for criminal prosecution.

Organizations must establish a disciplined incident response framework that segregates affected network segments, preserves cryptographic hash values (SHA-256) of affected volumes, and maintains contemporaneous response logs. Conducting periodic penetration testing and implementing defensive configurations through application security assessments prevents unauthorized privilege escalation across enterprise assets.

Corporate IT teams should maintain segregated, immutable backup repositories and enforce strict role-based access control (RBAC) across all database clusters. Establishing file integrity monitoring (FIM) allows administrators to detect unauthorized file alterations in real time, stopping intruders before data alteration results in catastrophic operational interruption.

If your enterprise is responding to an active computer breach, unauthorized data modification, or requires expert forensic preservation for law enforcement proceedings, contact our cyber response team for professional technical triage and legal support.

Found this helpful?

Share this page with others