Identity theft - Sec.66C

Section 66C of the IT Act makes identity theft a punishable offence. Learn how the law defines fraudulent use of passwords and digital signatures, and what steps you can take to protect your brand and personal data.

May 21, 2012

Section 66C of the Information Technology Act, 2000 criminalizes digital identity theft across India. Any person who fraudulently uses another individual's electronic signature, password, or unique identification feature faces up to three years imprisonment and a mandatory fine reaching one lakh rupees.

Defining Identity Theft Under Indian Cyber Legislation

Section 66C was enacted to address the expanding scope of digital impersonation, credential harvesting, and unauthorized authentication. Unlike traditional theft, which involves moving physical property without consent, digital identity theft targets the digital identifiers used to establish legal, financial, or administrative authorization. The law covers a wide spectrum of authentication artifacts, establishing a clear statutory boundary between legitimate delegated access and fraudulent credential misappropriation.

The statutory language recognizes several distinct categories of unique identification features:

  • Electronic and Digital Signatures: Public key cryptography certificates, private keys, USB cryptographic tokens, and Aadhaar-based electronic signing credentials.
  • Access Passwords and Personal Identification Numbers (PINs): Alphanumeric passwords, banking PINs, and single-use verification tokens used to access digital accounts.
  • Biometric Identifiers: Digital templates of fingerprints, facial geometry scans, retinal patterns, and voice authentication models.
  • Unique Technical Identifiers: Hardware MAC addresses, device tokens, cryptographic session keys, and digital certificates tied to specific individuals or enterprise roles.

This statutory protection complements broader property provisions, distinguishing digital credential misuse from general punishment for digital theft offences. When bad actors misappropriate administrative credentials to siphon funds or manipulate corporate filings, Section 66C provides targeted criminal penalties.

Common Attack Methodologies and Exploitation Vectors

Identity theft rarely occurs in isolation; it serves as the foundational phase for extensive corporate fraud, unauthorized fund transfers, and industrial espionage. Cybercriminals deploy diverse technical and psychological tactics to compromise personal identifiers:

  • Credential Stuffing and Automated Brute Force: Utilizing compromised password databases from third-party breaches to access corporate portals where users reused login credentials.
  • SIM Swapping: Deceiving telecommunications providers into reissuing an active phone number to hijack SMS-based verification codes and two-factor tokens.
  • Keylogging and Infostealer Malware: Deploying background utilities that capture keystrokes, browser autofill records, and active session cookies.
  • Phishing and Social Engineering: Creating high-fidelity spoofed login portals that harvest administrative usernames and passwords directly from corporate employees.
  • Session Hijacking: Stealing active authentication tokens from web browsers to bypass multi-factor authentication without knowing the user's password.

Legal Framework and Courtroom Proof Standards

Prosecuting an offence under Section 66C requires demonstrating fraudulent or dishonest intent along with technical attribution linking the stolen credentials to the accused. Courts demand clear evidentiary proof demonstrating that the victim did not willingly share the credentials, or that authorization was exceeded for illicit gain.

Investigating officers rely on digital forensic reports detailing server access timestamps, source IP addresses, geo-location telemetry, and endpoint logs. Navigating these evidentiary requirements demands thorough knowledge of the procedural rules governed by cyber law in India.

In cases involving digital signatures, forensic experts verify certificate authority revocation lists, timestamping servers, and private key storage tokens to establish whether the authentic owner maintained physical control over the signing device at the moment of execution.

Legal Recourse and Adjudication Pathways Under the IT Act

Victims of identity theft can initiate civil compensation claims under Section 43 alongside criminal prosecution under Section 66C. The Adjudicating Officer appointed under Section 46 of the Information Technology Act possesses powers equivalent to a civil court to award financial damages up to five crore rupees against unauthorized access and credential misuse. Seeking financial restitution before the Adjudicating Officer while concurrently pursuing criminal charges before the Judicial Magistrate ensures a multi-pronged legal strategy that addresses both personal financial loss and statutory punishment for the offender.

Regulatory Reporting Obligations and Consumer Protection

In addition to penal consequences under Section 66C, enterprises that experience credential compromises face strict mandatory reporting requirements. Under the CERT-In cybersecurity directions of April 2022, organizations must report unauthorized access to IT systems, identity compromises, and data breach incidents within six hours of identification.

Furthermore, under the Digital Personal Data Protection Act, 2023 (DPDPA), data fiduciaries are legally obligated to notify both the Data Protection Board of India and affected data principals when personal identifiers or authentication credentials are breached. Establishing proactive credential monitoring mechanisms and maintaining rapid incident notification workflows ensures regulatory compliance while minimizing civil liability and customer churn.

Corporate Prevention Controls and Technical Hardening

Protecting corporate credentials requires moving beyond static password policies toward adaptive, zero-trust security architectures. Passwords alone represent an inadequate security barrier against modern automated credential harvesting.

Organizations should enforce multi-layered defensive controls across all environments:

  • Phishing-Resistant Authentication: Transition from SMS OTPs to hardware security keys and FIDO2-compliant multi-factor authentication protocols.
  • Privileged Access Management (PAM): Implement strict session recording, just-in-time privilege elevation, and automated credential rotation for administrative accounts.
  • Vulnerability Assessments: Subject authentication endpoints, APIs, and single sign-on gateways to routine penetration testing to identify security flaws before adversaries exploit them.
  • Dark Web Exposure Tracking: Maintain continuous brand monitoring to detect compromised corporate credentials circulating on illicit forums.

Immediate Containment and Incident Remediation Workflow

When an individual or enterprise suspects that identity credentials have been compromised, swift containment minimizes operational and legal damage. Affected parties must immediately revoke active digital certificates, invalidate all active session tokens, and trigger enterprise-wide password resets. Forensic snapshots of authentication databases should be preserved to establish the timeline of unauthorized actions.

Engaging experienced reputation management experts helps contain collateral damage when compromised executive credentials are used to distribute misleading statements or commit public fraud.

If your organization is managing an identity theft crisis, unauthorized credential compromise, or requires legal and forensic support, contact our cyber response team for professional guidance.

Found this helpful?

Share this page with others