Information Technology Law
Subjects / Information Technology Law / Cyber Terrorism and International Cyber Crimes
Unit 5 · Unit 5

Cyber Terrorism and International Cyber Crimes

Cyber terrorism (S.66F IT Act) is the use of computer resources with intent to threaten the unity, integrity, security, or sovereignty of India, or

Cyber terrorism (S.66F IT Act) is the use of computer resources with intent to threaten the unity, integrity, security, or sovereignty of India, or to strike terror, by causing death, injuries, property damage, or disruption of critical services. International cyber crimes are offences with cross-border elements, requiring multilateral cooperation for investigation and prosecution.

Legal Framework

Provision Subject
IT Act S.66F Cyber terrorism (life imprisonment)
IT Act S.70 Protected systems (Critical Information Infrastructure): 10 years
IT Act S.70B CERT-In: nodal agency for cyber security incidents
IT Act S.75 Extra-territorial jurisdiction
BNS S.111 Terrorist act (includes electronic means)
BNS S.113 Punishment for terrorist act (death, life, or not less than 5 years)
UAPA 1967 (amended 2004) Unlawful activities with electronic dimension
Budapest Convention (2001) International framework for cybercrime cooperation (India not signatory)
INTERPOL Cybercrime Programme International police cooperation on cyber offences

Section 66F: Cyber Terrorism

Elements

Element Description
Intent Threaten unity, integrity, security, sovereignty of India OR strike terror
Act (S.66F(1)(A)) Denial of access + penetration of unauthorized computer resource + introduction of contaminant
Consequence Death, injuries, damage to/destruction of property, disruption of essential services, contamination of critical infrastructure
OR: Act (S.66F(1)(B)) Knowingly accessing computer resource without authorization + obtaining restricted information, data, or database
For S.66F(1)(B) Information which is restricted for reasons of sovereignty, security, defence, foreign relations

Punishment: Life imprisonment.

Why: A cyber attack on power grids, defence networks, financial systems, or transportation infrastructure can cause catastrophic harm equivalent to conventional terrorism. The life imprisonment penalty reflects this existential threat level.

Critical Information Infrastructure (S.70)

Defined as computer resources whose incapacitation or destruction would have debilitating impact on:

  • National security
  • Economy
  • Public health
  • Public safety

Examples: Power grids, defence systems, banking networks, telecommunications, air traffic control, nuclear facilities.

National Critical Information Infrastructure Protection Centre (NCIIPC) is the designated authority for CII protection under S.70A.

International Cyber Crimes

Classification

Type Description Example
State-sponsored attacks Government-backed hacking of other nations Stuxnet (US/Israel vs. Iran), SolarWinds
Transnational organized crime Criminal networks operating across borders Ransomware gangs, dark web marketplaces
Hacktivism Politically motivated hacking Anonymous collective attacks
Espionage Theft of classified/trade secret information Nation-state APT groups
Cyber warfare Digital attacks as acts of war Infrastructure attacks between states

International Legal Framework

Instrument Scope India's Position
Budapest Convention (2001) Comprehensive cybercrime treaty (substantive + procedural + cooperation) Not signatory (sovereignty concerns over Art.32b)
UN GGE Reports Norms of responsible state behavior in cyberspace Active participant
Paris Call for Trust and Security (2018) Multi-stakeholder commitment to stable cyberspace Signatory
Shanghai Cooperation Organization (SCO) Agreement Regional cooperation on information security Member
Bilateral MLATs Mutual Legal Assistance Treaties Operational with US, UK, EU states
INTERPOL Cybercrime Directorate International police cooperation, training, databases Active member

India's Cooperation Mechanisms

Mechanism Function
MLATs Bilateral treaties for evidence sharing, extradition
Letters Rogatory Formal court-to-court request for evidence from foreign jurisdiction
INTERPOL I-24/7 Network Secure communication channel for real-time intelligence sharing
CERT-In partnerships Information sharing with foreign CERTs
I4C (Indian Cyber Crime Coordination Centre) Domestic coordination + international liaison
Cyber Diplomacy Division (MEA) Diplomatic negotiations on cyber norms

Recall Check

  1. What are the two alternative acts under S.66F(1)(A) and S.66F(1)(B)?
  2. Why has India not signed the Budapest Convention?
  3. What is Critical Information Infrastructure and who protects it?

Key Cases

Mehdi Masroor Biswas Case (2014) Mehdi-Masroor-Biswas-Case-2014 Issue: Whether operating a pro-ISIS Twitter account (@ShamiWitness) from India, disseminating propaganda and recruiting, constitutes support for terrorism through electronic means. Rule: Using electronic communication to support, facilitate, or recruit for terrorism constitutes offence under UAPA and IT Act provisions; online radicalization is prosecutable. Held: Accused arrested in Bangalore for running a pro-ISIS social media account with 17,000+ followers. Charged under UAPA (support to terrorist organization) and IT Act provisions. Case highlighted the nexus between social media and terrorism.

Ajay Bharadwaj v. State (2018) Ajay-Bharadwaj-v-State-2018 Issue: Whether accessing restricted government databases without authorization and sharing sensitive defence data with foreign entities constitutes cyber espionage/terrorism. Rule: Unauthorized access to restricted information concerning sovereignty or security, when knowingly shared with foreign entities, may attract S.66F(1)(B) (cyber terrorism) and Official Secrets Act. Held: Accused charged under S.66F IT Act for accessing restricted defence databases and sharing information. Illustrates the application of S.66F(1)(B) to espionage-type offences.

Distinctions

Aspect Cyber Terrorism (S.66F) Regular Hacking (S.66)
Intent Threaten national security, sovereignty, strike terror Dishonest/fraudulent purpose (personal gain)
Target Critical infrastructure, restricted systems Any computer system
Consequence required Death, injuries, property damage, disruption of services Damage to computer/data (any level)
Punishment Life imprisonment 3 years + Rs.5 lakhs
Investigation NIA or CBI (typically) State cyber cell
Bail Non-bailable Bailable
Overlap with BNS S.111-113 (terrorist act), UAPA BNS S.303 (theft), S.318 (cheating)
International dimension Almost always cross-border May or may not be cross-border

Flashcards

Q: What is the punishment for cyber terrorism under S.66F? A: Life imprisonment.

Q: What are the two alternative limbs of S.66F? A: S.66F(1)(A): Acts causing death/injury/disruption/damage with intent to threaten security. S.66F(1)(B): Knowingly accessing restricted information related to sovereignty/security without authorization.

Q: What is Critical Information Infrastructure? A: Computer resources whose incapacitation or destruction would have debilitating impact on national security, economy, public health, or public safety (S.70 IT Act).

Q: Who is the designated authority for CII protection? A: NCIIPC (National Critical Information Infrastructure Protection Centre) under S.70A IT Act.

Q: Why has India not signed the Budapest Convention? A: Concerns over Art.32(b) which permits cross-border access to stored computer data without consent of the territorial state; sovereignty implications.

Q: What is the role of I4C? A: Indian Cyber Crime Coordination Centre (MHA, 2020): coordinates inter-state and international law enforcement response to cybercrime; provides analytics, capacity building, and the National Cyber Crime Reporting Portal.

Q: What was the Mehdi Masroor Biswas case about? A: Operating a pro-ISIS Twitter account from India for propaganda and recruitment; charged under UAPA and IT Act for online radicalization and support to terrorism.

Q: What cooperation mechanisms exist for India in absence of Budapest Convention membership? A: Bilateral MLATs, Letters Rogatory, INTERPOL I-24/7 Network, CERT-In partnerships with foreign CERTs, SCO agreement, Paris Call membership.

Exam Scenario

Hackers from an unknown foreign state breach the control systems of India's power grid, causing a blackout in three northern states lasting 48 hours. Hospitals lose power, resulting in 15 deaths. No group claims responsibility. Advise on the legal framework for prosecution and international cooperation.

Offences: (1) S.66F IT Act (cyber terrorism): Intent to threaten sovereignty + denial of access to critical infrastructure + causing death = life imprisonment. (2) S.70 IT Act: Unauthorized access to protected system (power grid declared CII) = 10 years. (3) BNS S.111-113: Terrorist act causing death (punishment: death or life imprisonment). (4) BNS S.103: Murder if deaths were caused with knowledge that act would likely cause death. Investigation: NIA has jurisdiction for terrorism-related offences. NCIIPC coordinates CII response. CERT-In coordinates technical incident response and forensics. International cooperation: Without identifying the state actor, India can: (1) invoke bilateral MLATs with suspected countries, (2) seek INTERPOL assistance, (3) raise the issue at UN GGE/OEWG as violation of international norms on responsible state behavior, (4) attribute the attack through technical forensics (CERT-In + NCIIPC + private sector), (5) consider proportionate response under international law (right of self-defence if attributable to state). Domestically: prosecution of any identified Indian collaborators; S.75 IT Act applies regardless of perpetrator's nationality.