Cyber terrorism (S.66F IT Act) is the use of computer resources with intent to threaten the unity, integrity, security, or sovereignty of India, or to strike terror, by causing death, injuries, property damage, or disruption of critical services. International cyber crimes are offences with cross-border elements, requiring multilateral cooperation for investigation and prosecution.
Legal Framework
| Provision | Subject |
|---|---|
| IT Act S.66F | Cyber terrorism (life imprisonment) |
| IT Act S.70 | Protected systems (Critical Information Infrastructure): 10 years |
| IT Act S.70B | CERT-In: nodal agency for cyber security incidents |
| IT Act S.75 | Extra-territorial jurisdiction |
| BNS S.111 | Terrorist act (includes electronic means) |
| BNS S.113 | Punishment for terrorist act (death, life, or not less than 5 years) |
| UAPA 1967 (amended 2004) | Unlawful activities with electronic dimension |
| Budapest Convention (2001) | International framework for cybercrime cooperation (India not signatory) |
| INTERPOL Cybercrime Programme | International police cooperation on cyber offences |
Section 66F: Cyber Terrorism
Elements
| Element | Description |
|---|---|
| Intent | Threaten unity, integrity, security, sovereignty of India OR strike terror |
| Act (S.66F(1)(A)) | Denial of access + penetration of unauthorized computer resource + introduction of contaminant |
| Consequence | Death, injuries, damage to/destruction of property, disruption of essential services, contamination of critical infrastructure |
| OR: Act (S.66F(1)(B)) | Knowingly accessing computer resource without authorization + obtaining restricted information, data, or database |
| For S.66F(1)(B) | Information which is restricted for reasons of sovereignty, security, defence, foreign relations |
Punishment: Life imprisonment.
Why: A cyber attack on power grids, defence networks, financial systems, or transportation infrastructure can cause catastrophic harm equivalent to conventional terrorism. The life imprisonment penalty reflects this existential threat level.
Critical Information Infrastructure (S.70)
Defined as computer resources whose incapacitation or destruction would have debilitating impact on:
- National security
- Economy
- Public health
- Public safety
Examples: Power grids, defence systems, banking networks, telecommunications, air traffic control, nuclear facilities.
National Critical Information Infrastructure Protection Centre (NCIIPC) is the designated authority for CII protection under S.70A.
International Cyber Crimes
Classification
| Type | Description | Example |
|---|---|---|
| State-sponsored attacks | Government-backed hacking of other nations | Stuxnet (US/Israel vs. Iran), SolarWinds |
| Transnational organized crime | Criminal networks operating across borders | Ransomware gangs, dark web marketplaces |
| Hacktivism | Politically motivated hacking | Anonymous collective attacks |
| Espionage | Theft of classified/trade secret information | Nation-state APT groups |
| Cyber warfare | Digital attacks as acts of war | Infrastructure attacks between states |
International Legal Framework
| Instrument | Scope | India's Position |
|---|---|---|
| Budapest Convention (2001) | Comprehensive cybercrime treaty (substantive + procedural + cooperation) | Not signatory (sovereignty concerns over Art.32b) |
| UN GGE Reports | Norms of responsible state behavior in cyberspace | Active participant |
| Paris Call for Trust and Security (2018) | Multi-stakeholder commitment to stable cyberspace | Signatory |
| Shanghai Cooperation Organization (SCO) Agreement | Regional cooperation on information security | Member |
| Bilateral MLATs | Mutual Legal Assistance Treaties | Operational with US, UK, EU states |
| INTERPOL Cybercrime Directorate | International police cooperation, training, databases | Active member |
India's Cooperation Mechanisms
| Mechanism | Function |
|---|---|
| MLATs | Bilateral treaties for evidence sharing, extradition |
| Letters Rogatory | Formal court-to-court request for evidence from foreign jurisdiction |
| INTERPOL I-24/7 Network | Secure communication channel for real-time intelligence sharing |
| CERT-In partnerships | Information sharing with foreign CERTs |
| I4C (Indian Cyber Crime Coordination Centre) | Domestic coordination + international liaison |
| Cyber Diplomacy Division (MEA) | Diplomatic negotiations on cyber norms |
Recall Check
- What are the two alternative acts under S.66F(1)(A) and S.66F(1)(B)?
- Why has India not signed the Budapest Convention?
- What is Critical Information Infrastructure and who protects it?
Key Cases
Mehdi Masroor Biswas Case (2014) Mehdi-Masroor-Biswas-Case-2014 Issue: Whether operating a pro-ISIS Twitter account (@ShamiWitness) from India, disseminating propaganda and recruiting, constitutes support for terrorism through electronic means. Rule: Using electronic communication to support, facilitate, or recruit for terrorism constitutes offence under UAPA and IT Act provisions; online radicalization is prosecutable. Held: Accused arrested in Bangalore for running a pro-ISIS social media account with 17,000+ followers. Charged under UAPA (support to terrorist organization) and IT Act provisions. Case highlighted the nexus between social media and terrorism.
Ajay Bharadwaj v. State (2018) Ajay-Bharadwaj-v-State-2018 Issue: Whether accessing restricted government databases without authorization and sharing sensitive defence data with foreign entities constitutes cyber espionage/terrorism. Rule: Unauthorized access to restricted information concerning sovereignty or security, when knowingly shared with foreign entities, may attract S.66F(1)(B) (cyber terrorism) and Official Secrets Act. Held: Accused charged under S.66F IT Act for accessing restricted defence databases and sharing information. Illustrates the application of S.66F(1)(B) to espionage-type offences.
Distinctions
| Aspect | Cyber Terrorism (S.66F) | Regular Hacking (S.66) |
|---|---|---|
| Intent | Threaten national security, sovereignty, strike terror | Dishonest/fraudulent purpose (personal gain) |
| Target | Critical infrastructure, restricted systems | Any computer system |
| Consequence required | Death, injuries, property damage, disruption of services | Damage to computer/data (any level) |
| Punishment | Life imprisonment | 3 years + Rs.5 lakhs |
| Investigation | NIA or CBI (typically) | State cyber cell |
| Bail | Non-bailable | Bailable |
| Overlap with | BNS S.111-113 (terrorist act), UAPA | BNS S.303 (theft), S.318 (cheating) |
| International dimension | Almost always cross-border | May or may not be cross-border |
Flashcards
Q: What is the punishment for cyber terrorism under S.66F? A: Life imprisonment.
Q: What are the two alternative limbs of S.66F? A: S.66F(1)(A): Acts causing death/injury/disruption/damage with intent to threaten security. S.66F(1)(B): Knowingly accessing restricted information related to sovereignty/security without authorization.
Q: What is Critical Information Infrastructure? A: Computer resources whose incapacitation or destruction would have debilitating impact on national security, economy, public health, or public safety (S.70 IT Act).
Q: Who is the designated authority for CII protection? A: NCIIPC (National Critical Information Infrastructure Protection Centre) under S.70A IT Act.
Q: Why has India not signed the Budapest Convention? A: Concerns over Art.32(b) which permits cross-border access to stored computer data without consent of the territorial state; sovereignty implications.
Q: What is the role of I4C? A: Indian Cyber Crime Coordination Centre (MHA, 2020): coordinates inter-state and international law enforcement response to cybercrime; provides analytics, capacity building, and the National Cyber Crime Reporting Portal.
Q: What was the Mehdi Masroor Biswas case about? A: Operating a pro-ISIS Twitter account from India for propaganda and recruitment; charged under UAPA and IT Act for online radicalization and support to terrorism.
Q: What cooperation mechanisms exist for India in absence of Budapest Convention membership? A: Bilateral MLATs, Letters Rogatory, INTERPOL I-24/7 Network, CERT-In partnerships with foreign CERTs, SCO agreement, Paris Call membership.
Exam Scenario
Hackers from an unknown foreign state breach the control systems of India's power grid, causing a blackout in three northern states lasting 48 hours. Hospitals lose power, resulting in 15 deaths. No group claims responsibility. Advise on the legal framework for prosecution and international cooperation.
Offences: (1) S.66F IT Act (cyber terrorism): Intent to threaten sovereignty + denial of access to critical infrastructure + causing death = life imprisonment. (2) S.70 IT Act: Unauthorized access to protected system (power grid declared CII) = 10 years. (3) BNS S.111-113: Terrorist act causing death (punishment: death or life imprisonment). (4) BNS S.103: Murder if deaths were caused with knowledge that act would likely cause death. Investigation: NIA has jurisdiction for terrorism-related offences. NCIIPC coordinates CII response. CERT-In coordinates technical incident response and forensics. International cooperation: Without identifying the state actor, India can: (1) invoke bilateral MLATs with suspected countries, (2) seek INTERPOL assistance, (3) raise the issue at UN GGE/OEWG as violation of international norms on responsible state behavior, (4) attribute the attack through technical forensics (CERT-In + NCIIPC + private sector), (5) consider proportionate response under international law (right of self-defence if attributable to state). Domestically: prosecution of any identified Indian collaborators; S.75 IT Act applies regardless of perpetrator's nationality.