Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Crimes and Investigation Procedures

Cyber Crimes: Meaning, Types and Classification

Updated 11 October 2026 · Fact-checked

A cyber crime is an unlawful act in which a computer, network or device is the tool, the target or both. You classify it by victim: against persons, property, government and society. To solve a question, identify the act, name its category, link the relevant provision, and conclude.

Understand Cyber Crimes: Meaning, Types and Classification

A cyber crime is a crime committed using a computer, a computer network or a digital device. The device can be the tool (phishing emails sent to cheat people), the target (hacking into a server), or both (ransomware that locks a company's systems). The Information Technology Act, 2000 does not give one single definition of cyber crime. It lists specific offences and penalties, and the Bharatiya Nagarik Suraksha Sanhita, 2023 supplies the procedure for charge, investigation and forfeiture.

The usual way to classify cyber crimes is by who suffers:

  • Against persons: cyber stalking, harassment, identity theft, defamation, circulation of obscene content.
  • Against property: hacking for gain, data theft, ransomware, online fraud, phishing for money, damage to computer systems.
  • Against government: cyber terrorism, attacks on critical information infrastructure, unauthorised access to restricted state information.
  • Against society: offences that harm public order or morals, such as trafficking in illegal content or large-scale online fraud schemes.

This is a teaching classification, not a statutory one. One act can fall into more than one category. Identity theft harms a person, but if it is used to empty a bank account it is also a property offence. Always say so in your answer.

Common forms you must be able to define: hacking is gaining access to a computer resource without authorisation. Phishing is tricking a person by a fake message or site into revealing passwords, card numbers or OTPs. Ransomware is malicious software that blocks access to data until money is paid. Identity theft is fraudulent or dishonest use of another person's electronic signature, password or other unique identification feature. Cyber stalking is repeated online following, monitoring or harassment of a person.

From the supplied text, three statutory anchors are useful. Section 66C of the IT Act punishes identity theft with imprisonment of either description up to three years and fine up to ₹1 lakh. Section 66F punishes cyber terrorism, up to imprisonment for life. Section 43A makes a body corporate liable to pay compensation where it is negligent in keeping reasonable security practices for sensitive personal data and thereby causes wrongful loss or wrongful gain to any person.

The difference between hacking and phishing is the method. Hacking attacks the system by getting unauthorised access. Phishing attacks the person by deception, and the victim hands over the credentials. A phishing attack is often the first step to hacking or identity theft.

Key rules to remember

Classification by victim
Cyber crime → against persons | property | government | society
A teaching classification, not a statutory one. One act may fit more than one category.
Role of the computer
Computer as tool | target | both
Use this to explain why an act is a cyber crime.
Identity theft (Section 66C, IT Act)
Fraudulent or dishonest use of another's electronic signature, password or unique identification feature → imprisonment up to 3 years + fine up to ₹1 lakh
Imprisonment is of either description. The offender is also liable to fine.
Cyber terrorism (Section 66F, IT Act)
Intent to threaten unity, integrity, security or sovereignty of India or to strike terror + prescribed conduct → imprisonment up to life
Covers denying access, unauthorised access and introducing a computer contaminant, with the stated consequences. It also covers unauthorised access to restricted information (clause B).
Failure to protect data (Section 43A, IT Act)
Body corporate + sensitive personal data + negligent security practices + wrongful loss or gain → compensation to the affected person
This is a civil liability to pay damages by way of compensation, not an imprisonment provision.

How to solve Cyber Crimes: Meaning, Types and Classification questions

Use the same sequence for any question on meaning, types or classification of cyber crimes.

  1. 1Read the facts and underline the act done (for example, fake email, locked files, repeated messages).
  2. 2State the meaning of cyber crime and say whether the computer is the tool, the target or both.
  3. 3Name the specific form: hacking, phishing, ransomware, identity theft, cyber stalking or another.
  4. 4Place it in a category by victim: person, property, government or society. Note any overlap.
  5. 5Link the provision where you are sure of it, such as Section 66C for identity theft, Section 66F for cyber terrorism or Section 43A for data protection failure.
  6. 6Add the practical point: preserve evidence, report to police or the cyber crime portal, and note a company's compliance duty.
  7. 7Conclude in one line that answers the exact question asked.

Quickest way: Act, form, victim, provision

When to use it: Use this when you have under ten minutes for a short note or a small fact-based question.

  1. Act: write what was done in one line.
  2. Form: give the technical name and a one-line definition.
  3. Victim: choose the category and mention overlap.
  4. Provision: cite only sections you are certain of.
  5. Close with one practical compliance or reporting point.

Common mistakes in Cyber Crimes: Meaning, Types and Classification

  • Treating the four-way classification as the statutory classification in the IT Act.

    Notes present it as a neat list, so it looks like law.

    Fix: Say it is a classification for study. The IT Act lists individual offences and penalties.

  • Using hacking and phishing as the same thing.

    Both end in unauthorised access to accounts.

    Fix: Hacking attacks the system. Phishing deceives the person into giving credentials. Mention the link between them.

  • Putting each crime in only one category.

    Students memorise one example per category.

    Fix: State the main category and note the overlap, for example identity theft used for fraud also harms property.

  • Stating Section 43A as a criminal penalty.

    Students link every section with jail or fine.

    Fix: Section 43A makes a body corporate liable to pay compensation for negligence in protecting sensitive personal data. It needs wrongful loss or gain.

  • Quoting section numbers or punishments from memory without certainty.

    Students try to look thorough.

    Fix: Cite only sections you know, such as 66C and 66F, with their correct punishments. Otherwise describe the rule in words.

  • Ending with the definition and no application to the facts.

    Students treat it as a theory question.

    Fix: Paper is case-based. Finish with analysis of the facts and a clear conclusion.

Worked examples

Example 1

Meera, an accountant at an Indian company, receives an email that looks like it is from her bank. She clicks the link and enters her net banking password. Later ₹2,40,000 is transferred from her account by someone using her credentials. Identify the cyber crimes, classify them and state the relevant provision.

Show the solution
  1. Act: a deceptive email led Meera to disclose her password. This is phishing, a computer-based deception where the device is the tool.
  2. The fraudster then used her password without her consent. This is identity theft, as it is fraudulent or dishonest use of another person's password.
  3. Provision: Section 66C of the IT Act punishes this with imprisonment of either description up to three years and fine up to ₹1 lakh.
  4. Classification: it is against a person, because her identity and credentials were misused. It is also against property, because ₹2,40,000 was taken.
  5. Practical point: Meera should report promptly to the bank and the police, and preserve the email and transaction records as evidence.

Answer: The facts show phishing followed by identity theft. The offence falls under Section 66C of the IT Act and is classified mainly as a crime against a person, with an overlap into crimes against property.

Example 2

Distinguish between hacking and ransomware attack with one example each, and say how a company holding customers' sensitive data may be exposed after such an attack.

Show the solution
  1. Hacking is access to a computer resource without authorisation. Example: an outsider breaks into an HR server and reads employee records.
  2. Ransomware is malicious software that blocks access to data or systems until a payment is made. Example: a manufacturer's files are encrypted and a payment is demanded to restore them.
  3. Difference: hacking is about unauthorised access. Ransomware is about locking data to extort money. Ransomware may be delivered after access is obtained.
  4. Both are mainly crimes against property, and they may overlap with persons where personal data is exposed.
  5. Company exposure: Section 43A applies to a body corporate that handles sensitive personal data in a computer resource it owns, controls or operates. If it was negligent in maintaining reasonable security practices and thereby caused wrongful loss or wrongful gain to any person, it is liable to pay compensation to the affected person.
  6. Reasonable security practices means those specified in an agreement or any law, or, failing both, those prescribed by the Central Government.

Answer: Hacking is unauthorised access, while ransomware locks data to demand payment. A company that negligently failed to keep reasonable security practices for sensitive personal data, and thereby caused wrongful loss or gain, must pay compensation under Section 43A.

Exam tips

  • Begin every answer with a one-line definition and the role of the computer: tool, target or both.
  • Give a short Indian example for each form you name. Examiners reward application to facts.
  • Cite Sections 66C, 66F and 43A only with their correct content. Do not guess other numbers.
  • Use the person, property, government, society headings in a note, and mention overlap in one sentence.
  • Finish case answers with a practical step: preserve evidence, report, and review compliance.

Practice questions from Cyber Crimes and Investigation Procedures

Cyber Crimes: Meaning, Types and Classification in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Crimes: Meaning, Types and Classification: frequently asked questions

What is the meaning of cyber crime for CS Professional?

A cyber crime is an unlawful act where a computer, network or digital device is used as a tool, a target or both. The IT Act, 2000 lists specific offences and penalties instead of one general definition. Write the meaning and then name the specific offence.

How are cyber crimes classified?

The common classification is by victim: against persons, property, government and society. It is a study classification, not a statutory one. Mention that one act can fit more than one category.

What is the difference between hacking and phishing?

Hacking is gaining unauthorised access to a computer resource. Phishing deceives a person into giving passwords or card details through a fake message or site. Phishing often leads to hacking or identity theft.

What is the punishment for identity theft under the IT Act?

Section 66C provides imprisonment of either description up to three years and a fine up to ₹1 lakh. The offence is fraudulent or dishonest use of another person's electronic signature, password or other unique identification feature.