Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Threats and Cyber Laws

Cyber Terrorism under Section 66F of the IT Act

Updated 11 October 2026 · Fact-checked

Cyber terrorism is an offence under Section 66F of the Information Technology Act, 2000. It covers two things: cyber attacks done with intent to threaten India's unity, integrity, security or sovereignty or to strike terror, and unauthorised access to restricted State-security information. Punishment may extend to imprisonment for life.

Understand Cyber Terrorism under Section 66F

Most cyber crimes harm a person or a business. Cyber terrorism is different. It targets the nation or the people at large. Section 66F is the provision that deals with it.

The section has two limbs. Clause (A) is about attack with terror intent. Clause (B) is about access to restricted information. You must know which limb a fact pattern fits.

Under clause (A), the person acts with intent to threaten the unity, integrity, security or sovereignty of India, or to strike terror in the people or any section of them. The means are any one of three: (i) denying or causing denial of access to a person authorised to access a computer resource; (ii) attempting to penetrate or access a computer resource without authorisation or exceeding authorised access; (iii) introducing or causing to introduce any computer contaminant. The conduct must also cause or be likely to cause death or injury to persons, or damage to or destruction of property. Alternatively it disrupts, or knowingly is likely to disrupt, supplies or services essential to the life of the community, or adversely affects the critical information infrastructure specified under Section 70.

Under clause (B), the person knowingly or intentionally penetrates or accesses a computer resource without authorisation, or exceeding authorised access, and thereby obtains access to information, data or a database restricted for reasons of State security or foreign relations. Any other restricted information also counts. There must be reason to believe it may be used to cause or likely cause injury to the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, public order, decency or morality, contempt of court, defamation or incitement to an offence, or to the advantage of any foreign nation, group of individuals or otherwise.

Sub-section (2) punishes whoever commits or conspires to commit cyber terrorism with imprisonment which may extend to imprisonment for life. Note that conspiracy alone is enough. Critical information infrastructure is defined in Section 70 as a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety.

Key rules to remember

Clause (A): terror attack
Intent (threaten unity, integrity, security or sovereignty of India, or strike terror) + Means (denial of access / unauthorised access / computer contaminant) + Consequence (death, injury, damage to property, disruption of essential supplies or services, or harm to critical information infrastructure)
All three elements are needed. Intent is the key separator from ordinary hacking.
Clause (B): restricted information
Knowing or intentional unauthorised access (or exceeding authorisation) + access to information restricted for State security or foreign relations (or other restricted information) + reason to believe it may cause injury or benefit a foreign nation or group
No death, injury or damage is required here. The harm is in the likely use of the information.
Punishment, Section 66F(2)
Commits or conspires to commit cyber terrorism: imprisonment which may extend to imprisonment for life
The text prescribes no fine and no minimum term. Conspiracy is punished the same as commission.
Critical information infrastructure (Section 70 Explanation)
Computer resource whose incapacitation or destruction has a debilitating impact on national security, economy, public health or safety
Harm to it satisfies the consequence limb of clause (A).

How to solve Cyber Terrorism under Section 66F questions

Use this provision, analysis and conclusion method for any fact-based question on Section 66F.

  1. 1Identify who did what to which computer resource, and whether the person was authorised.
  2. 2State the provision: Section 66F defines cyber terrorism in clauses (A) and (B) and punishes it in sub-section (2).
  3. 3Test intent. Was there intent to threaten India's unity, integrity, security or sovereignty, or to strike terror? If none, clause (A) fails.
  4. 4Match the means: denial of access, unauthorised or excess access, or a computer contaminant.
  5. 5Match the consequence: death, injury, property damage, disruption of essential supplies or services, or harm to critical information infrastructure under Section 70.
  6. 6If the facts involve restricted State-security or foreign-relations data, test clause (B) instead: unauthorised access plus reason to believe the data may cause injury or help a foreign nation.
  7. 7Conclude: offence made out or not, and state the punishment, imprisonment which may extend to life, including for conspiracy.
  8. 8Add related provisions where relevant, for example Section 70 for protected systems or Section 69B for monitoring.

Quickest way: Intent-Means-Impact check

When to use it: Use for short-note and 'is this cyber terrorism' questions when time is tight.

  1. Ask first: is there terror or anti-national intent? No intent means not 66F(1)(A).
  2. Name the means in one line: denial, unauthorised access, or contaminant.
  3. Name the impact in one line: life, property, essential services, or critical information infrastructure.
  4. If it is about secret government data, switch to clause (B) and check reason to believe harm.
  5. Close with the punishment: imprisonment which may extend to life, covering conspiracy.

Common mistakes in Cyber Terrorism under Section 66F

  • Treating every hacking or malware case as cyber terrorism.

    Students focus on the means and forget the intent requirement.

    Fix: Always check for intent to threaten India's unity, integrity, security or sovereignty or to strike terror, plus the stated consequence.

  • Saying a fine is also payable under Section 66F.

    Many other IT Act offences carry imprisonment and fine, so students assume the same here.

    Fix: Write only: imprisonment which may extend to imprisonment for life. The text of 66F(2) mentions no fine.

  • Requiring death or damage for clause (B).

    Students carry the consequence limb of clause (A) into clause (B).

    Fix: Clause (B) needs unauthorised access to restricted information and reason to believe it may be misused. Actual damage is not an element.

  • Forgetting conspiracy.

    Students read the section as covering only completed acts.

    Fix: Sub-section (2) punishes whoever commits or conspires to commit cyber terrorism.

  • Missing the link to Section 70.

    Students learn 66F and 70 as separate topics.

    Fix: Remember that adverse effect on critical information infrastructure specified under Section 70 is one consequence under clause (A).

  • Quoting a minimum sentence.

    Students confuse 'may extend to' with a fixed term.

    Fix: The section gives only a maximum, which is life imprisonment.

Worked examples

Example 1

A group of persons, intending to strike terror in the public, introduces a computer contaminant into the system that controls the power supply of a city. Power to hospitals fails and supply is disrupted. Examine liability under the IT Act, 2000.

Show the solution
  1. Provision: Section 66F(1)(A) covers acts with intent to threaten India's security or strike terror in the people by introducing a computer contaminant.
  2. Intent: the group intended to strike terror in the public, so the intent limb is met.
  3. Means: introduction of a computer contaminant, which is limb (iii).
  4. Consequence: disruption of supplies or services essential to the life of the community. If the system is critical information infrastructure, adverse effect on it also applies.
  5. Conclusion: the elements of clause (A) are satisfied, so the group commits cyber terrorism. Section 66F(2) applies, including to anyone who conspired.

Answer: The group commits cyber terrorism under Section 66F(1)(A) and is punishable under 66F(2) with imprisonment which may extend to imprisonment for life.

Example 2

Ravi, an employee of a private firm, exceeds his authorised access and reads confidential salary records of colleagues for curiosity. Is it cyber terrorism under Section 66F?

Show the solution
  1. Provision: Section 66F needs either clause (A) terror intent with a stated consequence, or clause (B) access to information restricted for State security or foreign relations, or other restricted information, with reason to believe it may cause injury of the kinds listed or benefit a foreign nation or group.
  2. Clause (A): Ravi had no intent to threaten India's unity or sovereignty or to strike terror, and no death, damage or disruption resulted.
  3. Clause (B): salary records are not restricted for State security or foreign relations, and there is no reason to believe they could be used to injure sovereignty, security or public order, or to help a foreign nation.
  4. Conclusion: the ingredients are not met. His conduct may attract other provisions of the Act on unauthorised access, but not Section 66F.

Answer: No. Ravi's act lacks the required intent and the required consequence or likely misuse, so Section 66F does not apply.

Exam tips

  • Write the two limbs, clause (A) and clause (B), as separate headings in your answer. It shows structure.
  • In case questions, spend one line on intent. It is the usual deciding fact.
  • State the punishment exactly: imprisonment which may extend to imprisonment for life, for commission or conspiracy.
  • Link to Section 70 (critical information infrastructure) and Section 69B to show wider understanding.
  • For 'cyber terrorism versus cyber crime' answers, contrast target, intent and punishment in short bullets.

Practice questions from Cyber Threats and Cyber Laws

Cyber Terrorism under Section 66F in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Terrorism under Section 66F: frequently asked questions

What is the punishment under Section 66F of the IT Act?

Whoever commits or conspires to commit cyber terrorism is punishable with imprisonment which may extend to imprisonment for life. The section states no fine and no minimum term.

How is cyber terrorism different from ordinary cyber crime?

Cyber terrorism needs intent to threaten India's unity, integrity, security or sovereignty or to strike terror, or access to restricted State-security information. Ordinary cyber crime usually targets a person or business for gain or harm. The punishment for 66F is also far heavier.

Does Section 66F cover only actual attacks?

No. Clause (A) also covers conduct likely to cause death, injury, damage or disruption. Sub-section (2) also punishes conspiracy to commit cyber terrorism.

What is critical information infrastructure in this context?

Under the Explanation to Section 70, it is a computer resource whose incapacitation or destruction has a debilitating impact on national security, economy, public health or safety. Adverse effect on it is one consequence under clause (A) of Section 66F.