Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Threats and Cyber Laws

Cyber Threats and Types of Cyber Crimes Explained

Updated 11 October 2026 · Fact-checked

A cyber threat is any act or event that can harm a computer resource, its data or the services that depend on it. Common ones are malware, phishing, ransomware, hacking, identity theft and denial of service. To answer an exam question, name the threat, explain how it works, state who is harmed, and link it to the IT Act.

Understand Cyber Threats and Types of Cyber Crimes

A cyber threat is a possible source of harm to a computer, network, data or service. A cyber crime is the threat carried out as an offence under law. The same act can be both a threat and a crime.

Start with the target. Threats hit individuals (stolen money, stolen identity), businesses (data loss, downtime, liability) and the State (attacks on essential services and security information). A good answer always shows the impact on one or more of these.

Learn the common threats by how they work:
- Malware: malicious software such as viruses, worms, trojans and spyware. The IT Act calls this a computer contaminant.
- Phishing: fake emails, messages or websites that trick you into giving passwords, OTPs or card details.
- Ransomware: malware that locks or encrypts data and demands payment to restore it.
- Hacking: accessing a computer resource without permission, or going beyond the permission given.
- Identity theft: using another person's password, electronic signature or other unique identification feature dishonestly. Section 66C covers it.
- Denial of service (DoS): flooding or blocking a system so that authorised users cannot access it.

Do not mix up the terms. Malware is the tool. Phishing is the trick. Ransomware is malware with a ransom demand. Identity theft is the misuse of credentials, often obtained through phishing.

At the extreme end sits cyber terrorism. Section 66F covers acts done with intent to threaten the unity, integrity, security or sovereignty of India, or to strike terror, by denying access, unauthorised access or introducing a contaminant. It also covers unauthorised access to information restricted for State security or foreign relations reasons. The punishment is imprisonment which may extend to imprisonment for life.

The law also puts duties on organisations. Under section 43A, a body corporate handling sensitive personal data that is negligent in keeping reasonable security practices, and thereby causes wrongful loss or gain, must pay compensation. CERT-In is the national agency for incident response under section 70B.

Key rules to remember

Identity theft, section 66C
Fraudulent or dishonest use of another's electronic signature, password or unique identification feature → imprisonment up to 3 years + fine up to ₹1,00,000
Both fraud or dishonesty and the use of another person's identifier must be present.
Cyber terrorism, section 66F
Intent to threaten India's unity, integrity, security or sovereignty, or to strike terror + denial of access / unauthorised access / contaminant + likely death, injury, damage or disruption → imprisonment up to life
Clause (B) separately covers unauthorised access to information restricted for State security or foreign relations reasons. Conspiracy is also punishable.
Data protection failure, section 43A
Body corporate + sensitive personal data + negligence in reasonable security practices + wrongful loss or gain → compensation to the person affected
This is civil compensation, not imprisonment.
CERT-In directions, section 70B
Failure to provide information or comply with direction → imprisonment up to 1 year or fine up to ₹1,00,00,000 or both
Courts take cognizance only on a complaint by an officer authorised by CERT-In.
Traffic data monitoring, section 69B
Intermediary intentionally or knowingly refusing technical assistance → imprisonment up to 1 year or fine up to ₹1,00,00,000 or both
The Central Government authorises an agency to monitor traffic data for cyber security.

How to solve Cyber Threats and Types of Cyber Crimes questions

Use this method for any question on cyber threats, whether it asks you to define, distinguish or apply.

  1. 1Identify each threat named or hidden in the facts, such as a fake email, locked files or a flooded server.
  2. 2Define it in one line and say how it works.
  3. 3Say who is harmed: the individual, the business or the State.
  4. 4Match it to the legal provision you are sure of, for example section 66C, 66F, 43A or 70B.
  5. 5Apply the conditions of that provision to the facts, point by point.
  6. 6Conclude with the likely liability, and add one practical safeguard or compliance step.

Quickest way: Threat, impact, law, action

When to use it: Use this when time is short or the question asks for a short note or a distinction.

  1. Write the threat and a one-line meaning.
  2. Write the impact in one line.
  3. Cite the section only if you are certain of it.
  4. Close with one preventive control or reporting step.

Common mistakes in Cyber Threats and Types of Cyber Crimes

  • Treating malware, phishing and ransomware as the same thing.

    All three appear together in news reports about attacks.

    Fix: Remember: malware is the software, phishing is the deception, ransomware is malware that demands payment.

  • Applying section 66F to every serious hacking incident.

    Students focus on the harm and ignore the required intent.

    Fix: Check for intent to threaten India's unity, integrity, security or sovereignty, or to strike terror, or for access to restricted State information.

  • Saying section 43A gives imprisonment.

    Students assume every section in the Act is a criminal penalty.

    Fix: Section 43A is compensation by a body corporate. It needs sensitive personal data, negligence and wrongful loss or gain.

  • Using identity theft for any misuse of data.

    The term sounds broad.

    Fix: Section 66C needs fraudulent or dishonest use of another person's electronic signature, password or unique identification feature.

  • Quoting section numbers or penalties from memory without certainty.

    Students try to look thorough.

    Fix: Quote only the provisions you know, such as 66C, 66F, 43A, 69B and 70B, and explain the rule in plain words.

Worked examples

Example 1

Riya, an accountant at Kaveri Textiles Ltd, receives an email that looks like it is from her bank. She enters her net-banking password on the linked page. The fraudster then uses the password to transfer money from her account. Identify the threats and the legal position.

Show the solution
  1. The fake email and website are phishing. They deceived Riya into revealing her password.
  2. The fraudster then used her password without her authority and with a dishonest purpose. This is the fraudulent or dishonest use of another person's password.
  3. Section 66C punishes this as identity theft: imprisonment up to three years and fine up to ₹1,00,000.
  4. The impact falls on Riya as an individual, through financial loss. Her employer is exposed if office credentials were also entered.
  5. Safeguards: do not click unverified links, enable two-factor authentication, and report the incident promptly.

Answer: The facts show phishing followed by identity theft. The fraudster is liable under section 66C, with imprisonment up to three years and fine up to ₹1,00,000.

Example 2

Sundaram Pharma Ltd holds customers' health and financial data. A ransomware attack encrypts its servers because the company never updated its security software. Customer data is leaked and customers suffer financial loss. Discuss the company's exposure.

Show the solution
  1. The attack is ransomware, a form of malware that encrypts data and demands payment.
  2. The data is sensitive personal data held by a body corporate in a computer resource it owns, controls or operates.
  3. Not updating security software suggests negligence in implementing and maintaining reasonable security practices and procedures.
  4. The leak caused wrongful loss to customers. All conditions of section 43A are therefore met.
  5. The company is liable to pay damages by way of compensation to the affected persons.
  6. Practical steps: report the incident to CERT-In, which is the national agency for incident response under section 70B, restore from backups, and review security practices.

Answer: Sundaram Pharma Ltd faces civil liability under section 43A to compensate affected customers, because negligence in security practices caused wrongful loss. The attackers are separately liable as offenders.

Exam tips

  • Expect case-based questions: spot the threat from the facts first, then name the provision.
  • Always show the impact on the individual, the business or the State. Examiners reward this link.
  • For distinction questions, use a two-column style in bullets: meaning, method, example, legal provision.
  • Do not state penalties you are unsure of. A correct rule in plain words earns more than a wrong section number.
  • End answers with a compliance or preventive step, such as reporting to CERT-In.

Practice questions from Cyber Threats and Cyber Laws

Cyber Threats and Types of Cyber Crimes in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Threats and Types of Cyber Crimes: frequently asked questions

What is the difference between phishing and ransomware?

Phishing is a deception technique that tricks a person into giving away credentials or data. Ransomware is malware that locks or encrypts data and demands payment. A phishing email can be the route through which ransomware enters a system.

Is hacking always cyber terrorism?

No. Cyber terrorism under section 66F needs intent to threaten India's unity, integrity, security or sovereignty, or to strike terror, or unauthorised access to information restricted for State security or foreign relations reasons. Ordinary hacking lacks that intent.

What is the punishment for identity theft under the IT Act?

Section 66C provides imprisonment of either description up to three years and a fine which may extend to ₹1,00,000. The use of the other person's password, electronic signature or unique identification feature must be fraudulent or dishonest.

What is a denial of service attack?

It is an attack that blocks or overloads a system so that authorised users cannot access it. Denying access to an authorised person can also form part of cyber terrorism under section 66F when the required intent and consequences exist.