Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Regulatory Framework on AI, Cyber Security and Cyberspace
Section 66F IT Act: Cyber Terrorism and Its Punishment
Updated 11 October 2026 · Fact-checked
Section 66F of the IT Act, 2000 defines cyber terrorism in two limbs. Limb (A) covers denying access, unauthorised access or introducing a contaminant with intent to threaten India's unity, security or sovereignty or strike terror, causing harm. Limb (B) covers unauthorised access to restricted data. Punishment may extend to imprisonment for life.
Understand Section 66F: Punishment for Cyber Terrorism
Most cyber offences in the IT Act are about money, privacy or fraud. Cyber terrorism is different. It is about attacks on the nation or on the safety of people, carried out through a computer resource. That is why section 66F carries the heaviest punishment in the Act.
The section has two limbs. Both end with the words "commits the offence of cyber terrorism".
Limb (A): the attack limb. You need an intent: to threaten the unity, integrity, security or sovereignty of India, or to strike terror in the people or any section of them. You need one of three acts: (i) denying or causing the denial of access to a person authorised to access a computer resource; (ii) attempting to penetrate or access a computer resource without authorisation or exceeding authorised access; (iii) introducing or causing to introduce any computer contaminant. You also need a result: by that conduct the person causes or is likely to cause death or injury to persons, or damage to or destruction of property; or disrupts, or knows it is likely to cause damage or disruption of, supplies or services essential to the life of the community; or adversely affects the critical information infrastructure specified under section 70.
Limb (B): the restricted information limb. Here the person knowingly or intentionally penetrates or accesses a computer resource without authorisation, or exceeds authorised access. By that conduct the person obtains access to information, data or a database that is restricted for reasons of the security of the State or foreign relations, or any restricted information with reason to believe it may be used to cause or likely cause injury to the interests of the sovereignty and integrity of India, security of the State, friendly relations with foreign States, public order, decency or morality, or in relation to contempt of court, defamation or incitement to an offence, or to the advantage of any foreign nation, group of individuals or otherwise.
The punishment under sub-section (2) applies to whoever commits or conspires to commit cyber terrorism: imprisonment which may extend to imprisonment for life. There is no fine stated in the section and no minimum term.
Note the wording "causes or is likely to cause". Under limb (A), actual harm is not always needed. Likelihood of harm is enough. Also, section 1(2) says the Act applies to an offence committed outside India by any person, save as otherwise provided.
Key rules to remember
- Limb (A) structure
- Intent + one of three acts + (actual or likely) harm = cyber terrorism
- Intent: threaten unity, integrity, security or sovereignty of India, or strike terror. Acts: denial of access, unauthorised access (or exceeding authorised access), introducing a computer contaminant.
- Limb (B) structure
- Knowing or intentional unauthorised access + obtaining restricted information = cyber terrorism
- Restricted for security of the State or foreign relations, or other restricted data with reason to believe it may be used to cause injury to listed interests.
- Punishment
- Section 66F(2): imprisonment which may extend to imprisonment for life
- Applies to whoever commits or conspires to commit. Maximum only; the section states no fine.
- Harm results under limb (A)
- Causes or is likely to cause death or injuries to persons or damage to or destruction of property | disrupts, or knowing that it is likely to cause damage or disruption of, supplies or services essential to the life of the community | adversely affect the critical information infrastructure specified under section 70
- Any one result is enough. Use the exact wording of each: 'causes or is likely to cause' for death, injuries or damage to property; 'disrupts or knowing that it is likely to cause damage or disruption' for essential supplies or services; 'adversely affect' for critical information infrastructure, where the section states no likelihood qualifier.
How to solve Section 66F: Punishment for Cyber Terrorism questions
Use the same sequence for every fact-based question on section 66F. It keeps your answer in the provision, analysis, conclusion format.
- 1State the provision: section 66F of the IT Act, 2000 defines cyber terrorism and sub-section (2) fixes the punishment.
- 2Identify the limb. If the facts show an attack causing harm, use limb (A). If the facts show access to restricted State or foreign relations data, use limb (B).
- 3For limb (A), test intent first: was it to threaten India's unity, integrity, security or sovereignty, or to strike terror? Ordinary profit or revenge motives do not satisfy it.
- 4Test the act: denial of access, attempting to penetrate or access without authorisation or exceeding authorised access, or introducing a computer contaminant.
- 5Test the result: death, injury, property damage, disruption of essential supplies or services, or an adverse effect on critical information infrastructure. For death, injury or damage, 'likely to cause' can suffice. For disruption, the section uses 'disrupts or knowing that it is likely to cause damage or disruption'.
- 6For limb (B), test unauthorised access, the knowledge or intention, and the restricted nature of the data or the reason to believe it may be misused.
- 7Add conspiracy and abetment if the facts show planning or helpers. Section 66F(2) covers conspiracy. Section 84B punishes abetment only if the abetted act is committed in consequence of the abetment and no express provision is made for its punishment. The punishment is then the one provided for the offence.
- 8Conclude with the punishment: imprisonment which may extend to imprisonment for life. If an ingredient is missing, say that section 66F is not made out and check which other provision of the Act fits the facts.
Quickest way: Intent-Act-Harm check
When to use it: Use this when a short case question gives you facts and asks whether section 66F applies.
- Write the section number and the word 'cyber terrorism' in your first line.
- Underline the intent in the facts. No terror or national-security intent means limb (A) fails.
- Match the act to one of the three listed acts.
- Match the harm to one listed result, or to restricted data for limb (B).
- Write the conclusion and the punishment in one sentence: imprisonment up to life.
Common mistakes in Section 66F: Punishment for Cyber Terrorism
Treating every serious hacking incident as cyber terrorism.
Students focus on the act and the damage and forget the required intent.
Fix: Always prove the intent to threaten India's unity, integrity, security or sovereignty, or to strike terror. A hack for money fits other sections, not 66F.
Stating that section 66F prescribes a fine or a minimum jail term.
Students mix it with sections like 66C and 66D, which mention fine of up to one lakh rupees.
Fix: Write only what sub-section (2) says: imprisonment which may extend to imprisonment for life.
Forgetting the second limb.
Limb (A) is long and gets all the attention.
Fix: Remember that clause (B) separately covers unauthorised access to restricted information, even without physical harm.
Saying actual damage must always occur.
Students assume criminal liability needs a completed result.
Fix: Quote 'causes or is likely to cause'. Likelihood of harm is enough for death, injuries or damage to property under limb (A).
Ignoring conspiracy.
Students think only the person who carries out the attack is liable.
Fix: Section 66F(2) punishes whoever commits or conspires to commit. Mention it when facts show planning.
Mixing up the three acts in limb (A), or naming an act without matching it to the facts.
Students memorise the list without linking it to examples.
Fix: The three acts are separate statutory categories. Link each to an example: denial of access for blocking authorised users, attempting to penetrate or access without authorisation (or exceeding authorised access) for intrusion, introducing a computer contaminant for malware. Name the act that matches the conduct in the facts. Do not claim that one incident can fit only one category.
Worked examples
Example 1
A group, intending to threaten the security of India, introduces malware into the control system of a city's power grid. The grid shuts down for several hours and hospitals lose power. Examine the liability under the IT Act, 2000.
Show the solution
- Provision: section 66F(1)(A) covers intent to threaten the security of India or strike terror, plus listed acts and results.
- Intent: the group intended to threaten the security of India. This satisfies the intent requirement.
- Act: introducing malware is introducing a computer contaminant, which is act (iii).
- Result: the shutdown disrupts supplies or services essential to the life of the community. Loss of hospital power also shows likely injury to persons. The grid may also be critical information infrastructure under section 70, if so specified.
- Conspiracy: if the members planned it together, section 66F(2) covers conspiring to commit the offence.
- Conclusion: the ingredients are met.
Answer: The group commits cyber terrorism under section 66F, punishable with imprisonment which may extend to imprisonment for life.
Example 2
Ravi, an employee at a private firm, breaks into a competitor's server without authorisation to steal its price lists and sells them for profit. A student argues this is cyber terrorism under section 66F. Is the student correct?
Show the solution
- Provision: section 66F has two limbs, one needing terror or national-security intent and one needing access to restricted State or foreign relations data.
- Limb (A): Ravi's intent was profit, not threatening India's unity, integrity, security or sovereignty or striking terror. The intent ingredient fails, and no listed harm occurred.
- Limb (B): Ravi did access a computer resource without authorisation. But price lists of a private competitor are not information restricted for the security of the State or foreign relations. There is also no reason to believe they could injure the listed national interests.
- Conclusion: neither limb is satisfied. Ravi's conduct is unauthorised access for commercial gain, which falls under other provisions of the Act, not section 66F.
Answer: The student is not correct. Section 66F is not attracted because the required intent and the restricted nature of the data are missing.
Exam tips
- Write the structure of section 66F as intent, act and harm. Examiners reward a clear framework before the analysis.
- In case questions, spend your first lines on intent. It is the fact that decides whether section 66F applies at all.
- Always end with the punishment in the section's own words: imprisonment which may extend to imprisonment for life. Do not add a fine.
- Mention conspiracy, which section 66F(2) covers. Where facts suggest helpers, mention abetment under section 84B, but only if the abetted act is committed in consequence of the abetment and no express provision exists. The punishment is then the one provided for the offence.
- In an open-book paper, mark the text of section 66F so you can quote the three acts and the results accurately.
Practice questions from Regulatory Framework on AI, Cyber Security and Cyberspace
- Under Section 69B of the Information Technology Act, 2000, who may authorise an agency of the Government to monitor and collect traffic data…
- Which statement correctly describes the composition and qualification requirements for the Data Protection Board under the Digital Personal …
- Which statement about the procedure and safeguards for monitoring and collecting traffic data under Section 69B is correct?
- Under Section 66F of the IT Act, 2000, which of the following would constitute cyber terrorism?
- Under the Information Technology Act, 2000, which body is designated by the Central Government as the national agency for collecting, analys…
Section 66F: Punishment for Cyber Terrorism in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Section 66F: Punishment for Cyber Terrorism: frequently asked questions
What is the punishment under section 66F of the IT Act?
Section 66F(2) says whoever commits or conspires to commit cyber terrorism is punishable with imprisonment which may extend to imprisonment for life. The section does not mention a fine or a minimum term.
What is cyber terrorism under the IT Act, 2000?
It is conduct under section 66F: either an attack on a computer resource with intent to threaten India's unity, integrity, security or sovereignty or to strike terror, causing or likely causing listed harm, or unauthorised access to restricted information relating to State security or foreign relations. Both limbs are treated as cyber terrorism.
Does section 66F need actual damage?
Under limb (A), the section covers conduct that causes or is likely to cause death, injury or damage to property. So likely harm can be enough. Intent is still required.
Does section 66F apply to acts committed outside India?
Section 1(2) of the Act says that, save as otherwise provided, it applies to any offence or contravention committed outside India by any person. In an answer, cite this when the facts involve a foreign offender.