Sample Read
© All copyright with All India Federation of Tax Practitioners, Mumbai Price : ` 1175 Edition : 2026 Published by : Taxmann Publications (P.) Ltd. Sales & Marketing : 59/32, New Rohtak Road, New Delhi-110 005 India Phone : +91-11-45562222 Website : www.taxmann.com E-mail : sales@taxmann.com Mumbai : 35, Bodke Building, M.G. Road, Opp. Railway Station, Mulund (W), Mumbai - 400 080 Mob. +91-9322247686, 9619668669, 7045453844/45/51 E-mail : sales.mumbai@taxmann.com Regd. Office : 21/35, West Punjabi Bagh, New Delhi-110 026 India Printed at : Tan Prints (India) Pvt. Ltd. 44 Km. Mile Stone, National Highway, Rohtak Road Village Rohad, Distt. Jhajjar (Haryana) India E-mail : sales@tanprints.com Disclaimer Every effort has been made to avoid errors or omissions in this publication. In spite of this, errors may creep in. Any mistake, error or discrepancy noted may be brought to our notice which shall be taken care of in the next edition. It is notified that neither the publisher nor the AIFTP or seller will be responsible for any damage or loss of action to any one, of any kind, in any manner, therefrom. It is suggested that to avoid any doubt the reader should cross-check all the facts, law and contents of the publication with original Government publication or notifications. No part of this book may be reproduced or copied in any form or by any means [graphic, electronic or mechanical, including photocopying, recording, taping, or information retrieval systems] or reproduced on any disc, tape, perforated media or other information storage device, etc., without the written permission of the AIFTP. Breach of this condition is liable for legal action. For binding mistake, misprints or for missing pages, etc., the publisher’s liability is limited to replacement within seven days of purchase by similar edition. All expenses in this connection are to be borne by the purchaser. All disputes are subject to Mumbai jurisdiction only.
2>=C4=CB
PAGE
Operation Sindoor - Hon’ble Prime Minister of India Shri Narendra ModI’s address to the Nation Message from Hon’ble Justice Rajesh Bindal, Judge, Supreme Court of India Message from Hon’ble Justice Anita Sumanth, Judge, High Court of Madras Message from Hon’ble Justice Piyush Agrawal, Judge, High Court of Judicature at Allahabad Message from Hon’ble Justice Abhay Ahuja, Judge, High Court of Bombay Message from Hon’ble Justice Dr. Neela Gokhale, Judge, High Court of Bombay Message from Justice Ms. Aarti Sathe, Judge, High Court of Bombay Message by Justice C. V. Bhadang (Former Judge, Bombay High Court), President Income Tax Appellate Tribunal From the Desk of the Editor Message from the National President Message from the Chairman and Co-chairman All India Federation of Tax Practitioners (AIFTP) 50 Years of celebration (Golden Jubilee) About the Authors Direct Tax Publication Committee Chapter-Headings
I-4 I-8 I-11 I-12 I-13 I-14 I-15 I-16
I-17 I-21 I-23 I-26 I-30 I-34 I-35
CHAPTER 1 CYBERCRIME IN CONTEXT
Q.1
What is cybercrime?
I-37
2
Contents PAGE
Q.2 Q.3 Q.4 Q.5 Q.6 Q.7 Q.8 Q.9 Q.10 Q.11 Q.12 Q.13 Q.14 Q.15 Q.16 Q.17 Q.18
Q.19 Q.20
What makes cybercrime differ from traditional crime? Is there a universally accepted definition of cybercrime? What are some of the ways cybercrimes are commonly classified? Can you give an example of a cybercrime targeting an individual? What kind of cybercrimes target organizations? How are cybercrimes categorized by the Indian government? Why is it important to classify cybercrimes? Does the classification of a cybercrime affect its prosecution? Are all cyber-related activities considered cybercrime? What is a cyber-dependent crime? What are the examples of cyber-dependent crimes? What is a cyber-enabled crime? What are some common examples of cyberenabled crimes? What is the key difference between cyberdependent and cyber-enabled crimes What is the significance of distinguishing between these two categories? Does the Indian Legal system differentiate between these two categories? Could online harassment be categorised as a cyber-dependent crime or a cyber-enabled crime? What about phishing attacks? Do law enforcement agencies handle the investigation of these two categories in different ways? Do law enforcement agencies approach the investigation of these two categories differently?
I-38
2 2 3 3 3 3 3 4 4 4 4 5 5 5 5 5 6
6 6
Contents PAGE
Q.21 Q.22 Q.23
Q.24 Q.25 Q.26 Q.27 Q.28 Q.29 Q.30 Q.31 Q.32 Q.33 Q.34 Q.35 Q.36
Q.37
When did cybercrime first emerge? What were some of the initial forms of cybercrime? In what ways did the rise of the internet influence cybercrime? How did the rise of the internet impact cybercrime? What is the “infrastructure shift” in relation to cybercrime? In what ways did the advent of e-commerce impact cybercrime? How has mobile technology helped in the rise of cybercrime? In what ways has the emergence of the Dark Web impacted cybercrime? What does “Internet of Things” (IoT) mean in the context cybercrime? How have cybercriminals adapted to the developments in cybersecurity? What is the trend of “Crime-as-a-Service”? How did the COVID-19 pandemic influence cybercrime? What specific types of cybercrime saw a rise during the pandemic? In what ways did the transition to remote work affect cybersecurity? How did fear and uncertainty influence cybercrime throughout the pandemic? Were any new methods of cybercrime noted during the pandemic? What actions did governments and organizations take in response to the increase in cybercrime during the pandemic? Has the rise in digital dependence after COVID-19 maintained the elevated levels of cybercrime?
I-39
6 7 7
7 7 8 8 8 8 8 9 9 9 9 9 10
10
Contents PAGE
Q.38 Q.39 Q.40 Q.41 Q.42 Q.43 Q.44 Q.45 Q.46 Q.47 Q.48 Q.49 Q.50 Q.51
Q.52
Q.53 Q.54
Q.55
What enduring effect has COVID-19 had on cybersecurity strategies? Did the use of digital payment platforms lead to an increase in cybercrimes? What is the primary law governing cybercrime in India? When was the Information Technology Act enacted? What was the purpose of the IT Act, 2000? What are some key offenses covered under the IT Act, 2000? Has the IT Act been amended, and if so, when was the major amendment? What are the powers of the Adjudicating Officer under the IT Act? Does the IT Act apply to offenses committed outside India? What function does the Cyber Appellate Tribunal serve under the IT Act? Is intermediary liability covered by the IT Act 2000? What are the penalties for cyber terrorism under the IT Act? What is the Bharatiya Nyaya Sanhita, 2023? When did the Bharatiya Nyaya Sanhita (BNS), 2023 take effect? When did the Bharatiya Nyaya Sanhita (BNS), 2023 come into effect? In what ways does the Bharatiya Nyaya Sanhita (BNS) influence the management of cybercrimes? Has the BNS established distinct classifications for cybercrimes? Can you provide an example of how the BNS is relevant to actions related to cyber activities? How does the BNS interact with the Information Technology Act?
I-40
10 10 11 11 11 11 12 12 12 12 13 13 13 14
14
14 14
15
Contents PAGE
Q.56 Q.57 Q.58 Q.59 Q.60
Q.61 Q.62 Q.63 Q.64 Q.65
Q.66 Q.67
Q.68 Q.69
Q.70 Q.71 Q.72
Does the BNS contain provisions against misinformation or fake news? Does the BNS extend to offenses committed outside India? How does the BNS make prosecution of cybercrimes more efficient? What is the function of the BNS within cybercrime framework? In what way is the Protection of Children from Sexual Offences (POCSO) Act, 2012, connected to cybercrime? Is the Consumer Protection Act, 2019 applicable to online frauds? What does Digital Personal Data Protection (DPDP) Act, 2023 entail? In what way does the DPDP Act help in fighting cybercrime? What consequences does the DPDP Act have for companies managing personal data? Is the Indian Copyright Act, 1957, applicable to cybercrime? Can the Indian Copyright Act, 1957, be applied to cybercrime? How does the Indian Telegraph Act of 1885 play role in cybercrime investigation? Are there any particular regulations in India aimed at combating money laundering via digital methods? How do these multiple laws interact in a cybercrime case? What is the importance of “due diligence” under various Indian laws concerning cybercrime? What is CERT-In and what is its role? What is the Indian Cybercrime Coordination Centre (I4C)? What are the key functions of I4C?
I-41
15 15 15 16 16
16 17 17 17 17
18 18
18 18
19 19 19
Contents PAGE
Q.73 Q.74 Q.75 Q.76 Q.77 Q.78 Q.79 Q.80 Q.81 Q.82 Q.83 Q.84 Q.85 Q.86 Q.87 Q.88 Q.89 Q.90
Who are “intermediaries” in the context of cybercrime, as per the IT Act? What are the responsibilities of intermediaries in combating cybercrime? What is a Cyber Cell in the context of Indian policing? In what ways do CERT-In, I4C, and Cyber Cells work together? What role does the National Cybercrime Reporting Portal (cybercrime.gov.in) play? Are there additional institutional bodies involved in combating cybercrime in India? How does the government ensure coordination among these diverse entities? What is the Budapest Convention on Cybercrime? When was the Budapest Convention adopted? What are the main objectives of the Budapest Convention? Is India a signatory to the Budapest Convention? Why has India not ratified the Budapest Convention? Although India is not a signatory, does it conform to any principles of the Convention? In what ways does India engage in international cooperation without being a signatory? What does the “24/7 network” represent in the context of the Convention? What alternative international instruments exist for cybercrime cooperation? What significance do UN Resolutions hold in the fight against cybercrime? Has the UN developed its own comprehensive treaty on cybercrime?
I-42
19 20 20 20 20 20 21 21 21 21 22 22 22 22 22 23 23 23
Contents PAGE
Q.91 Q.92 Q.93 Q.94 Q.95
Q.96 Q.97 Q.98 Q.99 Q.100 Q.101 Q.102 Q.103 Q.104
Q.105 Q.106
What are some regional pacts related to cybercrime? Is India involved in any regional pacts related to cybercrime? What is the aim of these regional pacts? In what ways do UN efforts vary from the Budapest Convention? What is the importance of the Ad Hoc Committee to Elaborate a Comprehensive International Convention on Countering the Use of Information and Communications Technologies for Criminal Purposes? In what way UN resolutions impact national cybercrime policies? Are there any challenges in achieving a global consensus on cybercrime through the UN? What is the role of Interpol in international cybercrime cooperation In what does India participate in bilateral cooperation on cybercrime? Which countries engage with India in notable bilateral collaboration regarding cybercrime? What are MLATs (Mutual Legal Assistance Treaties)? How does India participate in multilateral forums for cybercrime? What are the benefits of multilateral cooperation in combating cybercrime? Does India collaborate with international law enforcement agencies like Europol or FBI on cybercrime? What are the challenges India faces in international cooperation on cybercrime? How does India contribute to global cybersecurity capacity building efforts?
I-43
23 23 24 24 24
24 24 25 25 25 25 25 26 26
26 26
Contents PAGE
Q.107 Q.108 Q.109 Q.110 Q.111 Q.112 Q.113 Q.114 Q.115 Q.116 Q.117 Q.118 Q.119 Q.120 Q.121 Q.122 Q.123 Q.124 Q.125
What is the role of diplomatic channels in India’s international cybercrime efforts? Has India hosted any international conferences or initiatives on cybercrime? What are jurisdictional issues in cybercrime? Why is anonymity a significant challenge in cybercrime investigations How does the borderless nature of the internet contribute to jurisdictional problems? What is the “digital divide” in terms of law enforcement’s capabilities? How do legal differences between countries create challenges? What is “forum shopping” in the context of cybercrime? How do encrypted communications pose a challenge to law enforcement? Is it possible to completely eliminate anonymity online? What is the “cloud computing” challenge for jurisdiction? How does the principle of “territoriality” conflict with cybercrime’s nature? Why is cybercrime often underreported? What are the consequences of underreporting? What makes cybercrime enforcement difficult? Is there a shortage of skilled cyber investigators in India? How do “evidential challenges” impact cybercrime prosecution? What is the role of public-private partnerships in overcoming enforcement difficulties? How does the rapid pace of technological change affect enforcement?
I-44
26 27 27 27 27 27 28 28 28 28 28 29 29 29 29 29 30 30 30
Contents PAGE
Q.126 Q.127 Q.128 Q.129 Q.130 Q.131 Q.132 Q.133 Q.134 Q.135 Q.136 Q.137 Q.138 Q.139 Q.140 Q.141 Q.142 Q.143 Q.144
What challenges do victims face in seeking justice for cybercrimes? How can international collaboration help address enforcement difficulties? What is the “attribution problem” in cybercrime? How do cybercriminals’ techniques constantly evolve? What is “Ransomware-as-a-Service” (RaaS)? What is “phishing” and how has it evolved? How are AI and Machine Learning being used by cybercriminals? What is the threat posed by “deepfakes” in cybercrime? How does the rise of cryptocurrencies impact cybercrime? What is the concept of “supply chain attacks”? How are “Internet of Things” (IoT) devices being exploited by criminals? What is “social engineering” and why is it so effective? How are “zero-day exploits” a challenge for cybersecurity? Why is public awareness crucial in combating cybercrime? What are common legal knowledge gaps among the general public regarding cybercrime? How does legal literacy empower individuals against cybercrime? What initiatives can bridge these legal knowledge gaps? How can schools and universities contribute to legal literacy on cybercrime? What is the importance of knowing about reporting mechanisms (e.g., cybercrime.gov. in)?
I-45
30 30 31 31 31 31 31 32 32 32 32 32 32 33 33 33 33 34 34
Contents PAGE
Q.145 Q.146 Q.147 Q.148 Q.149 Q.150 Q.151 Q.152 Q.153 Q.154 Q.155
Q.156
Q.157 Q.158
How does understanding data protection laws benefit individuals What is the role of the media in raising public awareness about cybercrime? How can simplified Q&A formats help in promoting legal literacy? What is the long-term impact of increased legal literacy on cybercrime rates? What is the role of lawyers in combating cybercrime? How do Chartered Accountants (CAs) contribute to cybercrime prevention? What are the responsibilities of Compliance Officers in cybersecurity? How do these professionals help businesses navigate the legal complexities of cybercrime? What is the importance of legal counsel for victims of cybercrime? How do Chartered Accountants assist in cases of cyber-enabled financial fraud? What is the significance of “privacy by design” and “security by design” from a legal perspective? How do lawyers and compliance officers ensure an organization’s adherence to the DPDP Act? What training or specialization is required for these professionals in cyber law? How can these professionals help in reducing the overall impact of cybercrime on society?
34 34 34 35 35 35 35 35 36 36 36
36
36 37
CHAPTER 2 DIGITAL FINANCIAL FRAUDS
Q.159 Q.160
What is Phishing? How do Phishing attacks typically work?
I-46
41 42
Contents PAGE
Q.161 Q.162 Q.163 Q.164 Q.165 Q.166 Q.167 Q.168 Q.169 Q.170 Q.171 Q.172 Q.173 Q.174 Q.175 Q.176 Q.177 Q.178 Q.179 Q.180 Q.181 Q.182 Q.183
What are the common signs of a Phishing attempt? What is Vishing? How do Vishing scams usually work? What are the common signs of a Vishing attempt? What are QR Code Frauds? How do QR Code scams typically operate? What are the key red flags for QR Code Frauds? Can scanning a malicious QR code harm my smartphone? What is “Social Engineering” in the context of these frauds? Are there any specific scams in India that use these methods? Why are these types of frauds so common? What is a Remote Access Scam? How do Remote Access Scams typically work? What are the warning signs of a Remote Access Scam? What is OTP Hijacking? How do OTP Hijacking scams typically work? What is “SIM Swap Fraud” and how does it relate to OTP hijacking? What are the signs that my OTP might be hijacked or my SIM swapped? Are SMS OTPs becoming less secure? What is an “OTP Bot”? How can malware lead to OTP hijacking? Why is it so important to be careful with unsolicited requests for information? What role does “human weakness” play in OTP hijacking?
I-47
42 43 43 44 44 44 45 46 46 47 47 48 48 48 49 49 50 50 51 51 52 52 53
Contents PAGE
Q.184 Q.185 Q.186 Q.187 Q.188 Q.189 Q.190
Q.191 Q.192 Q.193 Q.194 Q.195 Q.196 Q.197 Q.198 Q.199 Q.200 Q.201 Q.202
What is Section 66C of the IT Act? What is the punishment for identity theft under section 66C? Can you give examples of identity theft relevant to financial fraud? What is Section 66D of the IT Act? What is the punishment for cheating by personation under section 66D? Can you give examples of cheating by personation relevant to financial fraud? What is the difference between identity theft (Section 66C) and cheating by personation (Section 66D)? Do these sections only apply to individuals, or can they apply to organized groups? Are there other sections of the IT Act relevant to cyber financial fraud? Is it important to report these crimes under the IT Act? What is “Cheating” under section 318 of the BNS? How does Section 318 BNS apply to digital financial frauds? What is the punishment for cheating under section 318 BNS? What is “Forgery” under section 336 of the BNS? What does “digital forgery” mean under BNS? How does Section 336 BNS apply to digital financial frauds? What is the punishment for forgery under section 336 BNS? What elements must be proven to establish forgery under BNS? Why is the BNS considered an important update for combating digital fraud?
I-48
55 56 56 56 56 57 57
58 58 58 59 59 60 60 61 61 62 62 62
Contents PAGE
Q.203 Q.204
Q.205 Q.206 Q.207 Q.208 Q.209 Q.210 Q.211 Q.212 Q.213 Q.214 Q.215 Q.216 Q.217 Q.218 Q.219
Can these sections be used in conjunction with the IT Act? What are the RBI guidelines on customer protection in unauthorized electronic transactions? What is “zero liability” for customers in case of unauthorized transactions? What if I report the fraud after three days but within seven working days? What happens if I report the fraud after seven working days? How quickly must banks resolve fraud complaints? What is “shadow reversal” and why is it important? What are the RBI’s new draft guidelines (2025) for digital banking and fraud protection? What is the Financial Fraud Risk Indicator (FRI) and how does it help? What is the Mobile Number Revocation List (MNRL) and its purpose? How does RBI promote customer awareness about fraud? What is the bank’s responsibility if I am a victim of fraud? Can banks force me to use digital banking? Why is timely reporting of fraud to the bank so important? Why are court cases important in understanding digital financial fraud? What is the “Digital Arrest” scam, and what was a recent landmark judgment related to it? Under which laws were the convicts in the “Digital Arrest” case punished?
I-49
63 64
65 65 65 66 66 66 67 67 68 68 68 69 70 70 71
Contents PAGE
Q.220
Q.221
Q.222
Q.223 Q.224 Q.225 Q.226 Q.227 Q.228 Q.229 Q.230 Q.231 Q.232 Q.233 Q.234 Q.235
Q.236
What was the outcome of the Kerala High Court case involving Bank of Baroda and forged cheques? What was the key legal principle established by the Kerala High Court in the Bank of Baroda case? What did the Allahabad High Court rule regarding the burden of proof in unauthorized online transactions? Did the Allahabad High Court always rule in favour of the customer in such cases? What is the significance of courts labeling cybercrimes as “economic terrorism”? How do these judgments impact victims of digital financial fraud? Do these cases suggest a trend in how Indian courts are handling cybercrime? What is the National Cyber Crime Reporting Portal (NCRP)? How do I file a complaint on the NCRP? What is the National Cyber Crime Reporting Helpline number? What should I do immediately if I realize I’ve been a victim of financial fraud? What is CERT-In’s role in cyber financial fraud? How can CERT-In help me if I am a victim? What are “Bank Helpdesks” and how do I use them? Why is providing evidence important when reporting a fraud? What is the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS)? Can I report a fraudulent website or app?
I-50
71
72
72
73 73 73 74 75 75 76 76 76 77 77 78 78
78
Contents PAGE
Q.237 Q.238 Q.239 Q.240 Q.241 Q.242 Q.243 Q.244 Q.245 Q.246 Q.247 Q.248 Q.249 Q.250 Q.251 Q.252 Q.253
What is the role of local police in cyber financial fraud cases? Is there a time limit for reporting fraud to my bank? What are the fundamental “Safe Banking” practices recommended by RBI and banks? How can I protect myself from Phishing and Vishing attempts? What specific precautions should I take for UPI and QR code payments? How can I prevent Remote Access and OTP Hijacking scams? What is “Juice Jacking” and how can I avoid it? What are the RBI’s efforts in raising public awareness about financial frauds? What is the “Sanchar Saathi” portal and how does it help? How do dedicated phone number series help prevent fraud? Why is it important to use strong, unique passwords for different accounts? What is “Card Skimming” and how can I protect my debit/credit cards? Why should I be cautious about public Wi-Fi networks? What role does “Digital Intelligence Platform (DIP)” play in preventing fraud? What is “MuleHunter.AI” and how does RBI plan to use it? Why are regular software updates important for security? What is the overall goal of these prevention efforts?
I-51
79 79 80 80 81 81 81 81 82 82 82 83 83 83 83 84 84
Contents PAGE
CHAPTER 3 IDENTITY-BASED CYBER OFFENCES
Q.254 Q.255 Q.256 Q.257 Q.258 Q.259 Q.260 Q.261 Q.262
Q.263 Q.264 Q.265
Q.266 Q.267 Q.268 Q.269
What is SIM swap fraud? How do fraudsters trick telecom providers into performing a SIM swap? What are the common signs that my SIM card might have been swapped? What immediate dangers does SIM swapping pose to me? How does Mobile Number Portability (MNP) relate to this fraud? What techniques do fraudsters use to gather information for SIM swaps? Can SIM swap fraud lead to unauthorized bank transactions? Are there any specific measures taken by Indian regulators to prevent SIM swap fraud? Why is relying solely on SMS-based TwoFactor Authentication (2FA) risky against SIM swap fraud? What role does the human element play in SIM swap fraud? What is a “port-out scam”? What should I do if I suspect my phone service has suddenly stopped working without explanation? What are deepfakes and how are they used in cybercrime? Can you provide examples of deepfake incidents in India? What is “spoofing,” particularly email spoofing? How do cybercriminals carry out email spoofing attacks?
I-52
87 87 88 88 89 89 89 90 90
90 91 91
91 92 92 92
Contents PAGE
Q.270 Q.271 Q.272 Q.273 Q.274 Q.275
Q.276 Q.277 Q.278 Q.279 Q.280 Q.281 Q.282 Q.283
Q.284 Q.285
Q.286
What is the difference between email spoofing and phishing? What is identity theft in simple terms? What are the different types of identity theft? How do criminals typically obtain personal information for identity theft? What is the “PAN 2.0 scam” and why is it dangerous? Why are deepfakes considered a significant leap in cybercrime compared to traditional spoofing? What is the “media trust crisis” caused by deepfakes? Why is personal identity information considered the “ultimate currency” in cybercrime? What is “phishing” in the context of identity theft? How can individuals protect themselves from phishing scams like the “PAN 2.0 scam”? What does Section 66C of the Information Technology (IT) Act, 2000, address? What is the punishment for identity theft under IT Act Section 66C? What does Section 72 of the IT Act, 2000, cover? What are the penalties for breaching confidentiality and privacy under IT Act Section 72? How do Sections 66C and 72 relate to identitybased cyber offenses? What is the primary purpose of the Information Technology Act, 2000, in relation to digital identity? Does the IT Act cover both physical and digital forms of identity theft?
I-53
93 93 93 94 94 95
95 95 96 96 97 97 97 98
98 98
99
Contents PAGE
Q.287 Q.288
Q.289 Q.290 Q.291 Q.292 Q.293 Q.294 Q.295 Q.296 Q.297 Q.298 Q.299 Q.300 Q.301 Q.302
Q.303
What does “fraudulently or dishonestly” mean in the context of Section 66C? Can a single cyber incident lead to charges under both Section 66C and Section 72 of the IT Act? What kind of information is protected under Section 72 of the IT Act? What is the Bharatiya Nyaya Sanhita (BNS), 2023, and how does it relate to cybercrime? How does BNS Section 336 define “forgery”? What are the different levels of punishment for forgery under BNS Section 336? What does “cheating by personation” mean under BNS Section 319? What is the punishment for cheating by personation under BNS? How does BNS address digital forms of forgery and personation? What was the Indian Penal Code (IPC) and why was it replaced by the BNS? What elements must be proven to establish an offense under BNS Section 336 (Forgery)? Is forgery under BNS Section 336(2) a bailable offense? Is forgery with intent to cheat under BNS Section 336(3) a bailable offense? Does “cheating by personation” under BNS Section 319 apply only to real people? How does the BNS’s definition of “Document” impact digital crimes? What is the role of the Telecom Regulatory Authority of India (TRAI) in preventing telecom fraud? What key guidelines has TRAI issued to prevent SIM porting fraud?
I-54
99 99
99 100 100 100 101 101 101 102 102 102 103 103 103 104
104
Contents PAGE
Q.304 Q.305
Q.306
Q.307 Q.308
Q.309 Q.310 Q.311
Q.312
Q.313 Q.314 Q.315 Q.316 Q.317 Q.318
What is the Digital Consent Acquisition (DCA) pilot launched by TRAI? How does the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, protect individual identity information? What are the penalties for unauthorized use or disclosure of Aadhaar data under the Aadhaar Act? What is the Central Identities Data Repository (CIDR) mentioned in the Aadhaar Act? What is the primary objective of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016? Does UIDAI collect sensitive personal information like religion or caste? How does UIDAI respond to requests for identity verification? What is the penalty for tampering with data in the Central Identities Data Repository (CIDR) under the Aadhaar Act? What is the ‘Chakshu’ platform introduced by the Department of Telecommunications (DoT)? How does TRAI’s Digital Consent Acquisition (DCA) pilot enhance consumer autonomy? Can you provide examples of real-world Aadhaar-linked financial fraud cases in India? How do phishing scams exploit Aadhaar and PAN details? What was the “PAN 2.0 scam”? How did the Mumbai ATM skimming scam operate? What legal recourse did victims of Aadhaar misuse find in cases like the Bombay High Court ruling?
I-55
105 105
105
106 106
106 107 107
107
107 108 108 109 109 109
Contents PAGE
Q.319 Q.320 Q.321 Q.322 Q.323 Q.324 Q.325 Q.326 Q.327 Q.328 Q.329 Q.330 Q.331 Q.332 Q.333 Q.334 Q.335 Q.336
Can Aadhaar misuse lead to victims being implicated in major financial crimes? How does identity theft linked to Aadhaar often cascade into other frauds? What are the broader consequences of Aadhaar misuse beyond direct financial loss? Why is prompt action critical for victims of Aadhaar-linked fraud? What is the significance of the Bombay High Court’s ruling regarding Aadhaar fraud? What is the role of phishing in Aadhaarlinked financial breaches? What immediate steps should I take if I suspect my SIM card has been swapped? How can I block a lost or stolen mobile phone in India? What are the official channels for reporting Aadhaar-related fraud to UIDAI? How does UIDAI assist individuals who have been victims of Aadhaar fraud? What is the ‘Chakshu’ platform? Why is it important to act quickly if you suspect SIM swap fraud? What is the National Cyber Crime Reporting Portal? Can a blocked phone’s IMEI be unblocked if the phone is recovered? What is the UIDAI toll-free helpline number and its availability? What kind of documentation should a victim of SIM swap fraud retain? How does the CEIR portal help in combating mobile phone theft and fraud? What is the significance of the government establishing centralized platforms for reporting cybercrimes?
I-56
110 110 111 111 111 111 112 112 113 113 114 114 114 115 115 115 115 116
Contents PAGE
Q.337 Q.338 Q.339 Q.340 Q.341 Q.342 Q.343 Q.344 Q.345
Q.346
Q.347 Q.348 Q.349 Q.350
Q.351 Q.352 Q.353 Q.354
What are biometric locks and how do they enhance digital security? How do biometric authentication systems work to prevent identity theft? Are biometric authentication systems being used for digital transactions in India? What is an Aadhaar Virtual ID (VID)? How do I generate an Aadhaar Virtual ID? What are the benefits of using an Aadhaar Virtual ID? Is a Virtual ID permanent? What is “liveness detection” in biometric systems? How does biometric authentication align with RBI’s Two-Factor Authentication (2FA) guidelines? Can Aadhaar Virtual IDs be used for linking Aadhaar with other services like PAN or bank accounts? What are some examples of biometric locks available in India? How does using a Virtual ID enhance privacy during e-KYC verification? What are consent-based authentication systems? How does India’s Digital Personal Data Protection (DPDP) Act, 2023, relate to consentbased data sharing? What are “Consent Managers” under the DPDP Act? How do consent-based systems enhance data privacy and control for individuals? Can consent for data sharing be withdrawn? What is the significance of the Digital Consent Acquisition (DCA) pilot in India?
I-57
116 117 117 117 118 118 119 119 119
120
120 120 121 121
121 122 122 122
Contents PAGE
Q.355
Q.356 Q.357 Q.358 Q.359
Q.360
What are the core principles of a data protection framework in India, as outlined in the White Paper on Data Protection? What does “informed consent” mean under India’s data protection framework? What is the role of “data fiduciaries” under the DPDP Act? How does the DPDP Act ensure transparency in data processing? What is the significance of the DPDP Act aligning with the electronic consent artefact design in the AA (Account Aggregator) ecosystem? How do Consent Managers provide a “single point of contact” for data principals?
123
123 123 124 124
124
CHAPTER 4 E-COMMERCE AND PLATFORM FRAUD
Q.361 Q.362 Q.363 Q.364 Q.365
Q.366
Q.367 Q.368
How did technological boom paved way for creation of Internet? What is e-commerce? What is Platform-based e-commerce and its types? What are various types of e-commerce platform fraud? Are there legal framework(s) provided by the Indian Statutes to address e-commerce platform fraud? What specific remedies are provided in the Information Technology Act and its subsequent amendments? Is Consumer Protection Act, 1986, adequate to cater to e-commerce platform frauds? Does the new data protection statute mandate any e-commerce compliance?
I-58
126 128 130 132 137
138
141 144
Contents PAGE
Q.369 Q.370
Is e-commerce taxed? Conclusion and suggestions
144 145
CHAPTER 5 INCOME TAX RELATED CYBER CRIMES AND LOSSES
Q.371 Q.372 Q.373
Q.374
Q.375
Q.376
Q.377
Q.378 Q.379
Discuss the impact of digitalization, as to the tax compliance? What are the challenges of digitalization in the tax system? Whether the digital challenges in tax compliance can be overcome by the taxpayer and authorities as well? In the present context, when we are standing at the cross roads of law, business and technology, discuss the significance of the cyber loss, if occurred, how to be dealt as per the provisions of Income Tax Act? What are the concerns that may be encountered in the event of lack of uncertainty or predictability of the disputes in respect of the claim of cyber losses; under the provisions of Income-Tax Act 1961? The principles of natural justice, being the soul of administration of justice, need to be adhered to for considering the allowability of Cyber loss – Discuss In the context of allowability of cyber loss occurred, in the event the substantial justice and technical consideration are pitted against each other, the cause of substantial justice deserves to be preferred – Discuss. Whether the cyber loss incurred can be treated as trading loss in commercial sense? Assessee an Individual had invested in shares. The shares held in a corporate entity have been sold and resulted in long-term capital
I-59
150 151 151
152
154
155
157
158 159
Contents PAGE
Q.380
Q.381
Q.382
Q.383
Q.384
Q.385
Q.386
gain. The proceeds were kept in his bank account. Due to cybercrime, he lost all the money in the bank. The recovery appeared to be remote. Can the loss occurred due to cybercrime be claimed as capital loss, considering that there was long-term capital gains, which is liable to be taxed? Further the amount in the bank being lost due to cyber fraud can the same be claimed as a capital loss, and if so against the resulted long-term capital gains, on the sale of shares? Once cyber loss has been established to be the loss on embezzlement, the year in which the deduction is to be claimed has its own eventualities – Discuss Explain the concept of allowability to business loss as per the provisions of Income Tax Act 1961? Explain the concept of Digital Evidence and its applicability to the provisions of Income Tax Act 1961 State as to how the Digital Evidence in the content of electronic records is to be considered in the applicability of cases covered under Search Action u/s 132 of the Income Tax Act 1961 State the contents of digital evidence investigation manual of Central Board of Direct Taxes In the context that pen drive and other electronic records are found and seized during Search Action discuss the evidentiary value of the same Whether revenue is entitled to demand unrestricted access to acquire electronic records present in laptops pertaining to third parties unconnected with person searched?
I-60
162
164
165
167
169
174
175
Contents PAGE
Q.387
Q.388 Q.389
Q.390 Q.391
Q.392
Q.393
Q.394
Q.395
Q.396
Is it justifiable to claim the deduction of bad debt, as business loss? If claimed so is the deduction allowable as business loss? State the nature of cyber crimes in relation to Income Tax Act 1961 Is there any scope for prevention or availability of any solutions for the averruncate or ward off or uproot, such cyber crimes? Is there any legal protection, and what is the scope for punishment under law? In the present process of digital revolution, era of digital economy, considering the explosion of data state the risks, and is there any protection? In the context of the claim for deduction of cyber losses, as per the provisions of Income Tax Act 1961, state the arguments that should meet the test of law Whether banks or lenders can claim deduction of cyber fraud losses as business loss either under section 28 or under section 37(1) of the Income Tax Act 1961. (Sections 26 and 31 of Income Tax Act 2025(2)) Whether the whatsapp chats, on standalone basis, can be considered as valid evidence to support the addition by Assessing Officer? The electronic records by way of secondary evidence are not admissible in evidence unless the requirements of sections 61 & 63 of “THE BHARATIYA SAKSHYA ADHINIYAM 2023” (Formerly section 65B of Indian Evidence Act (1872)) are satisfied – Discuss What shall be the evidentiary value of the data on a pen drive seized from the cashier, where no evidence produced regarding the computer from which the pen drive was copied?
I-61
176
177 178
179 180
181
182
183
184
187
Contents PAGE
Q.397
Q.398
Q.399 Q.400 Q.401
Q.402
Whether the document containing the details noticed in the smart phone of an assessee or employee during Search Action can be of evidentiary value, without corroborating such document with some other credible evidence? In the context of untested/unverified document, the print out taken from the computer back up of a third party, during Search Action is it justifiable to demonstrate, that payment has been received as mentioned in the said document without any other corroborative evidence Cyber security remains as an essential element for strategic business value – Discuss. In the context of money lost in crypto scam In the context of allowability of cyber loss, in the year in which the loss occurred, in the event the loss has been subsequently recovered and thereby credited in the books of account, discuss the taxability as per the provisions of Income Tax Act 1961 The consequences of “financial embezzlement”, when require consideration, and to be dealt with, the powers should be exercised judiciously under the Income Tax Act 1961 – Discuss.
189
190
192 193 195
196
CHAPTER 6 GOODS AND SERVICES TAX RELATED CYBERCRIMES IN INDIA
Q.403 Q.404 Q.405 Q.406 Q.407
What are tax-related cybercrimes? What constitutes a cybercrime in the context of the Income-tax Act? What constitutes a cybercrime in the context of GST? What are the broader implications of GST cybercrimes? How are such frauds detected by the authorities?
I-62
203 203 204 205 206
Contents PAGE
Q.408
Q.409 Q.410
Q.411 Q.412
Q.413 Q.414
Q.415
Q.416
Q.417 Q.418
How do the Income-tax Department (CBDT) and the GST Department (CBIC) coordinate in cases of cyber-enabled tax frauds? What immediate actions are taken by tax authorities once such frauds are detected? What responsibilities do tax authorities and professionals have as Data Fiduciaries under the Digital Personal Data Protection Act, 2023? How do fake invoice scams work? How are fake invoice frauds linked to money laundering under the Prevention of Money Laundering Act, 2002 (PMLA)? How do authorities detect large fake-invoice schemes (technical side)? What are the specific criminal offences and corresponding punishments, including the monetary thresholds for imprisonment, prescribed under section 132 of the CGST Act, 2017? What are the essential legal and procedural criteria that determine when GST authorities must initiate criminal prosecution under Section 132 (Punishment for Offences) instead of merely levying a civil penalty/demand under section 122 (Penalty for Certain Offences) of the CGST Act? Can a person be arrested under GST laws and/or the Income-tax Act, and what legal remedies are available to challenge or prevent such arrest? What is Circular No. 171/03/2022-GST (CBIC) and why does it matter? In practical terms, how should GST officers and taxpayers act differently after Circular 171/03/2022-GST dated July 6, 2022?
I-63
208
210 212
214 216
217 218
220
221
223 225
Contents PAGE
Q.419
Q.420 Q.421
Q.422
Q.423 Q.424 Q.425 Q.426 Q.427
What is the Directorate General of Systems & Data Management (DG Systems & DM) and what role does it play in cyber security and prevention within the Central Board of Indirect Taxes and Customs (CBIC)? What are some real instances of cybercrime and fraud under GST? If a purchaser received invoices from a supplier later found to be fake, will the purchaser automatically face prosecution? What procedural safeguards/actions should a taxpayer take on receiving an SCN alleging fake invoices? Can victims of identity theft (GST registrations created using stolen PAN/Aadhaar) get relief? What should one do if they become a victim of GST-related cybercrime? How can taxpayers safeguard themselves? What is the government’s approach to prevent such frauds? What is the way forward?
227
229 232
233
233 233 234 234 234
CHAPTER 7 NAVIGATING THE MINEFIELD OF MODERN EMPLOYMENT FRAUD
Q.428 Q.429 Q.430 Q.431 Q.432 Q.433
Which are the most prevalent job frauds now? What are the largest red flags of a job scam? What can I do to identify an AI based deep fake in a video interview? What should I do to distinguish between a veritable and a bogus offer letter? What are the primary legislations in India that combat job scams? I’ve been scammed! What are the three things I need to do first?
I-64
258 259 259 260 260 261
Contents PAGE
Q.434 Q.435
Q.436 Q.437
What happens to filing of formal police complaint in India? I have fallen into a trap of a fake foreign job opportunity and have gotten stuck in a foreign land. Who can help? What do I do to make sure that he is a legitimate company? How can firms prevent their brand being involved in frauds?
261 261
262 262
CHAPTER 8 MONEY LAUNDERING & CYBERCRIME UNDER PMLA
Q.438 Q.439
Q.440
Q.441
Q.442 Q.443 Q.444
Q.445
Q.446
How is Money Laundering committed through Cyber Crimes? What are the mechanisms put in place by the Government in order to detect money laundering through Virtual Digital Assets? What are the most common terms under at the nexus of money laundering and cybercrime in the Indian context? What are the legal provisions under the Prevention of Money Laundering Act, 2002, for in relation to cybercrimes? What is the process of attachment under PMLA? What is the provision for Bail under PMLA? Who are reporting entities under PMLA? What are the statutory obligations of a reporting entity? What are the obligations of Chartered Accountants under PMLA, 2002 since they are aware about certain business activities of the their clients? What are suspicious transactions? What are the obligations of a reporting entity in terms of suspicious transactions?
I-65
273 274
275
281
287 291 291
296
298
Contents PAGE
Q.447 Q.448
Does the PMLA provide for multi-agency coordination? What are a few examples of recent cases that had elements of being useful to understand the nexus between money laundering and cybercrime?
299 300
CHAPTER 9 RESPONSE PATHWAYS AND REDRESSAL TOOLKIT
Q.449 Q.450 Q.451 Q.452 Q.453 Q.454
Q.455
What are the various types of cybercrimes? What are the various elements of a crime in the case of a cyber offence What are various steps in cybercrime investigations? What are the standards of evidence and the internet in various jurisdictions? What are various types of Cyber/Computergenerated Evidence? Does Bharatiya Sakshya Adhiniyam (BSA), 2023 include provisions to encompass electronic evidence to thwart cybercrimes? Conclusion and suggestions
303 304 305 305 306 310
313
CHAPTER 10 DUBAI, UAE Q&A GUIDE ON FINANCIAL CRIME AND DATA PROTECTION UNDER UAE LAW
Q.456 Q.457 Q.458 Q.459 Q.460 Q.461 Q.462
What is the main purpose of Federal DecreeLaw No. (34) of 2021? What is Information Technology (IT)? What is Electronic Information? How does the law define “Data” and its categories? What is a cyberattack? What is Encryption? What does “Electronic” mean in this law?
I-66
315 316 316 316 317 317 317
Contents PAGE
Q.463 Q.464 Q.465 Q.466 Q.467 Q.468 Q.469 Q.470 Q.471 Q.472 Q.473 Q.474 Q.475
Q.476 Q.477 Q.478 Q.479 Q.480 Q.481 Q.482 Q.483 Q.484
What is digital evidence? What is Hacking? What is leakage? How does the law define “illegal content”? How does the law deal with fraud using credit cards or e-payment tools? How are personal data breaches punished? Is spreading rumors or false news online a criminal offence? How does UAE deals with creating fake websites or online accounts? What enforcement powers do authorities have against illegal content? Are there offences related to privacy violations and secret disclosure? What special provisions exist for crimes against UAE national security? Can cybercrime cases be settled amicably? Do UAE Courts have jurisdiction over a website or over a cybercrime committed by a person outside the UAE? What types of financial crimes does the law cover? How does the law treat digital/virtual currencies? What is e-payment instrument fraud? How does the law treat gambling promotion? How does the law define cyber extortion or blackmail? How does the law treat internet fraud? What are Illicit Financial Flows (IFFs) and how are they linked to money laundering? How is unauthorized fundraising regulated? Can legal entities be liable for financial crimes?
I-67
317 317 318 318 318 318 318 319 319 319 319 320 320
321 321 321 321 321 322 322 322 322
Contents PAGE
Q.485 Q.486 Q.487 Q.488 Q.489 Q.490 Q.491 Q.492 Q.493 Q.494 Q.495 Q.496 Q.497 Q.498 Q.499 Q.500 Q.501 Q.502
What additional measures can courts impose besides fines and imprisonment? How much time frame is taken in UAE to file a criminal complaint with the court ? What measures can the court impose besides imprisonment and fines? What are the core compliance risks under this law for financial institutions? What due diligence is required for detecting illicit financial flows? How should banks and PSPs mitigate e-payment instrument fraud risk? How to ensure compliance when dealing with virtual or digital currencies? What compliance measures prevent unauthorized fundraising? How should compliance teams respond to cyber extortion cases involving customers? What are the corporate liability obligations (Art. 58)? What reporting duties apply for illegal online content linked to financial crime? What are necessary documents required for the purpose of the compliance for regulatory? What is the principal objective of the PDPL in the context of financial transactions? What is Personal Data under the PDPL? What constitutes Personal Data for financial sector purposes? Does the PDPL apply to all financial institutions? When may financial personal data be processed without consent? What is a Financial Data Controller?
I-68
323 323 324 325 325 325 325 325 326 326 326 326 326 327 328 328 328 329
Contents PAGE
Q.503 Q.504 Q.505 Q.506 Q.507 Q.508 Q.509 Q.510 Q.511 Q.512 Q.513
Q.514 Q.515
Q.516 Q.517 Q.518 Q.519
What are the core obligations of financial data controllers? What is a Processor in the financial context? What obligations do Processors have in financial services? How is cross-border transfer of financial personal data regulated? What breach notification duties apply to the financial sector? What rights do Data Subjects have over their financial personal data? What are the penalties for non-compliance in the financial sector? What are the steps for reporting financial crime in UAE? What are the common types of consumer Fraud and scams in UAE ? How To Report Fraud & Scams in UAE? What are key punishment including penalties for committing cybercrimes related to finance in UAE? How to initiate Financial Crime before the courts in United Arab Emirates ? What is the legal basis for collecting and processing client data under Anti Money Laundering Law (AML laws)? What types of personal data can be collected for AML compliance? Can sensitive or special category data be processed for AML purposes? Is client consent required for AML-related processing? Can personal data be shared with regulators or Financial Intelligence Units (FIUs)?
I-69
329 330 330 331 331 332 333 334 334 335 336
336 338
338 339 339 339
Contents PAGE
Q.520
Q.521 Q.522 Q.523 Q.524 Q.525 Q.526 Q.527
Q.528
Q.529
Q.530 Q.531 Q.532 Q.533 Q.534 Q.535
How long can AML data be retained in accordance to the ADGM Data Protection Regulation? What safeguards must be applied when handling AML data? How should data breaches involving AML information be handled? Are automated AML screening systems compliant? What are the penalties for non-compliance? How do UAE data privacy laws interact with AML/CTF compliance for virtual assets? Which kinds of personal data are at risk for a VASPs entities? Whether VASPs entities in the UAE are permitted to share client data with regulators or any international regulatory authority? How does the UAE ensure the security of personal data collected for financial crime compliance? What are the retention and deletion obligations and compliance for data collected relating to financial crime? What are the penalties for mishandling personal data in the virtual asset sector? How can VASPs prevent financial crime related to the data privacy obligations? What is the legal basis for processing personal data for AML purposes under DIFC Law? Is client consent required for processing data for AML compliance? What categories of personal data may be processed for AML purposes? How long should financial institutions retain personal data collected for AML purposes?
I-70
340
340 340 341 341 342 342 342
343
343
343 343 344 344 344 345
Contents PAGE
Q.536 Q.537 Q.538 Q.539
Q.540 Q.541
Can personal data collected be used for other activities such as marketing? How can financial institutions transfer AMLrelated data outside the DIFC? What are the obligations in case of breach involving AML information? What internal measures should financial institutions adopt to ensure compliance with both AML and data protection obligations? What penalties apply for non-compliance with DIFC data protection related to AML? How do the DIFC Data Protection principles align with AML compliance requirements?
345 345 346 346
346 347
CHAPTER 11 CYBER FRAUD VICTIM CHECKLIST: IMMEDIATE ACTIONS
Specimen Letter Important Case Laws Customer Protection - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions Master Circular on Credit Card, Debit Card and Rupee Denominated Card Customer Service - Reversal of Erroneous Debits Arising on Fraudulent or other Transactions Frauds in Banks Frauds in Banks - Monitoring of Deposit Accounts List of Cases Subject Index
I-71
353 359 362 369 372 374 375 377 383
3
CHAPTER
834=C8CH 10B43 2H14A >554=24B Adv. Kritika Sethi and Adv. Kshitija Baitalwar
In today’s increasingly digital world, identity is no longer restricted to physical documents; it exists extensively online across countless online platforms and services. From banking and shopping to learning, work, and social interactions, almost every aspect of life is linked to digital identity. Unfortunately, this digital footprint has become a prime target for cybercriminals. Identity-based cyber offenses are crimes where fraudsters steals or misuse personal information to impersonate individuals, gain unauthorized access to accounts, or commit fraud, often leading to significant financial losses and emotional distress. This chapter serves as a practical guide for every individual navigating the digital landscape. It explains the common methods cybercriminals use to steal and misuse identity, delves into the robust legal frameworks in India designed to provide protection, examines real-world case studies to understand victim pathways, and finally, equips individuals with essential prevention tools to help readers to protect their digital presence. Understanding these threats is the first crucial step towards building a secure, informed and resilient digital presence - one which empowers people to engage online without fear.
A. Methods and Threat Vectors This section explores the primary techniques cybercriminals employ to compromise and exploit identity in the digital realm. Understanding these methods is crucial for recognizing potential threats and taking proactive measures to safeguard personal information.
86
Identity-Based Cyber Offences
i. SIM Swap and Porting Frauds SIM swap fraud, also known as SIM hijacking or SIM splitting, is a sophisticated cybercrime where fraudsters gain control of a mobile number by tricking the telecom service provider. Once the scammer manages to control the number or SIM, they can intercept calls, messages, and crucial OneTime Passwords (OTPs), which are often used for two-factor authentication (2FA) to access sensitive accounts. This type of fraud can lead to significant financial losses and identity theft. Q.254. What is SIM swap fraud? Ans: SIM swap fraud is a type of cybercrime where fraudsters illegally takes control of an existing mobile phone number to a new SIM card. They commit this fraud by tricking the mobile service provider into transferring the mobile number to a new SIM card under their control by making them to believe that they are the legitimate subscriber, often by falsely claiming that the original phone or SIM card is lost or damaged. It allows the scammer to intercept calls and text messages, including one-time passwords (OTPs), and gain unauthorized access to the sensitive accounts such as banking, emails, or social media. Q.255. How do fraudsters trick telecom providers into performing a SIM swap? Ans: Fraudsters trick telecom providers into a SIM swap primarily through social engineering and exploiting weak authentication process. Fraudster gather a victim’s personal information before hand by convincingly impersonate the individual and persuade a telecom employee to transfer the phone number into a new SIM card under their control. This information is often acquired through phishing emails/ messages, social engineering or by purchasing illegal data. Armed with the data, the fraudster contact the service provider for SIM replacement, posing as a legitimate account holder. They use the victim’s stolen personal information to answer
87
Identity-Based Cyber Offences
security questions, bypass standard identity verification protocols, and convince the consumer service representative of their legitimacy. In some cases, fraudster may even bribe telecom employees to facilitate the unauthorized swap. To prevent such tricks, individuals should avoid sharing personal details and OTPs with unknown callers and activate simlocking or port-locking features to add a layer of protection. Q.256. What are the common signs that my SIM card might have been swapped? Ans: Common signs of a SIM swap include a sudden and unexpected loss of cell service on a device, an inability to make or receive calls and text messages, or receiving security alerts about SIM activation to an individual’s account. Individuals might find themselves unable to log into online accounts (such as banking or social media) or they may notice unusual transactions on bank statements. Additional waring signs includes receiving messages about SIM activation that you have not requested. If any such things occur, immediately contact your telecom provider to prevent further misuse. Q.257. What immediate dangers does SIM swapping pose to me? Ans: The most immediate danger is unauthorized access to a person’s financial and personal accounts. Since many online services utilize SMS-based OTPs for two-factor authentication, fraudsters who gain control of your OTP can intercept with these codes. Once the fraudster gain access to the victim’s number, they misuse it to reset passwords, unauthorized transaction from bank accounts, and access email and social media profiles, thus leading to severe financial losses and identity theft. In some cases, attackers misuse the victim’s identity to apply for loans, open new accounts, or impersonate the victim online to target friends and colleagues, extending risk to your digital reputation. To mitigate such risks, individuals should contact their telecom providers and alert their bank.
88
Identity-Based Cyber Offences
Q.258. How does Mobile Number Portability (MNP) relate to this fraud? Ans: Mobile Number Portability (MNP) is a legitimate feature that allows and help individuals to switch mobile service providers while retaining their existing phone number. But the process can be misused by fraudsters by exploiting this feature in “port-out scams” by tricking the victim’s current provider into porting their number to a new service account or device controlled by the fraudster. They leverage stolen personal information to convince the company that the request is legitimate as porting transfers full control of the number to the new SIM which enables the attackers to receive OTPs and account alerts. To reduce such risks, users should enable port-out protection offered by telecom operators, avoid sharing personal details, and treating sudden “porting request’ message as red flags requiring immediate action. Q.259. What techniques do fraudsters use to gather information for SIM swaps? Ans: Beyond social engineering and data breaches, fraudsters employ various techniques to collect information required for SIM – swap fraud. These include sending phishing emails or messages designed to trick individuals into revealing sensitive information, infecting devices with malware to harvest credentials, using fake identification documents, or even exploiting the mobile number portability process itself. Fraudsters often identify and target individuals with significant financial assets. Q.260. Can SIM swap fraud lead to unauthorized bank transactions? Ans: Yes, it can. In fact, unauthorized bank transactions is one of the primary objectives of SIM swap fraud. Once the fraudster gain access to the mobile number, he can bypass two-factor authentication system by intercepting OTPs and banking alerts sent to the hijacked phone number. This enables them to gain unauthorized access to bank accounts,
89
Identity-Based Cyber Offences
payment applications, or cryptocurrency wallets, allowing them to drain funds or make fraudulent online purchases. Q.261. Are there any specific measures taken by Indian regulators to prevent SIM swap fraud? Ans: Yes, the Telecom Regulatory Authority of India (TRAI) has implemented specific measures to prevent SIM swap such as a 7-day restriction on SIM porting after a new SIM is issued. This 7-day “cooling-off” period aims to make it tougher for fraudsters to hijack a number and aware the victim of such request via text message. Additionally, the Department of Telecommunications (DoT) has introduced an enhanced KYC protocols for SIM swap and replacement procedures and launched platforms like ‘Chakshu’ for reporting such suspicious and fraudulent telecom activities which helps to detect and prevent such scams more efficiently. Q.262. Why is relying solely on SMS-based two-factor authentication (2FA) risky against SIM swap fraud? Ans: Relying solely on SMS-based 2FA is risky because once fraudsters successfully gain control of your mobile number through a SIM swap, they can intercept the one-time passwords (OTPs) sent via text messages. This bypasses the security layer that 2FA is supposed to provide, allowing the attckers to gain access to your personal accounts simply by intercepting those codes even if you have a strong password. Q.263. What role does the human element play in SIM swap fraud? Ans: The human element plays a significant role in SIM swap fraud as fraudsters heavily rely on social engineering tactics to manipulate victims into revealing sensitive and personal information to facilitate unauthorized SIM changes. This means that human susceptibility to deception or corruption can be one of the weakest links in the security chain. To avoid such risks, individuals can reduce such risks by staying alert to unsolicited calls/messages and refusing to share sensitive
90
Identity-Based Cyber Offences
information. Additionally, telecom operator shall enforce strict verification and periodic training to minimize such risks. Q.264. What is a “port-out scam”? Ans: A “port-out scam” refers to a type of SIM swap fraud where criminals trick a victim’s current mobile service provider into transferring their phone number to a new service account or device controlled by the fraudster, exploiting the legitimate mobile number portability feature. This enables to fraudster to hijack calls, messages, and OTPs linked to the number. Q.265. What should I do if I suspect my phone service has suddenly stopped working without explanation? Ans: A sudden and unexpected loss of network (e.g., “No Service” or only 911 calls) is a primary warning indicator of SIM swap fraud. You should immediately contact your telecom provider from another phone or landline to block the compromised SIM and mobile number. Additionally, you should alert your bank for any unusual activity and temporarily freezing of high-risk transactions and change the passwords of your key account until you number is restored. ii. Deepfakes, Spoofing, and Identity Theft The digital age has introduced new frontiers for identity-based cybercrime, moving beyond simple data theft to sophisticated forms of digital impersonation. Deepfakes and various spoofing techniques represent a significant escalation in the methods criminals use to deceive and defraud. Q.266. What are deepfakes and how are they used in cybercrime? Ans: According to CERT-In, deepfakes are “synthetic media created using artificial intelligence (AI) to generate or manipulate realistic images, videos, and audio.”20 In cybercrime, Fraudster 20. CERT-In, Advisory on Deepfake Content, Advisory No. CIAD-2024-0060, available at:https:// www.cert-in.org.in/s2cMainServlet?VLCODE=CIAD-2024-0060&pageid=PUBVLNOTES02
91
Identity-Based Cyber Offences
use them to exploit human trust in visual and auditory information for various malicious activities, primarily social engineering, financial fraud, or disinformation campaigns. Q.267. Can you provide examples of deepfake incidents in India? Ans: Yes, notable incidents include a viral, manipulated video showing a woman with actress Rashmika Mandanna’s face entering a lift, which sparked a national outcry over nonconsensual synthetic media. Another prominent case involved a fake video of veteran investor Madhusudan Kela promoting a fraudulent investment scheme. This highlights how deep fakes can be used to mislead the public and leads to financial harm and erosion of trust. Such cases underscore the need to re-check suspicious videos, verify financial and investment claims directly from official sources and immediately report such manipulated content to cybercrime portals. Q.268. What is “spoofing,” particularly email spoofing? Ans: Spoofing is a technique where cybercriminals disguise their communication via email, phone call, or website to appear as if it originates from a trusted source. Email spoofing specifically involves sending an email with the forged sender address to deceive the recipient into believing it came from legitimate source. It is the act of forging the “From” address in an email to mislead the recipient about the actual sender. The end goal is to trick the recipient into taking harmful actions like clicking malicious link, download malicious malware, or revealing sensitive information. Q.269. How do cybercriminals carry out email spoofing attacks? Ans: Email spoofing is a threat that includes sending emails with a fake sender’s address. Cybercriminals carry out email spoofing by altering the emails “FROM” name displayed into a familiar one, make it look like the message came
92
Identity-Based Cyber Offences
from a trusted source. The Simple Mail Transfer Protocol (SMTP), which handles email delivery, lacks strong built-in authentication features, allows the attackers to bypass it and send message with a forged senders address. Through spoofed emails, fraudster heavily rely on social engineering tricks to scam the recipient by convincing the recipient that the message is real and the emails might carry a sense of urgency or links to fake websites to fraud recipient. To reduce such risks, users should always check the full email address, check links before clicking, and avoid downloading unsolicited attachments. Q.270. What is the difference between email spoofing and phishing? Ans: Email spoofing is an act of faking the sender’s email address, while phishing is a broader act of sending deceptive emails to trick recipient to reveal their sensitive information. Email spoofing is a threat that includes sending emails with a fake sender’s address. Phishing, on the other hand, is a broader social engineering attack that often use email spoofing as a method to steal sensitive information. Spoofing is a method used to make phishing attacks more believable. Q.271. What is identity theft in simple terms? Ans: Identity theft occurs when someone uses another person’s personal information—such as their name, address, credit card details, Aadhaar number, PAN, or even personal photographs—without their knowledge or consent, typically to commit fraud or other crimes. The primary goal is usually to gain illegal financial benefits or cause harm to the victim. Q.272. What are the different types of identity theft? Ans: Types of identity theft includes financial theft, medical theft, criminal theft, and child identity theft, which often carried out through digital methods. Common types of identity theft include:
93
Identity-Based Cyber Offences
Financial Identity Theft: The common type of identity theft uses unauthorized personal data to open accounts, obtain loans, or make unauthorized transactions.
Child Identity Theft: Using a child’s identity to access benefits, loans, or credit, often remaining undetected for years.
Criminal Identity Theft: Posing as another person during an arrest or to avoid legal consequences.
Synthetic Identity Theft: Combining real and fake information to create a new, fabricated identity.
Tax Identity Theft: Filing fraudulent tax returns using another person’s details.
Q.273. How do criminals typically obtain personal information for identity theft? Ans: Criminals acquire personal information through various illicit means Common methods include large-scale data breaches (where large datasets are leaked), purchasing stolen data from the dark web, using phishing or vishing scams to trick individuals to share sensitive details, ATM skimming (installing devices on ATMs to steal card details), and malware attacks that infect devices to steal data. Fraudulent emails, such as the “PAN 2.0 scam,” are also a significant vector to extract personal identifiers. Q.274. What is the “PAN 2.0 scam” and why is it dangerous? Ans: The “PAN 2.0 scam” is a specific phishing scam where fraudulent emails are circulated, falsely promising users an upgraded Permanent Account Number (PAN) card. These emails are designed to appear official, using forged seals and urgent language to pressurize the recipient. The email contains malicious links that redirect unsuspecting citizens to fake websites, which then prompt the fraudster to enter their PAN, Aadhaar, bank account details, and other personal
94
Identity-Based Cyber Offences
data, leading to identity theft and financial fraud. To stay safe, users should avoid clicking links in unsolicited emails and always verify information on the official government websites or portals. Q.275. Why are deepfakes considered a significant leap in cybercrime compared to traditional spoofing? Ans: Deepfakes are considered a significant escalation in cybercrime because they employ advanced artificial intelligence to produce highly convincing video, image, and audio impersonations, making it much more difficult to tell real from fake compared to traditional text or email based spoofing. Because deepfake content can mimic voice tone, facial expressions, lip sync, shadows and other subtle cues, making it much harder for the average person to distinguish genuine content from fabricated media, unlike older spoofing attempt which could often be spotted as spelling mistakes, grammar errors or suspicious email addresses that often exposed older spoofing schemes are no longer enough to reliably detect fraud. Q.276. What is the “media trust crisis” caused by deepfakes? Ans: The “media trust crisis” refers to the blurring of lines between fact and fabrication due to AI-generated content like deepfakes. Public begins to doubt the authenticity of what they see and hear online as fake AI manipulative videos, audio clips, and images became increasingly realistic. This leads to erosion of trust and undermines confidence in legitimate news, public figures, and institutions. To navigate such crisis, individuals should rely on verified news or portals and cross-check sensational content before sharing. Q.277. Why is personal identity information considered the “ultimate currency” in cybercrime? Ans: Personal identity information (like PAN, Aadhaar, bank details) is considered the ultimate currency because it is not
95
Identity-Based Cyber Offences
just a target in itself, but a primary enabler for a wide array of financial exploitation, including unauthorized transactions, opening fake accounts, and money laundering. Once the criminals/fraudsters obtains the relevant data, they can carry out unauthorized transactions, open fraudulent bank and loan accounts, or even engage in large scale money laundering. Q.278. What is “phishing” in the context of identity theft? Ans: Phishing is a social engineering attack where cybercriminals send deceptive messages (often emails) that appear to be from a trusted source to trick individuals into revealing sensitive personal information, such as login credentials, banking details, or personal identifiers, which is then be misused for identity theft or financial fraud. Q.279. How can individuals protect themselves from phishing scams like the “PAN 2.0 scam”? Ans: To protect yourself from phishing scams like the “PAN 2.0 scam”, always verify the sender’s email address (legitimate government emails end in .gov.in or .nic.in), avoid clicking suspicious links or downloading attachments from unexpected or urgent-looking messages, and access government services only through official government portals, add extra layer of security by enabling two-factor authentication, and report suspicious emails immediately and delete it to prevent any accidental clicks.
B. Legal Framework India has established a robust legal framework to combat identity-based cyber offenses, drawing from specialized cyber laws and traditional criminal statutes. Understanding these provisions is crucial for victims seeking justice and for individuals to comprehend the legal consequences of such crimes.
96
Identity-Based Cyber Offences
i. Information Technology Act, 2000 (Punishment for identity theft Sections 66C) (Penalty for breach of confidentiality and privacy Section 72) The Information Technology (IT) Act, 2000, is India’s primary legislation addressing cybercrime and electronic commerce. It contains specific provisions that directly address identity theft and the breach of digital privacy. Q.280. What does Section 66C of the Information Technology (IT) Act, 2000, address? Ans: Section 66C of the IT Act, 2000, specifically addresses “identity theft.” It penalizes anyone who dishonestly or fraudulently uses other person’s electronic signature, password, or any other unique identification feature such as biometrics, OTPs, or digital IDs. The provision aims to protect individuals’ digital identities from abuse and illegal access. Q.281. What is the punishment for identity theft under IT Act Section 66C? Ans: Whoever commits identity theft under Section 66C can be punished with imprisonment of either description for a term which may extend to three years, and shall also be liable to a fine which may extend to rupees one lakh (Rs. 1,00,000). Q.282. What does Section 72 of the IT Act, 2000, cover? Ans: Section 72 of the IT Act, 2000, deals with the “Penalty for Breach of confidentiality and privacy.” It states that any person who has gained access to any electronic record, book, register, correspondence, information, document, or other material in the course of their duties under the Act or its rules, discloses such information to another person without consent can be punished. This provision aims to safeguard the privacy of individuals, empower trust, and to
97
CYBER CRIMES & FINANCIAL OFFENCES – PRACTICAL SOLUTION AUTHOR : PUBLISHER : DATE OF PUBLICATION : EDITION : ISBN NO : NO. OF PAGES : BINDING TYPE :
AIFTP Taxmann December 2025 2026 Edition 9789375618140 464 Paperback
Rs. 1175 DESCRIPTION Cyber Crimes & Financial Offences – Practical Solution is a landmark publication addressing the growing intersection of technology, finance, and law in India's rapidly digitising economy. As financial systems, identity platforms, tax portals, and commercial transactions move online, the scale and complexity of cyber and financial offences have increased dramatically. Commissioned by the All India Federation of Tax Practitioners (AIFTP) and edited by Dr K. Shivaram, Senior Advocate, this book fills a critical gap by offering a single, authoritative reference that explains cyber and financial offences through a clear, practical Q&A-driven approach. The publication stands out for its broad scope, consolidating Direct Taxes, GST, PMLA, IT Act, Data Protection, Banking Regulations, E-commerce Liabilities, Employment Fraud, and International Cyber Law into one comprehensive resource. It equips professionals and citizens alike to recognise risks, respond effectively to cyber fraud, and implement robust compliance and preventive measures. The book is intended for the following audience: • Legal Practitioners • Chartered Accountants & Tax Professionals • Compliance Officers & Corporate Leaders • Banks, NBFCs, Payment Operators & Fintech Entities • Government Agencies, Cyber Crime Cells & Enforcement Authorities • Academicians, Students & Researchers • Citizens The Present Publication is the Latest Edition, commissioned by AIFTP and published exclusively by Taxmann. It is edited by Dr K. Shivaram and authored by Mr M.V. Purushottama Rao (CA), Mr Rahul Hakani (Advocate), Mr Sujeet S. Karkala (Advocate), Mr Aditya Ajgaonkar (Advocate), Ms Niyati Mankad Hakani (Advocate), Ms Kritika Sethi (Advocate), Mr Abhinav Tewari (Advocate), and Ms Kshitija Baitalwar (Advocate) with the following noteworthy features: • [Comprehensive Cross-domain Coverage] Cybersecurity, financial frauds, tax-related offences, e-commerce and employment fraud, PMLA issues, and international compliance • [Practical Q&A Format] Provides quick, actionable answers • [Immediate-use Tools] including: o Specimen letters to banks, regulators, and police o Fraud-victim action checklists o Preventive guidance for individuals and organisations o AML/PMLA red-flag indicators • [International Perspective (UAE Chapter)] Covers AML, data protection, VASP obligations, and cross-border rules • [Case Laws & Regulatory Materials] Includes RBI circulars, fraud monitoring guidelines, and key legal principles • [Focus on Public Awareness & Ethics] Supports national efforts toward digital safety
Buy Now