Cyber Crime, IT Act Basics and Digital Policing
Free study material · concepts, shortcuts & solved questions
Why This Chapter Matters
Crime has migrated online faster than most police forces have been able to build the specialised skills needed to chase it there, and Andhra Pradesh, with its large digitally connected population and growing base of online banking, e-commerce, and social media users, is squarely on the frontline of this shift. A constable stationed at a local police station today is at least as likely to receive a complaint about a fraudulent online transaction or a morphed photograph circulating on social media as a complaint about a stolen bicycle. This chapter equips the aspirant with a conceptual map of cybercrime categories, the legal framework built around the Information Technology Act, and the emerging discipline of digital forensics and digital policing — not as a specialist add-on, but as core, mainstream police work in 2026. Every serving officer, regardless of rank or posting, now needs at least a working fluency in this area, and examiners have responded by making cybercrime and IT Act questions a fixture of AP SI and Constable papers.
Part One — Understanding Cybercrime
Cybercrime is best understood not as a single offence but as a broad label for criminal conduct in which a computer, computer network, or digital device is either the target of the crime, the tool used to commit it, or the medium through which it is committed. This framing matters because it explains why cybercrime spans an enormous range — from a technically sophisticated attack on banking infrastructure to a comparatively low-tech scam conducted over a messaging app.
Major Categories of Cybercrime
- Phishing — the practice of sending fraudulent communications, typically emails, text messages, or messages on social media and messaging apps, that appear to come from a reputable source (a bank, a government department, a well-known company) in order to trick the recipient into revealing sensitive information such as passwords, card details, or one-time passwords, or into clicking a malicious link. Variants include "vishing" (voice-based phishing over phone calls) and "smishing" (phishing via SMS text messages).
- Identity theft — the unauthorised acquisition and use of another person's personal identifying information — Aadhaar details, PAN details, bank account information, or social media credentials — typically to commit fraud, open accounts, or impersonate the victim for financial or other gain.
- Financial fraud — a broad category covering online banking fraud, fraudulent investment and trading schemes, UPI-related scams, fake loan apps that harass and extort borrowers, and card-skimming or cloning operations. This category has grown enormously with the spread of digital payments and is now one of the highest-volume categories of cybercrime complaints received by police in India.
- Online harassment and cyberstalking — repeated, unwanted online contact, threats, or monitoring of a person, frequently gendered in its targeting, including circulation of morphed or non-consensual intimate images, doxxing (publishing a person's private information without consent), and coordinated online abuse campaigns.
- Hacking and unauthorised access — gaining unauthorised access to a computer system or network, whether to steal data, disrupt services, or plant malicious code, encompassing everything from website defacement to large-scale data breaches.
- Ransomware and malware attacks — malicious software that either damages, disrupts, or encrypts a victim's data and systems, in the case of ransomware typically demanding payment for restoration of access, posing a serious and growing threat to both individuals and institutions including hospitals, businesses, and government offices.
- Online child sexual abuse material and child grooming — the production, distribution, or possession of child sexual abuse material online, and the use of digital platforms to groom and exploit minors, treated with particular severity under Indian law given the vulnerability of the victims.
- Cyberterrorism — use of digital means to threaten the unity, integrity, security or sovereignty of India, or to strike terror by disrupting critical information infrastructure, treated as an especially grave category of offence given the potential scale of harm.
A police aspirant should notice a pattern across these categories: many of the most common forms of cybercrime encountered at the local police station level are not exotic, highly technical attacks but variations on old-fashioned deception and fraud, merely relocated to a digital medium. This matters practically because it means much of cybercrime investigation depends on the same fundamental investigative skills — tracing money trails, establishing identity, gathering corroborating evidence — that apply to any fraud investigation, supplemented by digital-specific techniques for tracing IP addresses, device identifiers, and transaction logs.
Part Two — The Information Technology Act: General Framework
The Information Technology Act, enacted in 2000 and substantially amended in 2008, is India's primary legislative framework governing electronic commerce, digital signatures, and cyber offences. Its foundational purpose, worth understanding clearly, was to give legal recognition to transactions carried out through electronic data interchange and other means of electronic communication — in other words, to ensure that electronic records and digital signatures would be treated as legally valid and enforceable, on par with paper documents and handwritten signatures, which was essential groundwork for enabling e-commerce, e-governance, and digital transactions to develop with legal certainty.
Two Distinct Functions of the IT Act
Aspirants should hold in mind that the IT Act performs two conceptually distinct functions, and confusing them is a common source of exam errors:
- An enabling function — recognising electronic records and digital/electronic signatures as legally valid, establishing the framework for certifying authorities that issue digital signature certificates, and enabling government departments to accept electronic filings and issue electronic licences and approvals. This is the "e-governance and e-commerce enablement" side of the Act.
- A penal function — defining specific cyber offences and prescribing punishments and compensation for them, covering matters such as unauthorised access to computer systems, data theft, spreading of computer viruses, denial-of-service attacks, cyberstalking-related conduct where it involves electronic means, publishing or transmitting obscene material electronically, and offences relating to identity theft and cheating by personation using computer resources. This is the "cyber offences" side of the Act, and it is this function that police most directly work with day to day.
The Act also created adjudicatory machinery — Adjudicating Officers empowered to decide compensation claims in certain categories of contraventions, and an appellate structure for cyber-related disputes — reflecting the recognition that not every IT Act matter is criminal in nature; some are civil disputes over compensation for data or financial loss caused by a contravention of the Act.
Relationship With the General Penal Law
An important conceptual point for aspirants: cybercrime investigation in India does not rely on the IT Act alone. Many offences that occur online — cheating, criminal intimidation, defamation, offences against women and children — are also offences under the general penal law, and in practice a cybercrime case frequently involves charges under both the IT Act and the ordinary penal code, since the electronic medium is often just the mechanism through which a conventional offence (fraud, harassment, extortion) has been committed. Recognising this dual applicability is essential: an aspirant should not think of "cybercrime law" as a wholly separate silo but as an overlay of medium-specific provisions layered onto the general criminal law framework covered in earlier chapters.
Jurisdiction and the Borderless Nature of Cybercrime
A structural challenge unique to cybercrime, and one worth understanding conceptually even without citing specific provisions, is that offences frequently cross state and even national boundaries — a victim in Andhra Pradesh may be defrauded by a perpetrator operating from another state or another country, using servers located in yet another jurisdiction. Indian law addresses this in part by giving the IT Act extraterritorial application in certain circumstances, recognising that a purely territorial approach would leave large categories of harm unaddressed. In practice, this cross-border character is precisely why cybercrime investigation depends heavily on coordination — between police stations across districts and states, and increasingly through dedicated national-level cybercrime coordination mechanisms and portals that allow victims to report incidents regardless of which police station has jurisdiction over the perpetrator's actual location.
Part Three — Digital Forensics and Digital Policing
As crime has moved online, so has the evidence that proves it, and digital forensics has emerged as an indispensable investigative discipline rather than a specialist afterthought. Digital forensics is the process of identifying, preserving, analysing, and presenting digital evidence — data found on computers, mobile phones, servers, cloud storage, and network logs — in a manner that is both technically sound and legally admissible.
Core Principles of Digital Evidence Handling
- Preservation of the original — digital evidence is inherently fragile and easily altered, whether accidentally or deliberately, so the foundational principle is to work from a verified forensic copy of the original data wherever possible, rather than the original device itself, precisely to avoid any allegation that the original evidence was tampered with during examination.
- Chain of custody — just as with physical evidence, every digital exhibit must be documented from the moment of seizure through every subsequent step of handling and analysis, with a clear, unbroken record of who accessed it, when, and why — a lapse here can be as damaging to a prosecution as a lapse in physical evidence handling.
- Certification of electronic evidence — as discussed in the previous chapter, electronic records generally require a certificate establishing their authenticity and the manner of their production before a court will rely on them, which is why proper documentation at the point of seizure and analysis is not an optional formality but a precondition for the evidence being usable at all.
- Hash verification — a common forensic practice is to generate a cryptographic hash value of the original data at the point of seizure, so that at any later stage it can be mathematically demonstrated that the analysed copy is identical, bit for bit, to the original — providing strong technical assurance against tampering claims.
What Digital Evidence Typically Looks Like
Common categories of digital evidence encountered in police investigations include call detail records and tower location data (useful for establishing a suspect's location and communication pattern at relevant times), IP address logs (useful for tracing the source of an online transaction or communication), transaction records from banks and payment platforms, social media account activity and message logs, device-level data recovered from mobile phones and computers, and metadata embedded in photographs, documents, and videos (which can reveal information such as the time, device, or even location of creation). Building a cybercrime case typically involves stitching together several of these sources into a coherent chain linking the accused to the offence, since any single source in isolation is rarely conclusive.
The Growing Institutional Response
Recognising the scale of the challenge, India has built dedicated institutional infrastructure for cybercrime response, including a national cybercrime reporting portal that allows citizens to report incidents online regardless of location, dedicated cybercrime police stations and cyber cells at state and district level (Andhra Pradesh, like other states, has built out dedicated cybercrime units), and coordination mechanisms aimed at rapidly freezing fraudulently transferred funds before they can be withdrawn — a capability that has become central to financial cybercrime response, since the window to intercept a fraudulent transaction before funds are dispersed across multiple accounts is often measured in hours, not days. For a constable or SI, understanding that a cybercrime victim's best chance of recovering money often depends on how quickly a complaint is escalated through these channels is a genuinely practical, examinable, and operationally important piece of knowledge.
Prevention and Public Awareness as a Policing Function
Digital policing in the current era extends beyond investigation after the fact into prevention and public awareness — police departments increasingly run outreach campaigns warning citizens about common scam patterns, publish advisories about emerging fraud techniques, and work with banks and telecom providers to build faster reporting and fund-freezing pipelines. This reflects a broader shift in police thinking: because so much financial cybercrime is difficult to fully reverse once funds have moved through several layers of accounts, prevention and rapid early intervention have become as important to the police function as after-the-fact investigation and prosecution.
The Investigative Workflow for a Typical Cybercrime Complaint
Understanding how a cybercrime complaint moves through the system helps an aspirant connect the conceptual material above to the practical reality of police work. When a victim reports, for instance, an online financial fraud, the general workflow typically follows this sequence: the complaint is registered, either at a police station or through the national cybercrime reporting portal, with the victim providing transaction details, screenshots, and any communication received from the fraudster; the investigating officer works with banks and payment platforms to trace the flow of funds, seeking to identify and freeze the accounts into which the money was transferred before it can be withdrawn or moved further; parallel to this, technical evidence is gathered — IP logs, device information, and account registration details associated with the fraudulent transaction or communication; and finally, once sufficient evidence links a specific individual or group to the offence, the case proceeds through the same investigation-to-trial pipeline covered in the CrPC chapter, with charges typically drawn from both the IT Act and relevant provisions of the general penal law.
The single most time-sensitive step in this entire sequence is the fund-freezing stage, because fraudulently obtained money in a digital ecosystem can move through multiple accounts within minutes, often ending up withdrawn as cash or converted into other forms that are much harder to trace and recover. This is precisely why victims are strongly encouraged to report financial cybercrime within the shortest possible window, and why coordination mechanisms between police, banks, and payment platforms have become such a central feature of effective cybercrime response.
Common Scam Patterns Relevant to Public Awareness Policing
Because prevention has become as central to digital policing as investigation, an aspirant should be familiar with the recurring scam patterns that police departments routinely warn the public about, since public-facing awareness work is itself part of the modern police function:
- Fake customs/courier scams — fraudsters posing as customs officials or courier companies claiming a parcel is held up and demanding payment of a fictitious fee or fine.
- Digital arrest scams — fraudsters impersonating police, enforcement, or investigative agencies over video or voice calls, falsely claiming the victim is under investigation and coercing them into transferring money under threat of arrest, exploiting fear of law enforcement itself as the manipulation tool.
- Fake job and work-from-home scams — offers of easy online earning that require an upfront "registration" or "task completion" payment, which is never recovered.
- Loan app harassment — unregulated lending apps that extend small, high-interest loans and then use access to a borrower's contacts and personal data (often granted through excessive app permissions) to harass and blackmail the borrower and their contacts.
- Sextortion — fraudsters lure victims into compromising video calls or image exchanges, then threaten to circulate the material unless a ransom is paid.
- QR code and UPI-collect scams — victims tricked into scanning a QR code or approving a "collect request," believing they are receiving money when they are in fact authorising a payment out of their own account.
Recognising these patterns matters for two reasons: it helps an officer quickly categorise an incoming complaint and identify the likely investigative trail, and it equips police for the public-awareness role that has become an explicit part of the modern digital policing mandate.
Reference Table — Cybercrime Categories and Typical Modus Operandi
| Category | Typical Method | Primary Harm |
|---|---|---|
| Phishing / Vishing / Smishing | Fraudulent email, call, or SMS impersonating a trusted source | Theft of credentials, OTPs, financial loss |
| Identity theft | Unauthorised use of stolen personal identifying information | Financial fraud, impersonation, reputational harm |
| Financial fraud | Fake investment schemes, loan apps, UPI scams, card cloning | Direct monetary loss |
| Online harassment / cyberstalking | Repeated unwanted contact, morphed images, doxxing | Psychological harm, reputational damage, safety risk |
| Hacking / unauthorised access | Breaching systems or networks without authorisation | Data theft, service disruption |
| Ransomware / malware | Malicious software encrypting or damaging data/systems | Operational disruption, extortion, financial loss |
Data Protection and Privacy — A Related, Emerging Dimension
Closely connected to cybercrime and digital policing is the broader question of data protection — how personal data collected by companies, government bodies, and platforms is stored, used, and protected from misuse. India has moved toward a dedicated comprehensive data protection framework in recent years, reflecting global regulatory trends and growing public concern about how personal data, once leaked or misused, can itself become the raw material for identity theft, financial fraud, and targeted harassment. For a police aspirant, the connection to cybercrime work is direct: data breaches at companies or institutions are frequently the upstream source of the personal information later used downstream by fraudsters in phishing and identity theft schemes, meaning that data protection and cybercrime enforcement are two sides of the same broader problem of safeguarding digital trust. Aspirants should understand this as a rapidly evolving policy area rather than assume any single settled framework, and should focus their exam preparation on the conceptual link — breaches upstream fuel fraud downstream — rather than on disputed statutory particulars.
Key Facts at a Glance
- Cybercrime is defined by the role of the computer or digital device as target, tool, or medium of the offence — not by any single legal category.
- The IT Act, 2000 (amended 2008), performs two distinct functions: enabling legal recognition of electronic records and signatures, and defining cyber offences with penalties.
- Most everyday cybercrime complaints at the police station level — phishing, financial fraud, harassment — are conventional offences (fraud, cheating, harassment) committed through a digital medium, and are typically prosecuted using both IT Act and general penal law provisions together.
- Digital evidence must be preserved through a verified forensic copy, maintained with an unbroken chain of custody, and generally certified for authenticity before a court will rely on it.
- Hash verification allows forensic examiners to prove an analysed copy of digital evidence is identical to the original, guarding against tampering claims.
- Rapid reporting is critical in financial cybercrime because the window to freeze fraudulently transferred funds before dispersal is typically very short.
- Cybercrime frequently crosses state and national jurisdictional boundaries, requiring coordination mechanisms beyond a single police station's ordinary territorial jurisdiction.
- Prevention and public awareness have become as central to digital policing as post-incident investigation, given the difficulty of fully reversing financial cybercrime once funds have moved.
Capacity Building — Why Every Officer Needs Basic Digital Literacy
A final point worth impressing on any aspirant: digital cases are no longer confined to dedicated cyber cells. A theft, a missing person case, or a domestic dispute today routinely generates digital leads — a suspect's phone location history, a WhatsApp conversation, a bank transfer confirming a motive. Departments across India, including in Andhra Pradesh, have accordingly invested in basic digital literacy training for general-duty officers, not merely specialist cyber units, precisely because the ordinary constable or SI handling a routine complaint is often the first point of contact where a digital lead either gets preserved and escalated correctly, or is lost through inexperience — a witness's phone not being examined promptly, a screenshot not being properly documented, a bank not being alerted quickly enough. This is the practical reason cybercrime and digital policing content occupies the space it does in a modern police recruitment examination: it is no longer specialist knowledge reserved for a cyber cell, but baseline professional competence expected of every officer.
Practice MCQs
- Cybercrime is best defined by:
(a) The nationality of the victim (b) The role of a computer or digital device as target, tool, or medium of the offence (c) The value of money involved (d) Whether it occurs during business hours
Answer: (b) — This functional definition covers the broad range of cyber-enabled and cyber-dependent offences. - "Smishing" refers to:
(a) Phishing conducted via SMS text messages (b) A type of malware (c) A category of ransomware (d) A digital signature certificate
Answer: (a) — Smishing is SMS-based phishing. - The Information Technology Act was originally enacted in which year?
(a) 1995 (b) 2000 (c) 2008 (d) 2012
Answer: (b) — The IT Act was enacted in 2000 and substantially amended in 2008. - A core enabling purpose of the IT Act is to:
(a) Ban all electronic communication (b) Give legal recognition to electronic records and digital signatures (c) Replace the Indian Penal Code entirely (d) Regulate only government websites
Answer: (b) — This was the Act's foundational enabling purpose for e-commerce and e-governance. - Most everyday cybercrime complaints received at local police stations are typically prosecuted using:
(a) Only the IT Act (b) Only the Indian Evidence Act (c) A combination of the IT Act and general penal law provisions (d) International treaties only
Answer: (c) — Since the underlying conduct (fraud, harassment) is also an offence under general penal law. - Digital forensics analysts typically work from:
(a) The original seized device only, without copying it (b) A verified forensic copy of the original data (c) A verbal description of the data (d) Random samples of unrelated data
Answer: (b) — Working from a verified copy preserves the integrity of the original. - A cryptographic hash value in digital forensics is used to:
(a) Encrypt communications between suspects (b) Prove an analysed copy is identical to the original data (c) Delete unwanted data (d) Identify the suspect's physical location
Answer: (b) — Hash verification provides technical proof against tampering claims. - Ransomware primarily works by:
(a) Sending harmless spam emails (b) Encrypting or damaging data/systems and demanding payment for restoration (c) Only stealing physical documents (d) Blocking a device's camera
Answer: (b) — Ransomware encrypts or disrupts systems, typically demanding a ransom. - Chain of custody in digital evidence handling refers to:
(a) A list of suspects in a case (b) An unbroken documented record of who accessed evidence, when, and why (c) A type of encryption key (d) A court's final judgment
Answer: (b) — This documentation is essential to establishing the evidence's reliability at trial. - Rapid reporting is especially critical in financial cybercrime cases because:
(a) Banks close permanently after fraud (b) The window to freeze fraudulently transferred funds before dispersal is typically very short (c) Police cannot investigate after 24 hours (d) It has no real urgency
Answer: (b) — Quick action increases the chance of intercepting funds before they are dispersed. - Which of the following best describes identity theft?
(a) Physically stealing a person's wallet (b) Unauthorised acquisition and use of another person's personal identifying information (c) A type of malware (d) A civil contract dispute
Answer: (b) — Identity theft involves misuse of someone else's personal identifying data. - The IT Act's penal function primarily covers:
(a) Only digital signature certification (b) Cyber offences such as unauthorised access, data theft, and identity theft-related conduct (c) Only e-commerce licensing (d) Traffic violations
Answer: (b) — This is the offence-defining and punishment-prescribing side of the Act. - Metadata embedded in a digital photograph can potentially reveal:
(a) Nothing useful to investigators (b) Information such as time, device, or location of creation (c) Only the file size (d) The victim's bank balance
Answer: (b) — Metadata can be a valuable source of investigative leads. - Cyberstalking and online harassment frequently involve:
(a) Only anonymous threats with no gendered pattern (b) Repeated unwanted contact, morphed images, or doxxing, often gendered in targeting (c) Exclusively financial transactions (d) Only offences committed by government employees
Answer: (b) — This category frequently disproportionately targets women and involves the described conduct. - A key institutional response to cybercrime in India includes:
(a) Banning all internet access (b) A national cybercrime reporting portal and dedicated cyber cells/police stations (c) Removing police involvement entirely (d) Relying solely on private companies
Answer: (b) — India has built dedicated reporting and investigative infrastructure for cybercrime.