Hacking and the Types of Hackers
The same technique is a security test with permission and a crime without it.
Hacking means getting into a computer system, network or data without permission, or going beyond the access you were given. The word covers everything from a teenager guessing a weak password to an organised group sitting quietly inside a bank's network for months before moving money through the payment system.
Not every hacker is a criminal. Banks hire ethical hackers to break into their own systems before someone else does. The difference is authorisation: the same technique is a security test with written permission and an offence without it.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Types of Hackers
- White hat (ethical hacker)
- Tests systems with the owner's written permission and reports flaws so they can be fixed. Banks use them for penetration testing and red-team exercises.
- Black hat
- Breaks in without permission for gain or damage: stealing data, planting ransomware, siphoning money.
- Grey hat
- Breaks in without permission but without clear malicious intent, often to point out a flaw. Still unauthorised access, and so still exposed to the law.
- Script kiddie
- An unskilled attacker using ready-made tools written by others. Low skill does not mean low damage.
- Hacktivist
- Attacks for a political or social cause, typically through website defacement or denial of service.
- State-sponsored hacker
- Works for or with a government. Targets include banks and payment systems for espionage, disruption or funds.
- Insider
- An employee or contractor who misuses legitimate access. Often the hardest to detect because the access looks normal.
How an Attack Usually Unfolds
Knowing the stages tells you where a control can break the chain. This is the defender's view, not a method.
- 1
Reconnaissance
The attacker gathers information: staff names from social media, exposed services, leaked passwords.
- 2
Initial access
Most often through a phishing email, a stolen password, or an unpatched internet-facing system.
- 3
Escalation and movement
From one user's machine to administrator rights, and from there towards high-value systems such as the core banking or payment gateway.
- 4
Action on objective
Stealing data, altering records, initiating fraudulent transfers, or deploying ransomware.
- 5
Covering tracks
Deleting or altering logs. This is why log retention and protected log storage matter for investigation.
Quick practice on banking operations. No signup.
What the IT Act Says
Section 43 of the IT Act lists the acts: accessing a computer system without permission, downloading or copying data, introducing a virus, damaging data, disrupting a system, denying access to authorised users, and stealing or altering source code, among others. On its own, section 43 makes the person liable to pay compensation to whoever was harmed.
Section 66 turns those same acts into a crime when done dishonestly or fraudulently: imprisonment up to 3 years, or a fine up to ₹5 lakh, or both. Accessing or attempting to access a notified protected system (section 70) is far more serious, with imprisonment up to 10 years and a fine. Older books describe section 66 as "Hacking with computer system". That was its title in the original 2000 Act; the 2008 amendment, in force from 27 October 2009, replaced it with the current "computer related offences" wording.
How the IIBF Exam Tests This
Expect questions on hacker categories (which one has permission), and on the civil-versus-criminal split: section 43 means compensation, section 66 means punishment, and the difference is dishonest or fraudulent intent. The trap is an option quoting the old "hacking" wording of section 66 as the current title, or picking grey hat as lawful because the intent was good. Without permission, access is unauthorised.
FAQs
What is the punishment for hacking under the IT Act?expand_more
Under section 66, doing any act listed in section 43 dishonestly or fraudulently is punishable with up to 3 years' imprisonment, a fine up to ₹5 lakh, or both. The victim can also claim compensation under section 43.
Is ethical hacking legal in India?expand_more
Testing a system with the owner's clear, written authorisation is how banks run penetration tests. The same activity without permission is unauthorised access under sections 43 and 66 of the IT Act.
What is the difference between white hat, black hat and grey hat hackers?expand_more
White hats test with permission to fix flaws. Black hats break in for gain or harm. Grey hats break in without permission but without clear malicious intent; their access is still unauthorised.
Is hacking a bailable offence?expand_more
Under section 77B of the IT Act, offences punishable with 3 years' imprisonment are bailable, and offences punishable with 3 years and above are cognizable. Section 66 carries up to 3 years, so it is both bailable and cognizable.
Next steps
- Section 66 Offencesarrow_forward
- Section 43 & 43Aarrow_forward
- Database Hackingarrow_forward
- Malware Typesarrow_forward
120 questions, 2 hours, scored instantly.
