Types of Cyber Crime: A Map for Bankers
Nine crime types, grouped by who gets hurt, each with the law that applies.
Cyber crimes are easiest to learn in families: crimes against people, crimes against property and money, crimes against systems and data, and crimes against the state. A bank sees all four, though most branch-level complaints fall in the second family: a customer who lost money to a fake KYC call, a UPI collect request, or a cloned card.
This page is the map. Each crime below has its own page with how it works, how to spot it and the exact legal provisions.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Main Types at a Glance
Statutes shown are the ones most often invoked. A single incident usually attracts more than one.
Phishing, vishing, smishing
What happens
Fake email, call or SMS tricks the victim into giving credentials or an OTP
Main provisions
IT Act 66C, 66D; BNS 318, 319
Social engineering
What happens
Manipulating people (pretexting, baiting, tailgating) rather than breaking technology
Main provisions
Depends on the result: IT Act 66, 66D; BNS 318
Hacking
What happens
Unauthorised access to or damage of a computer system
Main provisions
IT Act 43 (compensation), 66 (offence)
Identity theft
What happens
Using someone else's password, electronic signature or other unique ID
Main provisions
IT Act 66C; BNS 319
Ransomware and cyber extortion
What happens
Data locked or stolen, payment demanded under threat
Main provisions
IT Act 43, 66; BNS 308
Cyber stalking
What happens
Repeated unwanted contact or monitoring of someone's online activity
Main provisions
BNS 78; IT Act 66E or 67 where images are involved
Cyber squatting
What happens
Registering a domain name that copies a brand, to sell it or to defraud
Main provisions
Trade mark law and passing off; domain dispute policies
Cyber terrorism
What happens
Attacks on systems to threaten India's security or strike terror
Main provisions
IT Act 66F; s.70 for protected systems
Cyber warfare
What happens
State-backed attacks on another state's systems
Main provisions
International law; IT Act 66F and 70 domestically
| Crime | What happens | Main provisions |
|---|---|---|
| Phishing, vishing, smishing | Fake email, call or SMS tricks the victim into giving credentials or an OTP | IT Act 66C, 66D; BNS 318, 319 |
| Social engineering | Manipulating people (pretexting, baiting, tailgating) rather than breaking technology | Depends on the result: IT Act 66, 66D; BNS 318 |
| Hacking | Unauthorised access to or damage of a computer system | IT Act 43 (compensation), 66 (offence) |
| Identity theft | Using someone else's password, electronic signature or other unique ID | IT Act 66C; BNS 319 |
| Ransomware and cyber extortion | Data locked or stolen, payment demanded under threat | IT Act 43, 66; BNS 308 |
| Cyber stalking | Repeated unwanted contact or monitoring of someone's online activity | BNS 78; IT Act 66E or 67 where images are involved |
| Cyber squatting | Registering a domain name that copies a brand, to sell it or to defraud | Trade mark law and passing off; domain dispute policies |
| Cyber terrorism | Attacks on systems to threaten India's security or strike terror | IT Act 66F; s.70 for protected systems |
| Cyber warfare | State-backed attacks on another state's systems | International law; IT Act 66F and 70 domestically |
Grouped by Who or What Is Harmed
- Against individuals
- Cyber stalking, harassment, identity theft, sextortion, morphing of photographs, privacy violations.
- Against property and money
- Phishing and online banking fraud, card fraud, UPI fraud, investment scams, cyber cheating.
- Against systems and data
- Hacking, malware and ransomware, denial of service, database theft, website defacement, source code tampering (IT Act section 65).
- Against society and the state
- Cyber terrorism, cyber warfare, attacks on critical information infrastructure such as banking and payment systems.
Quick practice on banking operations. No signup.
What Banks Are Required to Report
CERT-In's April 2022 Directions list the incident types organisations, including banks, must report to CERT-In within 6 hours of noticing them. The list doubles as a practical taxonomy. It includes:
- check_circleUnauthorised access of IT systems or data, and compromise of critical systems
- check_circleMalicious code attacks: virus, worm, Trojan, bots, spyware, ransomware, cryptominers
- check_circleIdentity theft, spoofing and phishing attacks
- check_circleDenial of Service (DoS) and Distributed Denial of Service (DDoS) attacks
- check_circleData breach and data leak
- check_circleAttacks or incidents affecting digital payment systems
- check_circleAttacks through malicious mobile apps, and fake mobile apps
- check_circleUnauthorised access to social media accounts
How the IIBF Exam Tests This
The syllabus lists crimes in pairs (stalking and cyber squatting, extortion and cheating, warfare and terrorism, phishing and hacking), and the paper tends to test the difference within a pair. Typical MCQ: a short scenario followed by four crime names. The trap is choosing the channel instead of the crime. A fraud done over a phone call is vishing; the same caller pretending to be a named bank officer is also cheating by personation. Read what was actually taken and how.
FAQs
What are the main types of cyber crime?expand_more
Phishing and its phone and SMS variants, social engineering, hacking, identity theft, ransomware and cyber extortion, cyber stalking, cyber squatting, cyber terrorism and cyber warfare. Malware, card fraud and UPI fraud are usually covered as methods or channels within these.
Which is the most common cyber crime against bank customers?expand_more
Fraud that starts with a phone call or message: the victim is persuaded to share an OTP, approve a UPI request, or install a screen-sharing app. The technology is rarely broken; the customer is.
Is cyber cheating a separate offence?expand_more
There is no offence called "cyber cheating". Cheating is charged under BNS section 318 (formerly IPC sections 415 and 420), and cheating by personation using a computer resource under IT Act section 66D.
What is the difference between cyber terrorism and cyber warfare?expand_more
Cyber terrorism is an offence under IT Act section 66F, committed by any person to threaten India's security or strike terror. Cyber warfare refers to attacks by or for a state against another state, governed mainly by international law.
Next steps
- What Is Cyber Crimearrow_forward
- Phishing, Vishing, Smishingarrow_forward
- Hacking & Hackersarrow_forward
- Syllabusarrow_forward
120 questions, 2 hours, scored instantly.
