What Is Cyber Crime? Meaning, Categories and Channels
Cyber crime is an umbrella label, not one offence. Here's what it covers and how the law actually charges it.
Cyber crime is any crime where a computer, phone or network is either the tool used to commit it or the thing attacked. A fraudster who calls a customer pretending to be from the bank's KYC team and talks him into reading out an OTP has committed a cyber crime. So has a gang that breaks into a co-operative bank's server and alters account balances.
For a banker the working definition matters more than a textbook one: if money, data or access was taken through a digital channel, treat it as a cyber crime, preserve the evidence, and route it through the bank's fraud and incident process.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
What the Law Says (and Doesn't)
No Indian statute defines "cyber crime" as a single term. The Information Technology Act, 2000 defines "cyber security" and then lists specific offences in Chapter XI: tampering with source code (section 65), computer related offences (section 66), identity theft (66C), cheating by personation using a computer resource (66D), cyber terrorism (66F) and others. The Bharatiya Nyaya Sanhita, 2023 (BNS), which replaced the Indian Penal Code from 1 July 2024, covers the rest: cheating, extortion, forgery of electronic records, stalking. BNS section 111 names "cyber-crimes" among the activities that can make up organised crime.
So "cyber crime" is an umbrella label. In an FIR, the actual charge is always a specific section of the IT Act, the BNS, or both.
Computer as Target vs Computer as Tool
The standard way to classify a cyber crime, with banking examples.
Computer as target
What it means
The attack is on the system or data itself
Banking example
Ransomware that encrypts a bank's branch servers; a DDoS attack that takes net banking offline
Computer as tool
What it means
A familiar crime (theft, cheating, extortion) committed through a digital channel
Banking example
A fake KYC call that ends in an OTP being shared and money moved by UPI
Computer as incidental
What it means
The device only holds evidence of an ordinary crime
Banking example
A loan fraudster's laptop holding forged salary slips
| Category | What it means | Banking example |
|---|---|---|
| Computer as target | The attack is on the system or data itself | Ransomware that encrypts a bank's branch servers; a DDoS attack that takes net banking offline |
| Computer as tool | A familiar crime (theft, cheating, extortion) committed through a digital channel | A fake KYC call that ends in an OTP being shared and money moved by UPI |
| Computer as incidental | The device only holds evidence of an ordinary crime | A loan fraudster's laptop holding forged salary slips |
Channels of Cyber Crime
Unit 2 asks where attacks come in. These are the routes a branch sees most.
- Voice calls
- Vishing: a caller posing as the bank, a regulator or the police. Still the most common entry point for retail fraud.
- SMS and messaging apps
- Smishing links, fake KYC-expiry alerts, and screen-sharing app invitations.
- Phishing at customers, and business email compromise at corporate clients who change a vendor's account number on a forged instruction.
- Websites and apps
- Look-alike net banking pages, fake loan apps, and malicious apps that read SMS (and so read OTPs).
- Physical devices
- Skimmers and pinhole cameras on ATMs, infected USB drives, and stolen phones.
- Insiders
- Staff with legitimate access who misuse it, or who are tricked into helping an outsider.
Quick practice on banking operations. No signup.
Why Cyber Crime Is Hard to Police
- check_circleReach: the IT Act (section 75) applies to an offence committed outside India by anyone, of any nationality, if it involves a computer system located in India. Enforcing that abroad is another matter.
- check_circleSpeed: stolen money is split across many mule accounts within minutes, which is why the 1930 helpline exists to trigger fast holds.
- check_circleEvidence is fragile: logs get overwritten and phones get wiped, so the first hours decide whether a case can be proved.
- check_circleRank of investigator: offences under the IT Act must be investigated by a police officer not below the rank of Inspector (section 78).
How the IIBF Exam Tests This
Expect definition-level MCQs: which category an example falls into (target vs tool), which channel an attack used, or which statute an offence sits in. The common trap is treating "cyber crime" as a defined legal term with one punishment. It isn't. A second trap: options built on section 66A of the IT Act. The Supreme Court struck it down in 2015 (Shreya Singhal), so it is never the correct answer for a live offence.
FAQs
What is cyber crime in simple words?expand_more
A crime committed using a computer, phone or network, or aimed at one. Online banking fraud, hacking, phishing, ransomware and cyber stalking are all cyber crimes.
Is cyber crime defined in the IT Act, 2000?expand_more
No. The IT Act defines "cyber security" and lists specific offences (sections 65 to 67B and others), but has no single definition of cyber crime. The BNS covers offences like cheating and extortion when done online.
Who investigates cyber crime in India?expand_more
The police, usually a state cyber crime cell. For IT Act offences, the investigating officer must be at least an Inspector. Citizens report through the 1930 helpline or the national cyber crime reporting portal.
Can someone abroad be punished under Indian cyber law?expand_more
The IT Act says yes if the offence involves a computer system located in India (section 75), whatever the offender's nationality. In practice that depends on international cooperation.
Next steps
- Types of Cyber Crimearrow_forward
- IT Act 2000arrow_forward
- Reporting Cyber Crimearrow_forward
- Syllabusarrow_forward
120 questions, 2 hours, scored instantly.
