Q.Rohit receives an email that looks like it is from his bank, asking him to click a link and "verify" his net-banking password and debit card PIN because of a "security update". He clicks the link, enters his details on the page that opens, and later finds ₹45,000 missing from his account. As a student of Cyber Law, identify the cybercrime involved and explain how Rohit could have protected himself. (Supplementary practice content — the real Semester II paper for this unit is Short-Answer only; Case Problems build the deeper apply-the-rule reasoning the SAQ format cannot fully test.)
The cybercrime involved here is Phishing. As Section b explains, phishing is a fraudulent attempt — typically a deceptive email, message, or fake website impersonating a genuine organisation — designed to trick a person into revealing sensitive information such as passwords, PINs, or card details. Rohit's bank did not actually send the email; a wrongdoer impersonated the bank, created a false sense of urgency ('security update'), and directed Rohit to a fake page designed to look like his bank's genuine site. Once Rohit entered his password and PIN there, the wrongdoer had everything needed to access his account and transfer the ₹45,000 out — this is also, more specifically, an instance of identity/data theft as covered under the scope of Cyber Law (Section c), and would typically be prosecuted under Section 66D of the Information Technology Act, 2000 (cheating by personation using a computer resource).
Rohit could have protected himself in several concrete ways, drawn from Section d's cyber-safety practices:
- Never click a link in an unsolicited email claiming to be from a bank; instead, always type the bank's known web address directly into the browser or use the bank's official app.
- Never enter a full password, PIN, or OTP on any page reached through an email or message link, since a genuine bank will never ask for these details this way.
- Verify directly with the bank (using a phone number or address independently obtained, not one given in the suspicious email) before acting on any message claiming urgent 'security' action is required.
- Report the suspicious email to the bank and, where funds have already been lost, report the incident promptly to the bank and to the appropriate cybercrime reporting channel, since prompt reporting can sometimes allow a fraudulent transaction to be reversed or blocked.
The cybercrime is Phishing (leading to identity/data theft and an unauthorised funds transfer, typically an offence under Section 66D of the IT Act, 2000). Rohit could have protected himself by never entering banking credentials through a link in an unsolicited email, accessing his bank only through its known official website/app, never sharing a password/PIN/OTP with anyone, and verifying independently before acting on any 'urgent security' message.
Unlock everything free for 14 days
- Full step-by-step solutions
- Concept-first explanations
- Methods, shortcuts & mistakes
- PYQ mapping + timed mock tests
Full access for 14 days. No credit card required.