BNS & The IT Act: Everything You Need to Know About Cybercrime Law in India

Kritika Verma
GLA Student Intern, PlanetLex Law Firm
(Legal Awareness Article)
Published: 26 September 2026

Cybercrime law in India: BNS and the Information Technology Act

Introduction: Understanding Cybercrime in India

Cybercrime describes unlawful conduct in which computers, phones, networks, online accounts or electronic communications are used as a target, a tool, or a means of carrying out an offence. It may involve a financial scam, misuse of personal information, unauthorised access, harassment, threats, or prohibited electronic material. The legal character of an incident depends on what happened, the evidence available, the people involved and the applicable law; the label “cybercrime” alone does not decide the charge.

How the Bharatiya Nyaya Sanhita Relates to Cyber Offences

The Bharatiya Nyaya Sanhita, 2023 (BNS) is India’s general criminal law framework. It can be relevant when conduct carried out online also has the elements of an offence recognised by general criminal law. Depending on the facts, this may include cheating, cheating by personation, stalking involving monitoring a person’s use of the internet or electronic communications, criminal intimidation, or other offences. The BNS does not turn every online dispute or unwanted message into a crime: the ingredients of the particular offence must be assessed and established.

For example, a person who uses a false online identity to obtain money may raise questions of cheating or personation under the BNS, while persistent electronic monitoring or threats may call for a different legal analysis. These are illustrations only. Whether any BNS provision applies depends on the conduct, intent, available evidence and applicable statutory requirements.

The Information Technology Act, 2000

The Information Technology Act, 2000 (IT Act) addresses specified conduct involving computer resources and electronic activity. Its provisions may be relevant to unauthorised access or damage to computer systems, computer-related offences, identity theft, cheating by personation using a computer resource, violation of privacy, and certain categories of prohibited electronic content. The precise provision and its elements must be checked against the current Act and the facts of the incident.

The IT Act is not a substitute for every general criminal offence, and the BNS is not a substitute for every technology-specific rule. Investigators and courts consider the conduct and the legal ingredients involved. Where the facts support it, provisions of the BNS and IT Act may be examined in relation to the same sequence of events, subject to the law’s requirements and safeguards. It is inaccurate to assume that every cyber offence is covered only by one of these Acts.

Common Cyber Offences and Online Misconduct

Common reports include payment and investment fraud, phishing, impersonation, identity misuse, account takeovers, unauthorised access to devices or accounts, cheating through electronic communication, cyber harassment, stalking, threats, and circulation of unlawful electronic material. Some incidents may involve civil, contractual, consumer, data-protection or other regulatory issues rather than—or in addition to—a criminal offence. Classification depends on the actual facts and applicable law.

A disputed transaction, rude message, failed online purchase or account restriction is not automatically a criminal offence. Relevant questions can include whether deception or dishonest intent is alleged, whether access was authorised, what information was obtained or altered, whether threats or repeated unwanted monitoring occurred, and who controlled the relevant account or device.

How the BNS and IT Act May Apply to the Same Facts

Consider an online impersonation used to induce a person to transfer funds. The alleged deception may require analysis under general criminal law, while the use of a computer resource or misuse of identity information may call for consideration of the IT Act. In another matter, access to an account without permission may raise technology-specific issues, and accompanying threats or extortionate conduct may require a separate criminal-law assessment.

These examples do not determine liability or identify charges for a particular person. Each provision has its own legal elements, and the same facts can be viewed differently as evidence develops. Any statutory provisions should be considered only as applicable to the facts of the case, and by the competent authorities and courts.

Preserving Digital Evidence

Digital evidence can be temporary and can be altered by routine device or account activity. Preserve original messages, emails with available headers, profile names and URLs, transaction references, bank notifications, call logs, screenshots, files and relevant dates. Keep the original device and files where possible; avoid editing, cropping or annotating the only copy. Record when and how material was obtained, and make a separate backup without changing the original.

Do not attempt to access another person’s account, confront a suspected offender in a way that could increase risk, or publish sensitive evidence online. Share relevant material through official reporting or investigation channels and follow directions about preservation and forensic handling. A screenshot can be useful, but it may not by itself establish authenticity, context or who controlled an account.

Reporting Options and Practical Remedies

For suspected cybercrime, a person may submit a report through India’s National Cyber Crime Reporting Portal or approach the local police or cybercrime police station. The national portal includes a route for reporting financial cyber fraud; where money has just been transferred, promptly contact the bank or payment provider and use the official reporting channel. For immediate danger, threats or an ongoing offence, contact local police or emergency services rather than relying only on an online form.

Also secure affected accounts from a trusted device: change compromised credentials, enable multi-factor authentication, revoke unknown sessions, notify the relevant platform and preserve its acknowledgement or complaint reference. Depending on the circumstances, remedies may include a police complaint, investigation, account or content reporting, bank/payment-provider action, or appropriate civil and regulatory steps. Outcomes and timelines depend on the facts and the authority handling the matter.

When to Consult a Cyber Crime Lawyer

Consider consulting a lawyer when significant money or sensitive data is involved, an account or device has been compromised, threats or repeated harassment continue, a police notice or complaint has been received, evidence may be lost, multiple jurisdictions are involved, or you are unsure how to respond as a complainant or an accused person. A lawyer can review documents, explain available procedures, help preserve and present material appropriately, and advise on steps suited to the facts.

Conclusion

Cybercrime matters often require both a careful account of the digital events and a precise legal analysis. The BNS may address general offences committed through online conduct, while the IT Act contains provisions directed to specified activity involving computer resources and electronic content. Preserve original evidence, report through appropriate channels, and seek qualified advice where the consequences or legal position are unclear.

References and Reporting Resources

Legal-awareness disclaimer: This article is for general educational information only. It is not legal advice, does not address any individual facts, and does not create an advocate-client relationship. Laws and official procedures may change; consult a qualified lawyer for advice on a specific matter.

Kritika Verma

About the Author:

Kritika Verma is a GLA Student Intern at PlanetLex Law Firm. Her legal-awareness work focuses on making Indian legal frameworks and public reporting processes easier to understand.

Core Areas of Interest
  • Cyber Law: Legal awareness around online offences, technology-related laws and digital evidence.
  • Legal Research: Reading statutory frameworks and explaining general legal concepts.
  • Public Legal Education: Sharing accessible information about reporting options and legal processes.

Disclaimer: This article is intended for general legal awareness and informational purposes only. It does not constitute legal advice and does not establish an advocate-client relationship.