CYBER TERRORISM UNDER THE INFORMATION TECHNOLOGY ACT
- sonalimukhia2002
- Jul 12
- 8 min read
Author: Sudarshana Panchariya, BM Law College, Jodhpur
Introduction
There is no doubt that the advancement of technology has positively impacted society. However, it has also provided an easier way to conduct illegal acts and has made instances of international and national terrorism grow and evolve. Cyber terrorism is the latest form of concern, as it has made the threats to national security and instilling fear in the populace no longer an issue of fantasy. During the Mumbai Terror Attack, the terrorists used various digital communication tools to organize. Following that incident, along with the other terror acts occurring in various regions, the parliament included Section 66F in the Information Technology Act of 2000. This act made terrorism of a digital nature an offense in India and reserved life imprisonment as punishment. This article analyses the structure and scope of Section 66F and attempts to describe the challenges that section and other national security laws face in their interpretation and enforcement. This analysis aims to show that while Section 66F was an important step that India had to take to respond to a new threat, it also has several outdated and narrow gaps in relation to Cyber Terrorism that the country lacks.
The Statutory Framework
Section 66F prohibits two distinct types of conduct. The first type (subpart (A)) is applicable to individuals whose actions, with intent to threaten the unity, integrity, security or sovereignty of India, strike terror into the citizens of India, and include, among other actions, by denying access to an authorized user of a computer resource, penetrating or accessing a computer resource without authorization, or by introducing a computer contaminant; such conduct must cause or be likely to cause bodily harm or death to persons and/or cause damage to property; and/or disrupt essential supplies and/or services; and/or have an adverse impact upon Critical Information Infrastructure (as defined by Section 70 of the Act). The second type of conduct (subpart (B)) is applicable to individuals who know or intentionally access a protected computer resource without authorization to obtain information that is restricted from them for reasons relating to the security of the State and that is likely to be used to inflict injury to the sovereignty, integrity and/or security of India or its relationship with foreign nations.
A higher degree of intent is required to establish an offence under Section 66F than for the offences of hacking or unauthorised access to information systems under sections 43 and 66 of the Act. The prosecution must prove that the unauthorized access was executed with the intention of threatening India's sovereignty or causing terror to the people of India. Courts have repeated the requirement for a sufficiently high burden of proof to restrict the application of the provision, which can carry a life sentence, to only the most serious of cyber crimes as opposed to everyday hacks or simple data thefts.
Section 70 of the Act defines Critical Information Infrastructure as any computer resource whose incapacitating would negatively affect any one of three areas; (1) National Security, (2) Public Health, and (3) A weakened economy. A portion of the practical force of Section 66F is given through this paragraph of the Act. The sectors included under this protective umbrella of Section 66F include; banking, power generation, telecommunications, healthcare, and defence. The nodal agency responsible for the protection of Critical Information Infrastructure in the National Critical Infrastructure Protection Agency; therefore any attack upon the critical infrastructure of either a power grid or a bank's computer network intended to induce panic or instability in the government, is squarely within the purview of Section 66F of the Act. However, any attack against a private person's social media account no matter how serious that attack may be will not ordinarily be described as being within the purview of Section 66F of the Act.
Similarities between UAPA and IT Act
A variety of laws have been enacted in India to deal with terrorism since 1967; the Unlawful Activities (Prevention) Act (UAPA) is the most powerful of them. The definition of terrorist acts in section 15 of UAPA is vague but includes this: "a terrorist act that threatens the unity, integrity, security or sovereignty of India." The UAPA's extensive list of potential methods of committing terrorism (for example, explosives, firearms, and chemical agents) has a great deal of overlapping language with section 66F(2) of the IT Act. This overlap both in wording as well as in substance is a basis for law enforcement agencies to prosecute cybercriminals, whether they are prosecuted under UAPA or IT Act. When law enforcement investigates and prosecutes cyber attacks committed by terrorist organizations or in connection with a larger terrorism conspiracy, both UAPA and IT Act section 66F can be used. This will benefit from UAPA's strict bail and long periods of review, while at the same time being able to be prosecuted only on the basis of UAPA's description of the crime.
The dual use of these legal definitions is not simply to aid prosecutors; it is also an indication of the fact that there is a lack of certainty in the way that Indian law regards cyberterrorism as a free standing crime as opposed to being included in the broader definition of terrorism or as part of a terrorism conspiracy. The second amendment made to the NIA Act in 2019 was enacted to provide the NIA with the authority to investigate offences as defined by Section 66F and therefore incorporated cyberterrorism into the larger counter-terrorism architecture. Although the NIA Act provides for the incorporation of cyberterrorism into the broader definition of counter-terrorism it does not indicate how the two laws interact to create ambiguity as to how the two laws will be applied by varying state and investigative agencies.
Judicial Caution and the Recent Expansion of Section 66F
Indian courts (generally) have been quite cautious in applying Section 66F the Delhi and Bombay High Courts have noted that Section 66F is only intended to apply to the most serious offences against the state; for example, the vast majority of hacking/unauthorised access cases do not constitute serious offences against the state. This cautious approach stems from the belief that (1) the punishment (i.e. life imprisonment) is much too harsh and not commensurate with the vast majority of cybercrimes; and (2) if the courts were to construe Section 66F broadly, they could criminalise conduct that is illegal but that does not amount to a threat to national security. The application of a cyber terrorism provision by the Ahmedabad City Cyber Crime Police Station in February 2025 represents a break from the cautious approach taken previously. Specifically, this new application was made in relation to the CCTV system hacking at a maternity hospital in Rajkot Gujarat, which resulted in private video footage of patients being made available via Telegram channels. As a result, Gujarat has become the first state to have applied the 'cyber terrorism' provision to unauthorized surveillance of private medical videos and illegal distribution of private medical videos to the public rather than applying it to the type of attacks on defense systems or critical infrastructure that were traditionally associated with "cyber terrorism". While this incident has certainly resulted in a massive violation of the patients' privacy and dignity and involved more than 50,000 hacked and compromised CCTV systems across 20 states, the application of the cyber terrorism crime raises a critical doctrinal question about how the specific intent requirement found in Section 66F is to be satisfied is the scale of the incident sufficient, or is there also required to be a demonstrated link between the act and a threat to the security or sovereignty of the state? This incident highlights the continued lack of clarity regarding the application of the provision nearly 20 years after its enactment.
Discussion and Critical Evaluation
Section 66F, when viewed against the threat it intends to capture, presents a number of challenges. First, Section 66F was drafted in 2008, which predates the rapid developments of attacks using ransomware-as-a-service, the use of artificial intelligence to conduct attacks, and the pervasive and deep interconnectedness of the different sectors of the digital economy. To illustrate, a ransomware attack on a hospital’s cyber network may not have been done with the intent of violating the sovereignty of India, but the effects on public health and safety of that attack would be comparable to a traditional act of cyber terrorism. The statutory threshold of intent, while useful, may be too high and risks permitting acts of overwhelming impact, but with a lack of clarity of intent.
Second, as India has not ratified the Budapest Convention on Cyber Crime, there will be limitations in the ability of India to conduct cross-border investigations of cyber terrorism that may be perpetrated in other jurisdictions. Because many of the more serious cyber-attacks on the Indian infrastructure have been perpetrated by persons in other jurisdictions, these limitations in international cooperation will further limit the ability to practically enforce Section 66F. Third, the multiple and overlapping application of the IT Act, the UAPA, and the Bharatiya Nyaya Sanhita, which now provides for the incorporation of terrorist acts in Section 113, creates a confusing legal framework in which prosecutors will be compelled to work within different legal frameworks with their own standards for evidence and their own procedural requirements, which will result in delays and outcomes that may not be consistent.
Conclusion
Section 66F of the Information Technology Act was added to underscore the seriousness of online terrorism. India introduced this section to address the threats of online terrorism after the 2008 Mumbai attacks. Laws, including Section 66F, have continued to develop over the years. Section 66F has become vague and overlaps with the Unlawful Activities Prevention Act after almost two decades of existence. Also, a number of countries do not provide assistance to India on these issues. The wording of Section 66F is poor and imprecise. Therefore, the formal responses of India to deal with online terrorism are still in development. The Indian government is repealing the IT Act and is implementing the Digital India Act. With the implementation of the Digital India Act, Indian legislators can articulate the definition of cyber terrorism and include forms of terrorism that threaten the security and integrity of critical AI and computer systems. They can also include possible forms with the threats to the security and integrity of critical AI and computer systems. However, they must retain the balance of the provisions, as the general punishment of terrorism in India is very severe. Section 66F also is the most important and relevant section in the legislation on cyber terrorism in India.
References
Statutes
Information Technology Act, 2000 Section 66F, No. 21 Acts of Parliament, 2000 (India).
Information Technology Act, 2000 Section 70 No. 21 Acts of Parliament, 2000 (India).
Unlawful Activities (Prevention) Act, 1967 Section 15 No. 37 Acts of Parliament, 1967 (India).
Books and Articles
Rahul Kailas Bharati writes about Cyber Terrorism (Section 66F of the IT Act, 2000) on SSRN, published on July 24 2025. You can find it at https://ssrn.com/abstract=5388638.
Amit Rangi discusses Cyber Terrorism in Law in the 11th issue of Intl. J. Envtl. Sci., published in 2025. The article is available at https://theaspd.com/index.php/ijes/article/download/1507/1220/2944.
Online Sources
Apnilaw explains Section 66F IT Act in an article about Cyber Terrorism and National Security published on October 11 2025. Read it at https://www.apnilaw.com/legal-articles/acts/section-66f-it-act-explained-cyber-terrorism-and-national-security/.
Another article on Apnilaw talks about Cyber Terrorism and Section 66F of the IT Act published on May 2 2025. Check it out at https://www.apnilaw.com/news/criminal/cyber-crime/cyber-terrorism-and-section-66f-of-the-it-act/.
Gungun Sharma writes about Cyberterrorism and State-Sponsored Cyberattacks in India covering gaps, national security and policy challenges on Jus Corpus, published on March 21 2026. Find it at https://www.juscorpus.com/cyberterrorism-and-state-sponsored-cyberattacks-in-india/.
The Centre for Internet and Society provides information on Section 66F of the Information Technology Act, 2000. Visit https://cis-india.org/internet-governance/resources/section-66f-of-the-i-t-act-2000, last updated on June 19 2026.
IntoLegalWorld discusses Challenges in Addressing Cyberterrorism in India published on January 24 2026. Read more at https://www.intolegalworld.com/post/legal-challenges-in-addressing-cyberterrorism-in-india.
ICLG provides an overview of Cybersecurity Laws and Regulations, in India for 2025, published on November 6 2024. Check it out at https://iclg.com/practice-areas/cybersecurity-laws-and-regulations/india/.






