Updated: August 2026 | Reading Time: 9 minutes

Introduction
Section 66C of the IT Act is a critical provision in India’s Information Technology Act, 2000, that deals with the punishment for identity theft. In an era where digital identities are increasingly targeted by cybercriminals, understanding Section 66C of the IT Act is essential for legal professionals, cybersecurity experts, and citizens alike.
Identity theft is one of the fastest-growing cybercrimes in India, with the number of reported incidents increasing significantly in recent years. Section 66C of the IT Act provides the legal framework to prosecute offenders who fraudulently or dishonestly use another person’s electronic signature, password, or other unique identification features.
Authored by Adv. Shoeb Hakim—a criminal defence, AML, digital forensics, and cybercrime specialist with decades of experience training police and judiciary—this comprehensive guide examines Section 66C of the IT Act, its provisions, penalties, judicial interpretations, and practical implications in 2026.
What Is Section 66C of the IT Act?
Section 66C of the IT Act deals with the punishment for identity theft. The provision states that if any person, fraudulently or dishonestly, makes use of the electronic signature, password, or any other unique identification feature of another person, they shall be punishable with imprisonment up to three years and/or fine up to ₹1,00,000.
This section was introduced through the Information Technology (Amendment) Act, 2008, which came into effect on 27 October 2009. The amendment recognized the growing threat of identity theft in the digital age and provided a specific legal framework to address it.
Key Provisions of Section 66C IT Act
1. The Offence
If any person, fraudulently or dishonestly, makes use of the electronic signature, password, or any other unique identification feature of another person, they shall be punishable.
2. The Punishment
- Imprisonment: Up to three years.
- Fine: Up to ₹1,00,000.
- Both: In some cases, both imprisonment and fine can be imposed.
3. Key Requirements
Fraudulence and Dishonesty: The act must be done fraudulently or dishonestly to attract punishment under Section 66C of the IT Act. Mere unauthorized use without fraudulent intent may not constitute an offence under this section.
4. Scope
This section covers a wide range of activities, including:
- Unauthorized use of electronic signatures
- Unauthorized use of passwords
- Unauthorized use of biometric data
- Unauthorized use of other unique identification features
What Constitutes Identity Theft Under Section 66C IT Act?
Identity theft under Section 66C of the IT Act involves the fraudulent or dishonest use of another person’s:
- Electronic Signature: Any digital signature or electronic authentication method.
- Password: Any code, phrase, or mechanism used to access accounts or systems.
- Other Unique Identification Feature: Biometric data (fingerprints, iris scans), Aadhaar, PAN, or any other unique identifier.
Examples of Identity Theft Under Section 66C
- Using someone else’s Aadhaar number to open a bank account
- Using someone’s password to access their email or social media accounts
- Using someone’s biometric data to authenticate a financial transaction
- Using someone’s electronic signature to sign legal documents
Related Sections of the IT Act
Section 66C of the IT Act is part of a broader framework of cybercrime provisions in the IT Act:
| Section | Offence | Penalty |
|---|---|---|
| Section 66 | Computer-related offences | Up to 3 years, ₹5,00,000 |
| Section 66B | Receiving stolen computer resource | Up to 3 years, fine |
| Section 66C | Identity theft | Up to 3 years, ₹1,00,000 |
| Section 66D | Cheating by personation | Up to 3 years, fine |
| Section 70 | Protected systems | Up to 10 years |
Judicial Interpretations of Section 66C IT Act
Supreme Court on Bailability (July 2026)
In July 2026, the Supreme Court of India clarified that a computer-related offence punishable under Section 66 of the IT Act is a bailable offence. The Court noted that since Section 66 prescribes a punishment up to three years, when read with Section 77B, the true nature of the offence treats it as a bailable offence.
While this ruling specifically addressed Section 66, it may have implications for the interpretation of Section 66C, which also prescribes punishment up to three years.
High Court Precedents
Various High Courts have interpreted Section 66C of the IT Act in the context of specific cases. Key principles that have emerged include:
- Mens Rea Required: The prosecution must establish fraudulent or dishonest intent.
- Burden of Proof: The prosecution must prove beyond reasonable doubt that the accused used the identification feature of another person.
- Digital Evidence: Courts rely heavily on digital evidence, including IP logs, device identification, and authentication records.
Section 66C IT Act vs. Other Identity Theft Laws
Section 66C of the IT Act is India’s primary law addressing identity theft. Here is how it compares to identity theft laws in other jurisdictions:
| Jurisdiction | Law | Penalty |
|---|---|---|
| India | IT Act, Section 66C | Up to 3 years, ₹1,00,000 |
| United States | Identity Theft and Assumption Deterrence Act | Up to 15 years (federal) |
| United Kingdom | Fraud Act 2006 | Up to 10 years |
| European Union | GDPR, E-Privacy Directive | Up to €20 million or 4% of global turnover |
| Singapore | Computer Misuse Act 1993 | Up to 3 years, $10,000 |
| Australia | Criminal Code Act 1995 | Up to 10 years |
How to Protect Against Identity Theft
Understanding Section 66C of the IT Act is important, but prevention is even more critical. Here are practical steps to protect against identity theft:
For Individuals
- Strong Passwords: Use unique, complex passwords for different accounts.
- Two-Factor Authentication: Enable 2FA wherever possible.
- Monitor Accounts: Regularly check bank statements and credit reports.
- Beware of Phishing: Never share personal information via email or text.
- Secure Devices: Keep software updated and use antivirus protection.
For Businesses
- Data Security: Implement robust data protection measures.
- Employee Training: Educate staff on identity theft risks.
- Incident Response: Have a plan for responding to data breaches.
- Compliance: Ensure compliance with data protection laws.
2026 Regulatory Context
Section 66C of the IT Act operates within a broader regulatory framework:
- Digital Personal Data Protection Act, 2023: Requires organizations to implement reasonable security safeguards to protect personal data.
- Information Technology (Reasonable Security Practices and Procedures) Rules, 2011: Specifies security practices for protecting sensitive personal data.
- RBI Guidelines: Regulates payment systems and customer authentication.
- Aadhaar Regulations: Regulates the use and authentication of Aadhaar data.
Conclusion
Section 66C of the IT Act is a crucial provision in India’s legal framework for combating identity theft. It provides for imprisonment up to three years and fines up to ₹1,00,000 for fraudulent or dishonest use of another person’s electronic signature, password, or other unique identification features.
In 2026, with identity theft becoming increasingly sophisticated, understanding Section 66C of the IT Act is essential for legal professionals, cybersecurity experts, and citizens. By understanding the law and implementing preventive measures, individuals and organizations can protect themselves from the devastating consequences of identity theft.
Frequently Asked Questions
Q1: What is Section 66C of the IT Act?
Section 66C of the IT Act deals with punishment for identity theft. It states that if any person fraudulently or dishonestly uses the electronic signature, password, or any other unique identification feature of another person, they shall be punishable with imprisonment up to three years and/or fine up to ₹1,00,000.
Q2: What is the punishment under Section 66C of the IT Act?
The punishment under Section 66C of the IT Act is imprisonment up to three years and/or fine up to ₹1,00,000. The act must be done fraudulently or dishonestly to attract punishment.
Q3: What activities are covered under Section 66C?
Section 66C covers unauthorized use of electronic signatures, passwords, biometric data, and other unique identification features such as Aadhaar, PAN, or any other unique identifier.
Q4: Is Section 66C of the IT Act a bailable offence?
While there is no specific Supreme Court ruling on Section 66C, the Supreme Court’s July 2026 ruling on Section 66 (which also prescribes punishment up to three years) clarified that it is a bailable offence. This may have implications for Section 66C.
Q5: How is Section 66C different from Section 66D?
Section 66C deals specifically with identity theft—fraudulent or dishonest use of another person’s identification features. Section 66D deals with cheating by personation using computer resources—pretending to be someone else to deceive or cheat.
📚 Related Legal Guides on Adv. Shoeb Hakim’s Website:
- Global Cybercrime Laws Comparison 2026: US, UK, EU, India & More
- Compliance Officer in a Stock Broking Company: Duties & 2026 Guide
- Compliance Department Roles and Responsibilities: 2026 Guide
- Group Legal, Compliance & Secretariat (LCS): Functions & 2026 Guide
- Become a Cybercrime Investigator 2026: Career Guide & Roadmap
📌 Explore More on Adv. Shoeb Hakim’s Website:
- Read More Articles on the Blog
- Book a Consultation with Adv. Shoeb Hakim
- Contact Adv. Shoeb Hakim
- Careers & Opportunities
By Adv. Shoeb Hakim
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1995.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
Additional Page Metadata
- Author: Adv. Shoeb Hakim
- Author Bio: Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police and judiciary since 1996. Provides expert commentary on cybercrime law, digital forensics, and criminal justice.
- Article Publisher: Adv. Shoeb Hakim
- Article Section: Cybercrime Law | Digital Forensics | Criminal Justice | IT Law
- Article Tags: Section 66C IT Act, Identity Theft India, IT Act Identity Theft, Section 66C Punishment, Cybercrime Law India, Digital Identity Theft, Electronic Signature Fraud, Password Theft, Biometric Fraud, Aadhaar Fraud, Adv Shoeb Hakim
#Section66C #ITAct #IdentityTheft #Cybercrime #DigitalSecurity #CyberLaw #DataProtection #DigitalIdentity #CyberCrimeIndia #PasswordSecurity #BiometricSecurity #AdvShoebHakim


