I. Introduction
India’s tryst with cyber legislation is now a quarter-century old. Yet, the gap between the volume of digital offending and the system’s capacity to punish it has arguably never been wider. The Indian Cyber Crime Coordination Centre recorded 15,96,679 cybercrime-related complaints on the National Cyber Crime Reporting Portal in 2023, rising to 22,68,346 in 2024 -a year-on-year increase of over 42 per cent, with reported financial losses climbing from ₹2,290.24 crore in 2022 to ₹22,845.73 crore in 2024.¹ Against this arithmetic of scale stands a strikingly modest conviction record: a Right to Information-based analysis of police data from twenty-eight states found that of roughly 1.67 lakh cybercrime cases registered between 2020 and 2022, only 2,706 persons were convicted, a conviction rate hovering between 0.93 per cent and 2 per cent across the three years.² The question this paper poses whether digital crime in India can be punished faster and more effectively is therefore not rhetorical. It is a live administrative and constitutional problem, and the answer depends on disentangling three distinct things that are often spoken of as one: the substantive statutory framework, the institutional machinery that operationalises it, and the technological tools now being deployed to compress the distance between offence and outcome. This paper proceeds in four parts. It first traces the evolution of the statutory architecture from the Information Technology Act 2000 (IT Act) through its 2008 amendment to the cyber relevant provisions of the Bharatiya Nyaya Sanhita 2023 and the Digital Personal Data Protection Act 2023. It then examines the enforcement and adjudicatory architecture -police cyber cells, the I4C ecosystem, the moribund Cyber Appellate Tribunal, and the courts – before turning to the “digital arrest” phenomenon as a case study in the law’s reactive posture. It concludes that speed and effectiveness in India’s cyber-justice system are being pursued chiefly through pre-emptive, technology-driven fraud interdiction rather than through the criminal trial process, and that this bifurcation, while pragmatic, raises its own accountability concerns.
II. The Statutory Architecture: From the IT Act 2000 to the BNS
The IT Act 2000 was drafted principally to give legal recognition to electronic records and digital signatures in line with the UNCITRAL Model Law on Electronic Commerce, and its penal provisions were, in this sense, an afterthought bolted onto a facilitative statute. ³ Chapter XI of the original Act criminalised a narrow band of conduct: tampering with computer source documents (section 65), hacking (the original section 66), and publishing obscene material in electronic form (section 67). Civil liability for unauthorised access, data theft, and the introduction of viruses was addressed separately under section 43, with adjudication entrusted to an “Adjudicating Officer” under section 46, whose orders were appealable to a Cyber Appellate Tribunal under section 48.⁴ The Information Technology (Amendment) Act 2008, passed in the aftermath of the 26/11 Mumbai attacks and following extensive industry lobbying after the Bazee.com controversy, substantially rewrote the penal architecture.⁵ It introduced section 66A, criminalising the sending of “grossly offensive” or “menacing” information by means of a computer resource; sections 66B to 66F, covering receipt of stolen computer resources, identity theft, cheating by personation, violation of privacy, and cyber-terrorism respectively; sections 67A and 67B on sexually explicit and child sexual abuse material; and a broadened section 69, empowering the government to intercept, monitor, or decrypt information without the “public emergency” precondition that governs telephonic interception under the Indian Telegraph Act 1885.⁶ It was this 2008 amendment, debated in Parliament for barely a few hours, that gave the Act both its enforcement teeth and its most notorious constitutional liability.
That liability crystallised in Shreya Singhal v Union of India, in which the Supreme Court, in a judgment delivered by Nariman J on 24 March 2015, struck down section 66A in its entirety as unconstitutionally vague and over-broad, holding that its terms were incapable of being narrowly construed to fall within the reasonable restrictions permitted under Article 19(2) of the Constitution and that its chilling effect on protected speech under Article 19(1)(a) could not be cured by assurances of restrained executive application.⁷ The Court preserved sections 69A and 79 with the intermediary “safe harbour” rules read down but excised 66A completely — and yet, as subsequent research by the Internet Freedom Foundation and reporting before the Supreme Court in People’s Union for Civil Liberties v Union of India has shown, first information reports continued to be registered under the dead provision for years afterward, prompting the Court in 2019 to direct state police forces and the National Crime Records Bureau (NCRB) to purge and prevent further prosecutions under it.⁸ The episode is instructive: it demonstrates that a statute’s formal invalidation does not, on its own, alter enforcement practice at the police-station level, a theme that recurs throughout the effectiveness question this paper examines.
The passage of the Bharatiya Nyaya Sanhita 2023, replacing the Indian Penal Code 1860 with effect from 1 July 2024, has layered a second stratum of cyber-relevant offences onto the IT Act rather than displacing it. Cheating, including online and UPI-based fraud, is now addressed under section 318 BNS (replacing IPC section 420); cheating by personation- the provision most directly applicable to fake profiles and impersonation frauds -is dealt with under section 319 (replacing IPC section 419); forgery of electronic records falls within sections 335, 336 and 338; and stalking, including cyberstalking through monitoring of a woman’s use of the internet, email, or other electronic communication, is retained under section 78, mirroring the erstwhile IPC section 354D.⁹ The result is a dual-track regime in which a single act of online fraud may attract simultaneous liability under the IT Act (say, section 66C or 66D) and the BNS (section 318 or 319), a structural overlap that complicates charge-framing and has generated inconsistent police practice as to which statute is invoked, or whether both are. A further, distinct layer arrived with the Digital Personal Data Protection Act 2023, India’s first cross-sectoral data protection statute, which received presidential assent in August 2023 but whose substantive provisions await full notification pending the operationalisation of the Digital Personal Data Protection Rules 2025.¹⁰ The DPDPA establishes obligations on “Data Fiduciaries” to process personal data only for lawful purposes with consent or specified legitimate uses, mandates breach notification, and creates a Data Protection Board with the power to impose penalties running up to ₹250 crore for significant non-compliance.¹¹ It is, however, a civil-regulatory instrument rather than a criminal one; it does not create new offences of the kind found in the IT Act, and its Board is not a court of criminal jurisdiction. Its relevance to the “faster justice” question is therefore indirect: it may improve the traceability and accountability of entities that hold breached data, but it does nothing to accelerate the prosecution of the individual fraudster who exploits that data.
III. Institutional Architecture and the Speed Problem
If the substantive law has multiplied, the institutional capacity to enforce it has not kept pace, and it is at this institutional layer that the “faster and more effective” question is really decided. Three features of the architecture are worth isolating.
First, adjudication under the IT Act’s civil track has effectively collapsed. The Cyber Appellate Tribunal, established in New Delhi under section 48, functioned only fitfully: the Centre for Internet and Society’s review of its record found that the Tribunal delivered a mere seventeen judgments before its Chairperson’s post fell vacant in 2011 upon the incumbent’s retirement, after which it could not lawfully hold hearings at all, since the presiding officer’s presence was a statutory precondition.¹² The vacancy persisted for years despite a writ petition before the Karnataka High Court and government assurances of appointment “within six months.” The Finance Act 2017 ultimately abolished the CAT altogether, along with several other sector specific tribunals, transferring its residual jurisdiction to the Telecom Disputes Settlement and Appellate Tribunal as part of a broader tribunal-rationalisation exercise.¹³ A specialised cyber adjudication forum conceived in 2000 to give victims a speedy, technically competent civil remedy had, within a decade, ceased to function in any meaningful sense – a cautionary illustration of how institutional design failures can nullify sound statutory intent.
Second, criminal enforcement remains overwhelmingly a police function exercised through general-purpose cybercrime cells that are unevenly resourced across states, and the NCRB’s Crime in India 2022 report – the most recent published in full – records 65,893 cybercrime cases registered under the IT Act and related sections that year, a 24.4 per cent increase over 2021’s 52,974, with cyber fraud alone accounting for 64.8 per cent of registrations, followed by extortion (5.5 per cent) and sexual exploitation (5.2 per cent).¹⁴ Notably, the NCRB’s published tables report registration and disposal figures for the criminal justice system as a whole but do not break out cybercrime-specific conviction rates, a gap that state-level RTI disclosures have had to fill; it is those disclosures that produced the sub-2-per-cent conviction figures cited at the outset.¹⁵ The reasons commonly advanced for this attrition – jurisdictional confusion where offender, victim, server, and payment gateway sit in different states or countries; the technical demands of digital forensics on an under-trained investigating cadre; the absence, in most districts, of dedicated cyber forensic laboratories; and the sheer delay in obtaining data from foreign platforms under mutual legal assistance treaties – are structural rather than doctrinal, meaning that no amount of statutory redrafting alone will cure them.
Third, and most significant for the “faster” half of the question, the Union government has invested its energy not in accelerating trials but in building a pre-emptive interdiction layer that operates largely outside the criminal process. The I4C’s Citizen Financial Cyber Fraud Reporting and Management System, accessible via the 1930 helpline and the National Cyber Crime Reporting Portal, allows victims to trigger an immediate freeze request to banks and payment intermediaries. Government data placed before the Lok Sabha records that more than ₹7,130 crore has been saved across over 23.02 lakh complaints since the system’s 2021 launch, that the Suspect Registry launched in September 2024 has enabled banks to decline transactions worth ₹8,031.56 crore by cross-referencing 18.43 lakh suspect identifiers and 24.67 lakh mule accounts, that the Samanvaya coordination platform has facilitated the arrest of 16,840 accused persons, and that over 11.14 lakh SIM cards and 2.96 lakh IMEIs linked to fraud have been blocked.¹⁶ This is, in effect, a parallel system of technologically mediated restitution and disruption that operates at a speed no criminal trial could match – freezing funds within hours rather than years- but it substitutes financial recovery and network disruption for the due process guarantees, evidentiary standards, and punitive function of a criminal conviction. It is fast, but it is not “punishment” in the doctrinal sense contemplated by the IT Act or the BNS.
IV. The Digital Arrest Phenomenon as a Case Study
The rise of “digital arrest” scams since 2023–24 crystallises the tension between statutory adequacy and enforcement capacity. In this modus operandi, fraudsters impersonating officers of the Central Bureau of Investigation, the Enforcement Directorate, or local police contact victims by video call, allege their involvement in offences such as money laundering or parcel trafficking, and coerce them -through fabricated arrest warrants and threats of “digital custody” – into transferring funds. Losses of ₹120.30 crore were reported in just the first four months of 2024, and individual cases involving losses in the range of ₹30 lakh to over ₹7 crore have been documented, including one incident in Agra where a woman reportedly suffered a fatal cardiac event after being falsely accused of involvement in human trafficking during such a call.¹⁷ Every element of a “digital arrest” scam is already an offence under existing law — impersonation of a public servant under section 204 BNS, cheating by personation under section 319 BNS, cheating under section 318 BNS, and offences under sections 66C and 66D of the IT Act for identity theft and cheating by personation using a computer resource — so the phenomenon is not evidence of a legislative lacuna.¹⁸ It is evidence that detection, attribution across international VoIP and messaging infrastructure (I4C has reported blocking over a thousand Skype IDs linked to such scams), and cross-border enforcement against operations frequently traced to Southeast Asian scam compounds remain the binding constraints, prompting the Union Home Ministry to constitute an inter-ministerial committee in May 2024 specifically to address transnational cyber-fraud networks.¹⁹ In November 2024, the Supreme Court itself intervened, directing the Reserve Bank of India, state governments, and banks to frame urgent standard operating procedures for fund freezing and restoration in digital-arrest cases, effectively judicially endorsing the pre-emptive, technology-based interdiction model discussed above as the practically available remedy where criminal prosecution is unlikely to be swift.²⁰
V. Assessment: Faster, But Not Yet More Effective
Drawing these threads together, the honest answer to whether Indian digital crime can be punished “faster and more effectively” is asymmetric. On speed, the answer is qualifiedly yes, but the acceleration has occurred almost entirely in the administrative and financial-interdiction space – helpline-triggered freezes, SIM and IMEI blocking, suspect registries – rather than in the judicial process of investigation, charge-sheeting, trial, and sentencing, which remains as slow and forensically under-resourced as ever, as the sub-2-per-cent conviction rate attests. On effectiveness, understood as the law’s capacity to secure accountability through conviction and deterrence, the record is weak, and the weakness is institutional rather than textual: India does not obviously lack criminal provisions covering hacking, identity theft, cyber-fraud, obscenity, or stalking, but it lacks a functioning specialised adjudicatory forum (the CAT experiment failed and was formally abandoned), a sufficiently trained investigative cadre at the district level, forensic infrastructure proportionate to caseload, and a settled jurisdictional protocol for offences that are inherently multi-state or transnational. The DPDPA, when fully operational, may improve upstream data governance and breach accountability but will not itself accelerate criminal disposal. A coherent reform agenda would therefore need to run on two tracks simultaneously: consolidating the fragmented dual-track liability under the IT Act and BNS into clearer charging guidance, and – more urgently – reviving genuine judicial or quasi-judicial capacity, whether through dedicated cyber courts on the model recommended intermittently by law commissions and bar bodies, or through properly resourced forensic and investigative units, so that the considerable technological gains already achieved in fraud interdiction are eventually matched by gains in the courtroom itself.
REFERENCES
1. Ministry of Home Affairs, Lok Sabha Unstarred Question No 432 (2 December 2025) https://www.mha.gov.in/MHA1/Par2017/pdfs/par2025-pdfs/LS02122025/432.pdf accessed 30 August 2026.
2. ‘Only 1.6% Conviction Rate in 2 yrs Amid Surge in Cybercrime Cases’ The Tribune (Delhi, 2024) https://www.tribuneindia.com/news/delhi/only-1-6-conviction-rate-in-2-yrs-amid-surge-in-cybercrime-cases accessed 30 August 2026.
3. Information Technology Act 2000, Preamble; Debarati Halder and K Jaishankar, Cyber Crime and the Victimization of Women: Laws, Rights and Regulations (IGI Global 2012) ch 2.
4. Information Technology Act 2000, ss 43, 46, 48 (as originally enacted). 5. Information Technology (Amendment) Act 2008.
6. Information Technology Act 2000, ss 66A–66F, 67A, 67B, 69 (as inserted/amended by the Information Technology (Amendment) Act 2008); Indian Telegraph Act 1885, s 5(2).
7. Shreya Singhal v Union of India AIR 2015 SC 1523.
8. People’s Union for Civil Liberties v Union of India, Writ Petition (Criminal) No 199 of 2013, Supreme Court of India, order dated 5 February 2019; Internet Freedom Foundation, ‘SC Direction: Stop Prosecuting People Under S.66A’ (Internet Freedom Foundation, 2019) https://internetfreedom.in/sc-direction-stop-prosecuting-people-under-the-unconstitutional-s-66a/ accessed 30 August 2026.
9. Bharatiya Nyaya Sanhita 2023, ss 78, 318, 319, 335, 336, 338.
10. Digital Personal Data Protection Act 2023 (No 22 of 2023); Digital Personal Data Protection Rules 2025.
11. Digital Personal Data Protection Act 2023, ss 8, 25, 27, sch (penalty schedule).
12. Centre for Internet and Society, ‘A Review of the Functioning of the Cyber Appellate Tribunal and Adjudicatory Officers under the IT Act’ (CIS-India) https://cis-india.org/internet-governance/blog/review-of-functioning-of-cyber-appellate-tribunal-and-adjudicatory-officers-under-it-act accessed 30 August 2026.
13. Finance Act 2017, s 183 and Part XIV (Eighth Schedule); Telecom Disputes Settlement and Appellate Tribunal, ‘Introduction’ https://tdsat.gov.in/admin/introduction/uploads/TDSAT%20INTRO.pdf accessed 30 August 2026.
14. National Crime Records Bureau, Crime in India 2022 (Ministry of Home Affairs 2023); summarised in ‘NCRB’s Crime in India 2022 Report’ (Drishti IAS, 2023) https://www.drishtiias.com/daily-updates/daily-news-analysis/ncrbs-crime-in-india-2022-report accessed 30 August 2026.
15. The Tribune (n 2).
16. Ministry of Home Affairs (n 1); ‘Over Rs 7,000 Crore Saved Through Citizen Financial Cyber Fraud Reporting and Management System’ (News on Air, 17 December 2025) https://www.newsonair.gov.in/over-rs-7000-crore-saved-through-citizen-financial-cyber-fraud-reporting-and-management-system/ accessed 30 August 2026.
17. Vivekananda International Foundation, ‘The Growing Problem of Digital Arrest Scams in Bharat’ (VIF, 26 November 2024) https://www.vifindia.org/article/2024/november/26/The-Growing-Problem-of-Digital-Arrest-Scams-in-Bharat accessed 30 August 2026.
18. Bharatiya Nyaya Sanhita 2023, ss 204, 318, 319; Information Technology Act 2000, ss 66C, 66D.
19. Deccan Herald, ‘Amid Rise in Digital Arrest Cases, Indian Cyber Crime Coordination Centre Issues Advisory for Citizens’ (2024) https://www.deccanherald.com/india/amid-rise-in-digital-arrest-cases-indian-cyber-crime-coordination-centre-issues-advisory-for-citizens-3221509 accessed 30 August 2026.
20. ‘Breaking: Supreme Court Directs RBI, States & Banks to Implement Urgent SOPs and Money Restoration Measures to Tackle “Digital Arrest” Scams’ (Verdictum, 2024) https://www.verdictum.in/amp/supreme-court/digital-arrest-scams-interim-directions-rbi-1619172 accessed 30 August 2026.