India's Premier Full-Service Law Firm — Precision. Pedigree. Global Reach.
Goldschmidt Pallonji& Associates
Get in Touch
Home / Practices / Criminal Defence / Cyber Crime
★★★ Criminal Defence — Individual

Cyber Crime Defence

Every cyber crime prosecution in India rests on digital evidence. That evidence has specific technical requirements for admissibility under Section 65B of the Indian Evidence Act. It has specific methodological requirements for reliability. And the most common piece of evidence — the IP address — is far weaker identification evidence than most courts, complainants, and investigators understand. The defence that understands the technology makes these weaknesses visible.

IT Act 2000 · Section 66 · Section 66C · Section 66D · Section 66E · Section 67 · Section 72
Hacking · Identity Theft · Online Fraud · Cyber Defamation · Morphed Images · Stalking · DPDP
The Defence

Cyber crime cases are technically complex but legally vulnerable. The police's digital evidence collection is often not Section 65B-compliant. The IP address that is presented as identifying the accused uniquely does not, in most cases, do so — it identifies a device, not a person, and a shared network address identifies neither. The social media account that allegedly contains the offensive content may have been accessed by others, compromised, or attributed incorrectly. These are not legal technicalities — they are the factual foundation of a reliable prosecution, and they are frequently absent.

The Information Technology Act 2000 (as amended in 2008) creates a comprehensive framework of cyber offences — hacking and computer damage (Section 66), identity theft (Section 66C), cheating by personation using computer resources (Section 66D), violation of privacy (Section 66E), publishing sexually explicit material (Section 67), and unauthorised access to protected computer systems (Section 70). These provisions are frequently invoked alongside IPC offences — Section 419 (cheating by personation), Section 499/500 (defamation), Section 354D (stalking), and Section 509 (obscene gestures or words to a woman) — creating composite IT Act and IPC charges that require defence on both statutory frameworks simultaneously.

The technical unreliability of cyber crime prosecution evidence is GP's most important working assumption in every case. IP address evidence requires corroboration that the investigation rarely provides — and often cannot, because NAT addressing, VPN usage, and shared networks mean that the IP address logged by a server may be shared by hundreds of users simultaneously. Social media account attribution — proving that the specific person accused actually made the specific post, sent the specific message, or uploaded the specific content — requires device forensics that the police investigation often skips. Section 65B certification of digital evidence is mandatory since Arjun Panditrao, and its absence is a complete bar to the evidence's admissibility.

GP's cyber crime defence practice draws directly on GP's in-house digital forensics capability — the same team that supports GP's corporate investigations, tax search proceedings, and digital evidence collection for civil litigation. The digital forensics specialist who challenges the prosecution's technical evidence is the same person who, in other matters, builds the digital evidence chain for GP's clients. This dual experience — understanding both how digital evidence is correctly collected and how police investigations fall short — gives GP's cyber crime defence a technical grounding that criminal law practices without in-house digital forensics cannot match.

Key IT Act Provisions
S.66 — Hacking / Computer Damage S.66C — Identity Theft S.66D — Cheating by Personation S.66E — Privacy Violation S.67 — Obscene Material S.67A — Sexually Explicit Material S.72 — Breach of Confidentiality
Practice at a Glance
Offences Defended
Hacking · Identity theft · Online fraud · Cyber defamation · Morphed images · Cyber stalking · Data theft · Revenge content · Online impersonation
IT Act 2000 offences · IPC companion charges · BNS equivalent provisions · DPDP Act (emerging)
Technical Defence
IP address insufficiency · Section 65B challenge · Account attribution failure · Device forensics counter-analysis · Digital forensics team in-house
First Actions
Anticipatory bail · FIR quashing assessment · Digital evidence review · Technical counter-analysis of prosecution evidence
Speak to Our Cyber Crime Defence Team
Our Services

Cyber Crime Defence Services

Technical evidence challenge, FIR quashing, anticipatory bail, and full trial defence — for every category of cyber crime allegation, backed by GP's in-house digital forensics team.

💻

Hacking & Unauthorised Access Defence

Defence against Section 66 IT Act hacking charges — establishing that the accused did not access the complainant's computer resource without authorisation, or that the access was authorised at the time even if the relationship subsequently deteriorated. The technical evidence challenge: the log files that the prosecution relies upon to establish unauthorised access, the forensic analysis of the accused's devices, and the network traffic analysis that the investigation typically does not conduct. For corporate hacking allegations — where a former employee is accused of accessing company systems after their employment ended — the authentication logs, the VPN access records, and the access termination procedures are the factual battleground that GP's digital forensics team analyses.

👤

Identity Theft & Online Impersonation

Defence against Section 66C (identity theft) and Section 66D (cheating by personation using computer resources) charges — the specific digital evidence challenge that establishes the accused did not use another person's electronic signature, password, or unique identification feature. For social media impersonation allegations — a fake account created in the complainant's name — the account attribution evidence: the device used to create the account, the login locations, the email address linked to the account, and the consistency of the activity pattern with the accused's known online behaviour. Many impersonation accounts are created by parties other than the accused — and the technical investigation, if properly conducted, often reveals this.

📸

Morphed Images & Revenge Content Defence

Defence against charges of publishing morphed or sexually explicit images (Section 66E, Section 67, Section 67A IT Act, and Section 354C IPC) — frequently filed in the context of relationship breakdowns, workplace disputes, or online harassment campaigns. The attribution challenge: proving that it was the accused who published the specific content requires device forensics that establishes the content was uploaded from the accused's device, at a time consistent with the accused's location, using accounts linked to the accused. Where this chain of attribution is incomplete — and it frequently is in police investigations that proceed from the content to the IP address without establishing device-to-person linkage — the prosecution case cannot succeed.

📌

Cyber Defamation & Online Harassment

Defence against defamation charges (Section 499/500 IPC and Section 66A IT Act, now struck down) in the context of online content — social media posts, review sites, WhatsApp messages, and blog content. The legal element of defamation — the statement must be false, must be published to a third party, and must be about the complainant specifically — is frequently absent in online defamation FIRs that target opinions, satire, or general commentary. Where the statement is true, or where the accused had an honest belief in its truth, or where the content is clearly opinion rather than a statement of fact, the defamation charge fails. FIR quashing is often available where the online content does not satisfy the specific legal elements of defamation.

🛡️

Online Fraud Defence — Section 66D

Defence against online fraud allegations under Section 66D (cheating by personation using computer resources) and companion Section 420 IPC — where the accused is alleged to have deceived the complainant through a fake website, fake email communication, social media impersonation, or digital identity fraud. The technical challenge to the prosecution's attribution evidence: establishing that the accused did not control the allegedly fraudulent digital identity, did not send the allegedly fraudulent communications, or did not benefit from the fraud. Section 65B compliance of the prosecution's digital evidence — email headers, IP logs, and account records — is the first review in every online fraud defence.

🔒

Data Theft & Confidentiality Breach

Defence against Section 72 IT Act (breach of confidentiality and privacy) and companion charges for the disclosure or use of information obtained from electronic systems. Employment context: a departing employee accused of taking client data, trade secrets, or confidential information from company systems. The specific evidence challenge: device forensics establishing whether the accused actually accessed and copied the specific data alleged, or whether the company's own investigation has identified the wrong device or the wrong person. GP's digital forensics team analyses the company's forensic investigation — frequently finding that the evidence of data extraction is less specific than the company believes, or that the investigation has attributed data extraction to the wrong user account.

Key Highlights

The three technical weaknesses in most Indian cyber crime prosecutions — and the specific defences they generate.

The IP address defence — what an IP address actually proves, and what it does not
An IP address identifies a network connection — not a person. A home broadband connection may have ten devices connected simultaneously. A café or shared WiFi network may have hundreds. A VPN connection routes traffic through a server that may be shared by thousands of users. And dynamic IP addressing means that the IP address logged at a particular time may have been assigned to a different user the following hour. The prosecution that relies on "the IP address used was the accused's" without establishing: (1) the specific device that used that IP address; (2) the specific user who was logged in to that device; and (3) the absence of other users of the same network at the same time — has not established that the accused committed the offence. GP's digital forensics team prepares the technical analysis that explains these limitations to the court in terms that are legally relevant and technically accurate.
Section 65B — the admissibility requirement that most cyber crime investigations miss
Every piece of digital evidence in a cyber crime prosecution must be accompanied by a Section 65B certificate — prepared by a person occupying a responsible official position in relation to the computer resource from which the evidence was produced, certifying the device's proper operation and the accuracy of the output. The Supreme Court's Arjun Panditrao decision made this requirement mandatory for all electronic evidence. Police cyber crime units frequently collect digital evidence without producing Section 65B certificates — or produce certificates that do not satisfy the legal requirements. Screenshots taken by a complainant and submitted to police are not Section 65B-certified documents. IP address logs produced by a social media company without certification are not admissible. GP challenges Section 65B compliance in every cyber crime case as a matter of routine — because the certificate is often missing, and its absence bars the evidence entirely.
Account attribution — the link between the online account and the accused person
Proving that a social media account was controlled by the accused requires more than showing that the account bears the accused's name or profile picture. The account may have been created using the accused's personal information without their knowledge. It may have been created by the accused but then accessed by others. It may have been hacked. The mobile number linked to the account may have been obtained through SIM swap fraud. The investigation that proceeds from "the content was posted from an account in the accused's name" to "the accused posted the content" without establishing device-to-person linkage — through device forensics, login location analysis, and session time correlation with the accused's known location — has not proved attribution. GP identifies this attribution gap in every social media case as the most critical technical challenge.
The FIR as a personal dispute weapon — quashing the cyber crime complaint that is a relationship dispute
A significant proportion of cyber crime FIRs in India are filed in the context of relationship disputes — former romantic partners, estranged family members, or bitter business separations — where the IT Act is used as a weapon rather than a remedy. The FIR alleging that a former partner posted intimate images, that an estranged family member is running a harassment campaign, or that a business rival has hacked company systems — often without any technically reliable evidence of the alleged act — is the cyber crime equivalent of the commercial cheating FIR. The High Court's quashing jurisdiction is available where the allegations are based on malice rather than genuine crime, and where the technical evidence cited in the FIR does not actually establish what the complainant alleges. GP assesses the quashing potential of every cyber crime FIR on first instruction.
How GP's Digital Forensics Team Challenges the Prosecution's Technical Evidence
1
Section 65B Certificate Review
Every item of digital evidence is reviewed for Section 65B compliance — is the certificate present, does it identify the right person, does it describe the correct device, and does it certify the right things?
2
IP Address Analysis
Technical analysis of the IP address evidence — NAT addressing, shared networks, dynamic allocation, VPN routing — establishing what the IP address actually proves and what additional evidence would be needed to establish person-specific attribution.
3
Account Attribution Analysis
Assessment of whether the investigation has established device-to-person linkage for the social media or email account in question — or whether the attribution chain has gaps that the prosecution cannot close.
4
Device Forensics Counter-Analysis
Where the police have conducted device forensics on the accused's devices, GP's team reviews the methodology, the tool used, the chain of custody, and the conclusions — identifying where the police analysis is technically incorrect or methodologically flawed.
Section 66A IT Act — The Provision the Supreme Court Struck Down, That Police Still Try to Use

Section 66A of the IT Act — which made it an offence to send "offensive" or "menacing" messages through electronic communication — was struck down by the Supreme Court in Shreya Singhal v. Union of India in 2015 as unconstitutional, on the ground that it violated the right to freedom of speech and expression. The provision no longer exists in Indian law. Despite this, police stations across India continue to register FIRs citing Section 66A — either in ignorance of the Shreya Singhal decision or in the hope that the accused will not challenge it. Any FIR citing Section 66A as a basis for prosecution is immediately susceptible to quashing at the High Court — because the provision is void and never existed as valid law after the Supreme Court's decision.

The Cyber Crime FIR Filed by a Former Partner. The Content Is Not Yours. The Account Is Not Yours. But the Police Have Your Name.

The most common pattern of unjust cyber crime prosecution in India is the FIR filed by a former romantic partner or estranged spouse — alleging that the accused posted intimate content, created impersonation accounts, or sent harassing messages — on evidence that amounts to: the content exists on a platform, and the accused is identified in the FIR. The technical investigation that would establish whether the accused actually created the content — device forensics, account authentication analysis, login location data — is rarely conducted before the FIR is registered and the accused is summoned or arrested. GP's first action in any such case is a technical analysis of the available evidence to establish whether it supports the accusation — because in most such cases, it does not. Where it does not, an immediate quashing petition to the High Court, backed by the technical analysis, is the most effective remedy. Where anticipatory bail is also needed, it is filed simultaneously.

The GP Difference

Why GP for Cyber Crime Defence

1

In-house digital forensics — the technical counter-analysis that most criminal firms cannot provide

The cyber crime defence that challenges Section 65B compliance, IP address reliability, and account attribution requires a digital forensics team that understands both the technical methodology and the legal admissibility requirements. GP's digital forensics team is the same team that supports GP's corporate investigations, tax search proceedings, and forensic accounting matters — with specific proficiency in the IT Act's evidence requirements and Section 65B certification. The technical counter-analysis is built on GP's expertise in collecting digital evidence correctly — because the team that knows how evidence should be collected knows exactly where the police investigation has fallen short.

2

DPDP Act emerging liability — the new legal framework that cyber crime defence must now address

The Digital Personal Data Protection Act 2023 creates a new framework of civil and regulatory liability for data breaches and unauthorised processing of personal data — overlapping with the IT Act's criminal provisions in some areas. Cyber crime allegations increasingly arise in a context where DPDP Act compliance is also relevant — particularly for businesses accused of data theft or privacy violations. GP's Cybersecurity and DPDP practice coordinates with the Criminal Defence team on matters where both the criminal IT Act charges and the DPDP regulatory exposure require simultaneous management — ensuring a consistent strategy across both the criminal and regulatory dimensions.

3

Complainant representation — cyber crime victims need a team that can recover and stop the harm

GP also acts for victims of cyber crime — individuals and companies who have been hacked, whose data has been stolen, whose accounts have been compromised, or who are being harassed online. The complainant-side cyber crime service includes: reporting to CERT-In and the appropriate enforcement authority, take-down applications to social media platforms and content hosts, civil injunctions requiring removal of content, police complaint management, and coordination with the cybercrime division for technical investigation. For businesses — incident response coordination, forensic investigation of the breach, and regulatory reporting under CERT-In and DPDP Act frameworks.

Representative Matters

The type of work we do.

Complete confidentiality maintained. All client identities protected.

India Online Fraud — IP Defence, FIR Quashed

Software professional — Section 66D FIR for online fraud, IP address from shared café network, prosecution evidence inadequate, FIR quashed at HC

Defended a software professional against whom a Section 66D FIR was filed by a complainant who alleged that an online loan fraud had been perpetrated using the accused's name and photographs to create a fake lending profile. The complainant had traced the registration IP address of the fraudulent website to an ISP-assigned IP address and then to a residential broadband subscription registered at an address the accused had previously occupied. GP's digital forensics team established that: the IP address in question had been dynamically allocated and had been reassigned to at least four different subscribers in the six months around the fraud date; the residential address to which the subscription was linked was an apartment building with shared lobby WiFi; no device forensics had been conducted on any device associated with the accused; and the website registration details showed a mobile number not associated with the accused. GP filed a quashing petition at the High Court supported by the technical analysis. The High Court quashed the FIR, holding that the IP address evidence was insufficient to establish a prima facie case against the specific accused person.

India Morphed Images — FIR Quashed

Former relationship dispute — Section 67A FIR, account not controlled by accused, login metadata showed different city, FIR quashed at HC

Defended a young professional against whom a former partner had filed a Section 67A FIR — alleging that the accused had posted morphed intimate images of the complainant on a social media account using the accused's name as the display name. GP's digital forensics team obtained, through a court order, the login records for the social media account from the platform — which showed that all logins to the account had originated from IP addresses associated with a city 900 kilometres from where the accused lived and worked, during a period when the accused's location was verifiably established by work records, access card logs, and client meeting records. The account had been created using a disposable email address with no link to the accused's known email accounts. GP filed a quashing petition at the High Court supported by the login metadata analysis and the accused's alibi evidence. The High Court quashed the FIR, finding that the available digital evidence was not consistent with the accused having controlled the account.

India — Complainant Corporate Data Theft — Injunction + FIR

Tech company — former CTO data theft, GP obtained injunction within 24 hours, FIR filed, cryptocurrency tracing initiated, CERT-In notified

Acted for a technology company whose departing CTO had, in his final days of employment, systematically downloaded the company's source code, client database, and proprietary algorithms to personal cloud storage accounts and an encrypted external drive. GP's digital forensics team conducted immediate forensic investigation of the company's systems — establishing the specific files downloaded, the dates and times of download, the cloud accounts and external devices used, and the authentication logs showing the CTO's credentials. Within 24 hours of instruction, GP obtained an ex parte injunction from the Delhi High Court requiring the CTO and his new employer to preserve all downloaded materials and cease any use of the company's proprietary information. A Section 66 IT Act FIR was filed alongside a Section 72 complaint. The CTO's new employer — which had been sharing the stolen code with clients — was joined as a respondent in the injunction proceedings.

Practice Leadership

GP's cyber crime defence practice is led by a senior criminal advocate with specific IT Act expertise, working directly with GP's digital forensics team for the technical counter-analysis and GP's Cybersecurity and DPDP practice for regulatory dimensions.

The practice acts for both accused — whose IT Act FIRs are challenged on technical and legal grounds — and complainants — whose cyber crime matters require immediate technical investigation, evidence preservation, and law enforcement engagement. For accused persons, the digital forensics team's Section 65B review and IP address/account attribution analysis begins the same day as instruction — because the technical challenge is time-sensitive where evidence may be lost or overwritten.

For NRI accused facing Indian cyber crime FIRs from overseas — particularly in online harassment, defamation, and impersonation cases that arise from cross-border relationship or business disputes — GP manages the complete Indian proceedings without requiring the client's physical presence, through anticipatory bail applications, FIR quashing petitions, and platform content take-down proceedings.

GP
Cyber Crime Defence Team
Criminal Advocate + Digital Forensics + Cybersecurity DPDP
Section 65B Analysis IP Address Defence FIR Quashing Platform Take-down Accused + Complainant
Courts: Cyber Crime Courts · MM Courts · Bombay HC · Delhi HC · Karnataka HC · Madras HC · Supreme Court
✉ Write to Our Cyber Crime Team All Criminal Defence Areas
Latest Insights
Technical Guide

Why an IP Address Is Not Enough — The Technical Limitations of IP Evidence in Indian Cyber Crime Prosecutions

NAT addressing, dynamic IP allocation, shared networks, VPN routing, and the evidence chain required to link an IP address to a specific person — explained in terms that make the legal challenge clear for the accused, their family, and the court.

Read Guide →
Legal Alert

Section 66A Is Dead — But Police Still Register FIRs Under It. What to Do If Your FIR Cites a Provision the Supreme Court Struck Down in 2015

The Shreya Singhal decision, the current status of Section 66A, why police stations continue to register FIRs citing it, and the immediate quashing petition that ends any such prosecution at the High Court level.

Read Alert →
Cyber Crime Defence

Speak to Our Cyber Crime Team

Whether you are accused of an IT Act offence, are a victim of cyber crime who needs immediate help, or face an FIR based on an IP address that is not uniquely yours — call us today. Our digital forensics team begins the technical analysis immediately on instruction.

Digital forensics begins Day 1 — Section 65B review, IP analysis, account attribution
FIR quashing — assessed and filed immediately where technical evidence is insufficient
Section 66A FIRs quashed immediately — the provision does not exist in law
Complainant services — immediate injunction, evidence preservation, CERT-In, platform take-down
Send Us a Message

All communications are strictly confidential and legally privileged.