Definition
The fraudulent or dishonest use of another person's electronic signature, password, or any other unique identification feature — a criminal offence under Section 66C of the Information Technology Act, 2000.
Identity theft in the cyber context involves using another person's digital credentials — password, OTP, biometric data, digital signature, login credentials, PAN, Aadhaar number — without authorisation, typically to commit financial fraud, access private data, or impersonate the person online. Section 66C IT Act penalises fraudulent or dishonest use of another's electronic signature, password, or unique identification feature — punishable with up to 3 years imprisonment and fine of Rs. 1 lakh. Section 66D IT Act penalises cheating by personation using communication devices (making phone calls pretending to be another person). Physical identity theft — forging identity documents — falls under BNS forgery provisions.
Statutory Definition
Section 66C, Information Technology Act, 2000 (as amended 2008): 'Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.'
Etymology & Origin
From 'identity' (from Latin 'identitas' — sameness, from 'idem' — same) + 'theft' (from Old English 'theofth'). Identity 'theft' is a metaphor — the 'thief' takes not physical property but the identifying features of another person, using them as their own.
Full Legal Analysis
Identity Theft: Taking Someone Else’s Digital Self
Your digital identity — your login credentials, OTP, Aadhaar, PAN, email password — is as valuable as physical property. An identity thief can drain your bank accounts, take loans in your name, commit fraud under your identity, and leave you to face the consequences. Section 66C IT Act criminalises this appropriation of digital identity, reflecting the law’s recognition that your digital self deserves the same protection as your physical self.
Common Forms of Identity Theft in India
(a) SIM swap fraud: Criminal obtains a duplicate SIM using forged documents; intercepts OTPs sent to the number; accesses bank accounts. (b) Aadhaar-based fraud: Using another's Aadhaar biometrics for authentication — accessing benefits, opening accounts, taking loans. (c) Credential stuffing: Using usernames/passwords leaked from one breach to access other accounts of the same person. (d) Phishing-to-theft pipeline: Phishing captures credentials (username, password, OTP) → identity theft uses those credentials to impersonate and commit fraud. (e) KYC fraud: Forging KYC documents using another's identity to open accounts or take financial services.
Legal Response: IT Act + BNS + Aadhaar Act
Identity theft may be prosecuted under multiple statutes: (a) IT Act Section 66C — electronic identity theft; (b) BNS Section 318 — cheating (financial fraud perpetrated using stolen identity); (c) Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 — Section 29: unlawful disclosure/use of Aadhaar data; (d) BNS forgery provisions — forging documents to enable identity fraud.
“Digital identity is not merely a credential — it is who you are in the digital world. When a criminal takes your identity online, they don’t just steal data; they become you in the eyes of every digital system that interacts with them. The harm this causes — financial, reputational, administrative — can take years to fully repair.”
This Term in Indian Statutes
Information Technology Act, 2000, 2000
"Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh."
Identity theft: fraudulent use of another's electronic signature/password/unique ID feature — 3 years imprisonment + Rs. 1 lakh fine
