Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 66F of the Information Technology Act, 2000: punishment for cyber terrorism

Section 66F(1) has two limbs. Limb (A) needs an intent to threaten the unity, integrity, security or sovereignty of India or to strike terror, together with one of three listed...

Published
Updated
Reading time
8 min
Views
4
Questions
7 answered
  • Expert Reviewed
  • High Complexity
  • In-Depth Guide
Topic
Cyber & Data Protection
Published
October 2, 2026
Last updated
Oct 9, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Section 66F of the Information Technology Act, 2000 defines the offence of cyber terrorism in two limbs, (A) and (B), and prints a punishment of imprisonment which may extend to imprisonment for life. This article sets out the elements of each limb in the section's own words and does not go beyond them. It follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008); later amendments and the current position should be checked.

What section 66F says

Sub-section (1) begins "Whoever," and then sets out two limbs, each ending with the words "commits the offence of cyber terrorism". Sub-section (2) reads: "Whoever commits or conspires to commit cyber terrorism shall be punishable with imprisonment which may extend to imprisonment for life."

Limb (A): intent, means and result

Limb (A) is built from an intent, a means and a result.

Intent. The act must be done "with intent to threaten the unity, integrity, security or sovereignty of India or to strike terror in the people or any section of the people".

Means. The intent is to be carried out "by" one of three things:

  • (i) "denying or cause the denial of access to any person authorized to access computer resource" (the copy prints "cause" where the grammar calls for "causing"; we flag it and do not correct it);
  • (ii) attempting to penetrate or access a computer resource without authorization or exceeding authorized access; or
  • (iii) introducing or causing to introduce any computer contaminant.

Result. And by means of such conduct, the person "causes or is likely to cause" one of the following: death or injuries to persons; damage to or destruction of property; disruption, or knowing that it is likely to cause damage or disruption, of supplies or services essential to the life of the community; or an adverse effect on "the critical information infrastructure specified under section 70".

The reader should note the structure: intent, one of the means, and one of the results. The text does not use the word "terrorism" for any other act than the ones that fit this structure.

Limb (B): restricted information

Limb (B) applies to a person who "knowingly or intentionally penetrates or accesses a computer resource without authorization or exceeding authorized access", and by means of that conduct obtains access to either:

  • information, data or computer database "that is restricted for reasons for the security of the State or foreign relations"; or
  • any restricted information, data or computer database, "with reasons to believe" that it may be used to cause or likely to cause injury to listed interests.

The listed interests are the sovereignty and integrity of India, the security of the State, friendly relations with foreign States, public order, decency or morality, contempt of Court, defamation or incitement to an offence, or the advantage of any foreign nation, group of individuals or otherwise.

FeatureLimb (A)Limb (B)
Starting pointIntent to threaten India or strike terrorKnowing or intentional unauthorised access or exceeding authorised access
Requires a resultYes: one of the listed resultsObtaining access to restricted information, data or computer database
Mental elementIntent as stated"Knowingly or intentionally"; "reasons to believe" for the second part
Linked provisionSection 70 (critical information infrastructure)Restricted for reasons for the security of the State or foreign relations

Critical information infrastructure and section 70

Limb (A)(iii) refers to "the critical information infrastructure specified under section 70". Section 70(1) lets the appropriate Government declare, by notification in the Official Gazette, a computer resource which directly or indirectly affects the facility of Critical Information Infrastructure to be a protected system, and its Explanation defines Critical Information Infrastructure as a computer resource, the incapacitation or destruction of which "shall have debilitating impact on national security, economy, public health or safety". Our article on sections 70 and 70A explains that section.

An organisation that operates systems on which essential services depend should know the position under section 70 for its own systems. A legal consultation can help map what the notification process in section 70 means for a business.

Punishment as printed

ElementPrinted text
Who"Whoever commits or conspires to commit cyber terrorism"
Punishment"imprisonment which may extend to imprisonment for life"
FineNo fine is printed in sub-section (2)

The section prints no minimum term. Section 77B, which says offences punishable with imprisonment of three years and above are cognizable, is quoted in our article on sections 77A and 77B; section 77A bars compounding of offences "for which the punishment for life or imprisonment for a term exceeding three years has been provided". Section 78 says a police officer not below the rank of shall investigate any offence under the Act. Sections 84B and 84C deal with abetment and attempt. The copy refers to the Code of Criminal Procedure, 1973; check the current procedural law for the corresponding provisions.

A worked example, at the level of the elements

Take an invented utility operator, Sagar Grid Services Limited, whose control systems are declared a protected system under section 70(1). The question under limb (A) is not whether an incident has happened but whether the person who caused it had the intent in the section, used one of the three means, and caused or was likely to cause one of the listed results, which here includes an adverse effect on the critical information infrastructure. If a person without that intent gains unauthorised access, section 66F(1)(A) is not the provision that fits; other provisions, for example section 43 and section 66, would be read on their own words. For the operator itself, the practical question is its duty to report incidents to CERT-In, covered in our article on cyber incident reporting under the CERT-In Directions of 28 April 2022.

Need help understanding obligations around critical systems?

If your organisation operates systems that may be treated as critical, or you need to understand an incident reporting and security obligation read with this section, our team can help. Begin with a legal consultation.

Key takeaways

  • Section 66F(1) has two limbs: (A) intent plus means plus result, and (B) restricted information obtained by unauthorised access with the stated reasons to believe.
  • Sub-section (2) prints imprisonment which may extend to imprisonment for life, for committing or conspiring to commit cyber terrorism.
  • The reference to critical information infrastructure points to section 70.
  • One printing slip in limb (A)(i) ("denying or cause the denial") is flagged, not corrected.

Read next

Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Section 66F

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What are the two limbs of cyber terrorism in section 66F?

Limb (A) is conduct done with intent to threaten the unity, integrity, security or sovereignty of India or to strike terror, by a listed means that causes or is likely to cause a listed result. Limb (B) is unauthorised access that obtains restricted information, data or computer database, with the stated reasons to believe.

What is the punishment?

Imprisonment which may extend to imprisonment for life, under sub-section (2), for whoever commits or conspires to commit cyber terrorism.

When in doubt, read the provision itself rather than a summary of it — including this one.

— TaxClue Compliance Desk

Section 66F: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 7 questions readers ask most on this topic.

Limb (A) is conduct done with intent to threaten the unity, integrity, security or sovereignty of India or to strike terror, by a listed means that causes or is likely to cause a listed result. Limb (B) is unauthorised access that obtains restricted information, data or computer database, with the stated reasons to believe.

Imprisonment which may extend to imprisonment for life, under sub-section (2), for whoever commits or conspires to commit cyber terrorism.

No fine is printed in sub-section (2).

The Explanation to section 70(1) defines it as the computer resource, the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety.

Sub-section (2) says "commits or conspires to commit cyber terrorism".

No. Limb (A) needs the stated intent, a listed means and a listed result; limb (B) needs access to restricted information with the stated elements.

Section 85 deals with offences by companies and the persons in charge, as explained in our article on section 85.