Legal Remedies for Phishing and Ransomware Attacks in India

Updated: July 15, 2026
Published: July 13, 2026

Quick Answer

Phishing and ransomware attacks are punishable offenses under the IT Act and Bharatiya Nyaya Sanhita (BNS). Victims must immediately isolate infected devices, preserve electronic logs under the BSA, and report the attack to the National Cyber Crime Reporting Portal (1930) to initiate criminal prosecution and potential civil recovery.

Key Takeaways

  • Phishing and ransomware are distinct crimes, but both carry severe penalties under the IT Act and BNS.
  • Never pay the ransom; paying does not guarantee data recovery and funds cybercrime.
  • Immediate reporting on cybercrime.gov.in (or dialing 1930) is critical for tracing malicious IP addresses.
  • Businesses must preserve electronic evidence strictly as per the Bharatiya Sakshya Adhiniyam (BSA) for court admissibility.

Introduction

Phishing and ransomware represent two of the most prevalent and damaging cyber threats in India today. Phishing involves deceptive emails or messages designed to steal sensitive credentials, while ransomware maliciously encrypts a victim's data, demanding payment for its release. Falling victim to these attacks can lead to severe financial and data loss, but Indian law provides stringent legal remedies to prosecute offenders and seek compensation.

Indian law treats both phishing and ransomware as serious cybercrimes, offering avenues for criminal prosecution and civil compensation.

Criminal Remedies (Prosecution and FIR)

The primary legal weapons against these attacks reside in the Information Technology (IT) Act, 2000 and the Bharatiya Nyaya Sanhita, 2023 (BNS).

  • Information Technology Act: Section 43 penalizes unauthorized access and downloading or copying of data (classic ransomware behavior). Section 66 deals with computer-related offenses, while Section 66C targets identity theft, and Section 66D punishes cheating by personation by using a computer resource (highly applicable to phishing).
  • Bharatiya Nyaya Sanhita (BNS): Phishing and ransomware attract severe BNS provisions for cheating, forgery, and extortion. Extortion, central to ransomware attacks, is heavily penalized under the BNS.

Civil Remedies (Compensation)

Under Section 43 read with Section 46 of the IT Act, victims can seek civil remedies by filing a complaint with the Adjudicating Officer (typically the IT Secretary of the State). This allows victims to claim financial compensation for damages caused by the unauthorized access and data encryption, separate from the criminal proceedings.

Critical Statutory Time Limits

When dealing with financial loss due to phishing, the "golden hour" is critical. You must report unauthorized financial transactions to your bank immediately. Delays beyond 3 working days can significantly shift the liability burden onto you. For ransomware, businesses must report critical cybersecurity incidents to CERT-In (Computer Emergency Response Team) within 6 hours of noticing the breach, as per recent government mandates.

Practical Tips: Step-by-Step Reporting

  • Isolate and Preserve: In ransomware cases, immediately disconnect the infected device from the network to prevent the spread. Preserve all phishing emails, server logs, and ransom notes. Under the Bharatiya Sakshya Adhiniyam, 2023 (BSA), electronic records must be properly certified to be admissible in court.
  • Never Pay the Ransom: Paying extortion money does not guarantee data recovery and encourages further criminal activity.
  • Call the Helpline: Dial 1930 immediately if funds were stolen via phishing to freeze the transaction.
  • Register a Complaint: File a detailed complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) with all preserved digital evidence.

When Should You Consult a Cyber Lawyer?

While initial police complaints can be filed by citizens, professional legal help is necessary when:

  • Filing Civil Compensation Claims: Drafting and arguing a damages claim before the IT Adjudicating Officer requires legal expertise.
  • Handling Business Data Breaches: If ransomware exposes client data, a lawyer must guide you through data protection compliance and potential liability defenses.
  • Law Enforcement Inaction: If the cyber cell fails to register an FIR or investigate the matter properly.

Conclusion

Phishing and ransomware attacks are sophisticated crimes, but quick, calculated action can mitigate the damage. By understanding your rights under the IT Act and BNS, preserving electronic evidence, and refusing to succumb to extortion, you can legally safeguard your assets and hold cybercriminals accountable.

Frequently Asked Questions

Q: Should I pay the ransom if my data is encrypted?

A: No. Paying the ransom does not guarantee the recovery of your data, heavily funds criminal syndicates, and often marks you as a target for future attacks. Immediately report the extortion to the authorities instead.

Q: Can a company be held liable if customer data is leaked in a ransomware attack?

A: Yes. Companies can be held liable for failing to implement reasonable security practices under the IT Act and emerging data protection frameworks, potentially facing hefty fines and compensation claims.

Q: What evidence is required to prove a phishing attack?

A: Crucial evidence includes original email headers, malicious URLs, bank statements, and server logs. These must be preserved in compliance with the Bharatiya Sakshya Adhiniyam (BSA) for court admissibility.

Need personalized legal help?

Find advocates on JurisOS and send an enquiry.

Find Cyber Law Lawyers