Investigation and Adjudication of Cyber Crimes

Cyber crimes have emerged as one of the most significant challenges of the digital age. The increasing use of computers, smartphones, online banking, social media platforms and cloud-based services has created new opportunities for offenders to commit crimes through digital means. Effective investigation and adjudication of cyber crimes are therefore essential for ensuring accountability, protecting digital rights and maintaining public confidence in technology-driven systems.
Understanding Cyber Crime Investigation
Cyber crime investigation refers to the process of identifying, analysing and collecting evidence relating to offences committed through computers, networks or digital devices. Unlike conventional investigations, cyber crime investigations primarily rely on electronic evidence, technical expertise and digital forensic techniques.

The objective of cyber crime investigation is to identify the offender, preserve evidence, determine the method used to commit the offence and support legal proceedings.
Importance of Cyber Crime Investigation
A proper investigation is essential because cyber offences often involve:
- Financial losses caused through online frauds, phishing attacks and unauthorised transactions.
- Theft of personal information, confidential business data and intellectual property.
- Damage to computer systems, networks and digital infrastructure.
- Threats to privacy, reputation and national security.
Since digital evidence can be altered, deleted or transferred within seconds, timely investigation becomes critical.
Nature of Digital Evidence
Digital evidence refers to any information stored, transmitted or generated through electronic devices that can be used in legal proceedings.
Common examples include:
- Emails and electronic communications
- Social media posts and messages
- IP addresses and server logs
- Mobile phone records
- Online transaction records
- CCTV footage stored digitally
- Data recovered from computers and storage devices
The reliability of cyber crime investigations largely depends upon the proper collection and preservation of such evidence.
Legal Framework Governing Cyber Crime Investigation
Cyber crime investigations in India are governed by several laws that collectively regulate offences, procedure and evidence.
Information Technology Act, 2000
The Information Technology Act, 2000 is the primary legislation dealing with cyber offences in India. It provides provisions relating to:
- Unauthorised access to computer systems
- Data theft and hacking
- Identity theft
- Cheating by personation through electronic means
- Publication of obscene and sexually explicit material
- Violation of privacy
- Cyber terrorism
The Act also grants powers relating to search, seizure and investigation of cyber offences.
Bharatiya Nagarik Suraksha Sanhita, 2023
The Bharatiya Nagarik Suraksha Sanhita provides procedural rules regarding:
- Registration of FIRs
- Investigation of offences
- Search and seizure
- Arrest procedures
- Filing of investigation reports
These provisions apply to cyber offences unless specifically modified by the Information Technology Act.
Bharatiya Sakshya Adhiniyam, 2023
The Bharatiya Sakshya Adhiniyam recognises electronic records as evidence and lays down the legal requirements for proving electronic documents in courts and other proceedings.
Authorities Involved in Cyber Crime Investigation
The investigation of cyber offences requires coordination among several agencies and authorities.
Cyber Crime Cells
Specialised cyber crime cells operate at State and district levels. These units are equipped to handle technologically complex offences and possess expertise in digital investigations.
Police Authorities
Regular police authorities investigate cyber offences and coordinate with technical experts, service providers and forensic laboratories whenever necessary.
Indian Cyber Crime Coordination Centre (I4C)
The Indian Cyber Crime Coordination Centre strengthens cyber crime response mechanisms across the country. It assists in information sharing, capacity building and coordination among investigating agencies.
CERT-In
The Computer Emergency Response Team-India plays a vital role in responding to cyber security incidents and providing technical assistance relating to cyber threats.
Digital Forensic Laboratories
Forensic laboratories examine seized electronic devices and generate expert reports that help investigators and courts understand technical evidence.
Process of Investigation of Cyber Crimes
Cyber crime investigations generally follow a systematic procedure designed to preserve evidence and identify offenders.
Registration of Complaint and FIR
The investigation begins with a complaint made by the victim or an authorised person. Complaints may be filed before local police stations, cyber crime police stations or online reporting portals.
Where a cognisable offence is disclosed, an FIR may be registered and formal investigation begins.
Collection of Digital Evidence
After registration of the case, investigators collect relevant digital evidence from various sources.
These sources may include:
- Computers and laptops
- Mobile phones
- Cloud storage platforms
- Email accounts
- Social media platforms
- Banking records
- Internet service providers
The objective is to secure all information that may establish the commission of the offence.
Preservation of Electronic Records
Electronic records are highly vulnerable to alteration or deletion. Therefore, investigators must ensure that evidence is preserved in its original form.
Important measures include:
- Creating forensic copies of devices
- Maintaining chain of custody
- Generating hash values
- Securing seized devices from unauthorised access
Proper preservation strengthens the evidentiary value of digital records.
Search and Seizure of Electronic Devices
Electronic devices often contain critical evidence relating to cyber offences. Investigating officers may conduct searches and seize:
- Computers
- Mobile phones
- External storage devices
- Servers
- Networking equipment
Such actions must comply with statutory safeguards and procedural requirements.
Digital Forensic Examination
Digital forensic analysis helps investigators recover, examine and interpret electronic evidence.
Forensic experts may:
- Recover deleted files
- Analyse communication records
- Trace unauthorised access
- Examine malware infections
- Verify authenticity of electronic records
Their findings often play a crucial role in establishing guilt or innocence.
Identification of Offenders
One of the most challenging aspects of cyber crime investigation is identifying the person responsible for the offence.
Investigators may rely upon:
- IP address tracking
- Subscriber information
- Device identifiers
- Transaction trails
- Login histories
- Telecom records
Since offenders often use fake identities and anonymity tools, multiple forms of evidence are usually required before attribution can be established.
Understanding Adjudication of Cyber Crimes
Investigation alone does not resolve a cyber dispute. Once facts are established, legal liability must be determined through adjudication.
Adjudication refers to the process through which designated authorities examine evidence, hear parties and determine liability under the Information Technology Act.
The objective is to provide remedies, compensation and penalties where contraventions of cyber law have occurred.
Adjudicating Officers Under the Information Technology Act
The Information Technology Act provides for the appointment of Adjudicating Officers to decide specific cyber law disputes.
These officers perform quasi-judicial functions and are empowered to inquire into contraventions under the Act.
Powers of Adjudicating Officers
Adjudicating Officers possess powers similar to those of a civil court in relation to certain matters.
Their powers include:
- Summoning witnesses
- Receiving evidence
- Requiring production of documents
- Examining electronic records
- Conducting inquiries
- Awarding compensation and penalties
These powers enable them to effectively resolve cyber law disputes.
Jurisdiction of Adjudicating Officers
Adjudicating Officers generally deal with contraventions involving:
- Unauthorised access to computer systems
- Data theft
- Introduction of malicious software
- Damage to computer resources
- Failure to protect sensitive information
The jurisdiction depends upon the nature of the contravention and applicable statutory provisions.
Procedure for Adjudication of Cyber Disputes
The adjudication process follows principles of natural justice and procedural fairness.
Filing of Complaint
The aggrieved party files a complaint containing relevant facts, allegations and supporting documents.
Issuance of Notice
The opposite party is informed of the allegations and given an opportunity to respond.
Examination of Evidence
The Adjudicating Officer examines:
- Documentary evidence
- Electronic records
- Expert reports
- Witness statements
The objective is to determine whether liability has been established.
Hearing of Parties
Both parties are allowed to present their arguments and evidence before a final decision is made.
Passing of Orders
After considering the material on record, the Adjudicating Officer may:
- Award compensation
- Impose penalties
- Dismiss the complaint
- Grant appropriate relief
Appeals Against Adjudication Orders
The law provides mechanisms for challenging adjudication orders before higher forums.
An aggrieved party may file an appeal against the decision of the Adjudicating Officer. The appellate mechanism ensures that errors relating to facts, law or procedure can be reviewed.
The availability of appeals promotes fairness, accountability and consistency in cyber law enforcement.
Difference Between Investigation and Adjudication of Cyber Crimes
Although closely connected, investigation and adjudication serve different purposes.
| Basis | Investigation | Adjudication |
| Purpose | Collection of facts and evidence | Determination of liability |
| Conducted By | Police and investigating agencies | Adjudicating Officers |
| Nature | Fact-finding process | Quasi-judicial process |
| Focus | Identifying offenders and evidence | Awarding compensation and penalties |
| Outcome | Investigation report or charge sheet | Final order or decision |
Conclusion
Investigation and adjudication are two essential pillars of cyber law enforcement. Investigation focuses on identifying offenders, collecting evidence and establishing facts, while adjudication determines liability and provides legal remedies. As cyber crimes continue to evolve in complexity and scale, effective coordination among investigating agencies, forensic experts, adjudicating authorities and courts becomes increasingly important.
A robust system of investigation and adjudication is necessary for ensuring accountability, protecting digital rights and promoting trust in the digital ecosystem.
Attention all law students and lawyers!
Are you tired of missing out on internship, job opportunities and law notes?
Well, fear no more! With 2+ lakhs students already on board, you don't want to be left behind. Be a part of the biggest legal community around!
Join our WhatsApp Groups (Click Here) and Telegram Channel (Click Here) and get instant notifications.








