18. Ethics, the Law and a Safe Kali Lab
18.3 Reporting Cyber Crime in India
Ethical hacker mhanje tumhi kaydyachya bajune aahat – mhanun report kuthe karaycha he pan mahit hava. He tumchya family aani clients la pan sanga.
| Where | For what |
|---|---|
| cybercrime.gov.in (National Cyber Crime Reporting Portal) | Report any cyber crime; a special section for women/child-related offences |
| 1930 (national cyber crime / financial fraud helpline) | Urgent financial fraud – call fast so the money trail can be frozen |
| Local police / cyber cell | File an FIR for serious offences |
| CERT-In (Indian Computer Emergency Response Team, under s. 70B of the IT Act) | Report security incidents affecting organisations; they issue advisories and vulnerability notes |
| NCIIPC | Incidents affecting Critical Information Infrastructure |
| Responsible disclosure / bug bounty program policy | When you find a bug in a system that has a disclosure program (Part 11) |
If you find a real vulnerability by accident (for example a public S3 bucket), do not download the data or "prove" it further. Note the minimum evidence, stop, and report it through the owner's disclosure channel or CERT-In. Going further can move you from "helpful finder" to "s. 66 offender".
Why this matters for security
Knowing the reporting path is part of incident response (Part 11). The first hour of a financial fraud matters most – 1930 exists so banks can try to freeze the transfer. For organisations, CERT-In reporting is not just good manners; certain incidents must be reported within the timelines CERT-In specifies.
Ravindra Bagale's Tip
If they find a bug by accident, many students pull out more data and take screenshots "just to see" – and that's exactly where the legal trouble starts. Take the minimum evidence, stop, and report it. "I stopped and reported" is your best protection.
Ravindra Bagale's Tip – मराठी
चुकून एखादा bug सापडला तर बरेच students "पाहून तर घेऊ" म्हणून आणखी data काढतात आणि screenshots घेतात – आणि तिथेच कायद्याचा problem सुरू होतो. कमीत कमी पुरावा घ्या, थांबा, आणि report करा. "I stopped and reported" हे तुमचं सगळ्यात चांगलं सुरक्षा कवच आहे.
Ravindra Bagale's Tip – हिंदी
गलती से कोई bug मिल जाए तो बहुत से students "देख तो लें" कहकर और data निकालते हैं और screenshots लेते हैं – और वहीं से क़ानूनी problem शुरू होती है. कम से कम सबूत लो, रुको, और report करो. "I stopped and reported" तुम्हारा सबसे अच्छा सुरक्षा कवच है.
Practice task
Bookmark cybercrime.gov.in and note the 1930 helpline. Write a 3-step personal plan for what you would do if you discovered a data leak: (1) stop and record minimally, (2) do not download, (3) report through which channel.