Skip to content Skip to left sidebar Skip to right sidebar Skip to footer

Difference between Hacking and Phishing

Phishing and hacking are driven by similar intents as both are primarily used to defraud people in some way. However, phishing relies on people voluntarily providing information while hacking involves forcefully gaining unauthorized access to it, such as by disabling the security measures of a computer network.

What is hacking?

The act of obtaining unauthorised information is known as hacking. A hacker who gains access to an account can use it against the person or business and, in the worst situations, demand a ransom to release the information.

Chapter XI Section 66 of IT Act, 2000 particularly deals with the act of hacking. Section 66(1) defines a hack as, any person, dishonestly or fraudulently, does any act referred to in Section 43 is called hacking, and Section 66(2) prescribes the punishment for it. Hacking is a punishable offense in India with imprisonment up to 3 years, or with fine up to two lakh rupees, or with both.

Chapter IX Section 43 of IT act, 2000 prescribes a penalty for the damage to computer or computer system. It is a common thing which happens whenever a computer system is hacked. Black hats damage the system that they hack and steal the information. This enumerative provision includes a lot of activities.

Chapter XI Section 65 of the said act makes tampering with computer source documents an offense. Section 72 of the same chapter makes the breach of confidentiality and privacy, a punishable offense. This is the most common aftermath of hacking.

All the above-mentioned provisions mandatorize the need of mala fide i.e. intention to cause harm which is absent in ethical hacking therefore ethical hacking is not illegal in India.

What is phishing?

Phishing is a fraud where someone sends you links to take your sensitive data. It can be an email that seems to be from a bank or a link that appears to require you to check in to your account once more. By leading you to a website or link and forcing you to share your account credentials, the Sender in this situation gains access to your accounts and vital information.

Given that phishing involves a practice where data is extracted from the virtual world, it is treated as a cybercrime and as such, is subject to the provisions of the Information and Technology Act, 2000 ( (‘IT Act). The provisions dealing with the crime were incorporated via the 2008 amendment. The provisions that have been incorporated and regulate the crime of phishing are :

  • Section 43 – extracting or accessing data without consent
    Section 43 stipulates that if an individual accesses another person’s computer system or network for the purposes of downloading, accessing, disrupting, denying or corrupting the data contained therein, without the consent of the owner – then that person may be held liable under this provision.
  • Section 66 – Punishment for phishing
    The provision under Section 66 of the IT Act prescribes the punishment that can be inflicted for the act of stealing a victims account by a phisher. The punishment includes either imprisonment for a term that can exceed up to three years or a fine that can exceed up to five lakh rupees, or both, depending on the severity of the crime.
  • Section 66A – spreading false information
    The provision stipulates that the act of spreading information knowing that it is false, with the intent of causing some form of damage to the victim would be punishable. The provision additionally, outlines the offences that attract the punishment prescribed under the provision.
  • Section 66C
    The provisions under this Section forbids the use of passwords, electronic signatures, or any other feature which is a unique identification of any person. Phishers commit fraudulent actions while disguising themselves as the legitimate owner of the account and carrying out fraudulent acts.

What is the difference?

Hacking and Phishing, both are ways to obtain personal information; the difference is in the methodology. A phish occurs when a user is baited with an email, phone call, text messages and is tricked into “voluntarily” responding with information. Victims are tricked by individuals posing as known people by using forged phishing email or website and making them look official enough to make them act.

In a hack, information is extracted involuntarily, forcing the perpetrator to first take over your computer system, through brute force or more sophisticated methods, to access the sensitive data—that’s not the case with phishing.

In all fairness, there are ethical hackers—known as penetration or pen testers– who attack systems on behalf of owners to explore and document security weaknesses but they are different from the above.

Who are the victims?

Any individual, organization – small or large, across any verticals, and in any country can be vulnerable.  The Motives for such attacks can involve espionage—stealing secrets–or could be monetary. A prime target for cyber thieves are an organization’s servers–that’s where the data is stored, and where the pot of gold lies in the form of sensitive data.

Conclusion:

Phishing and hacking are both internet crimes. Phishing involves using fake websites or emails that claim to be from a trusted entity. They are designed to trick people into divulging their personal information, such as bank account details or online passwords. Generally Phishing and hacking, one needs to first understand hackers. One can easily assume them to be intelligent and highly skilled in computers. In fact, breaking a security system requires more intelligence and expertise than actually creating one.

0 Comments

There are no comments yet

Leave a comment

Your email address will not be published. Required fields are marked *