Our website was hit by a DDoS attack, what legal steps can we take?

Our company website/server went down due to what appears to be a deliberate denial-of-service attack, and we want to pursue this legally. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

Our website was hit by a DDoS attack, what legal steps can we take? is governed in India primarily by Information Technology Act, 2000 – Section 43(f), Information Technology Act, 2000 – Section 66 and CERT-In Directions, 2022. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Section 43(f) of the IT Act specifically covers denying access to an authorised person or disrupting a computer system, entitling the company to compensation for the loss, and Section 66 criminalises this conduct where done dishonestly with up to 3 years imprisonment.

Under the CERT-In Directions, 2022, a DDoS attack causing disruption must be reported to CERT-In within 6 hours of detection, which is mandatory for all service providers, intermediaries, and body corporates in India.

Preserve server logs, traffic analytics and firewall/CDN reports immediately, as tracing the source IPs is essential and logs are often auto-purged after a short retention window.

If the attack is traced to servers outside India, cross-border investigation typically requires the cyber cell to route requests through the CBI's Interpol wing or via Mutual Legal Assistance Treaty requests, which can take months.

You can simultaneously pursue a civil claim for the financial loss caused (lost sales, downtime cost) either before the adjudicating officer under Section 46 IT Act or through a civil suit, if the attacker is identified.

What to do next: 1) Engage your hosting/CDN provider to mitigate the attack and preserve logs; 2) Report to CERT-In within 6 hours as mandated; 3) File a complaint at the cyber cell citing Section 43(f) and Section 66 IT Act; 4) Consult a lawyer for a civil compensation claim once evidence is secured.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology Act, 2000 – Section 43(f) carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.