NASSCOM v Ajay Sood

119 (2005) Delhi Law Times 5962005Information Technology Law
it-lawphishingpassing-offcyber-fraud

Rule established

Phishing: fraudulently collecting personal data by impersonating legitimate entities online: is actionable as passing off even in the absence of specific legislation; the Delhi HC recognized phishing as illegal.

Facts

  • The defendants operated a placement agency and sent bulk emails to job seekers using NASSCOM's name, logo, and domain identity
  • The emails invited recipients to submit CVs and personal details for purported job opportunities
  • NASSCOM had no connection with the defendants or the recruitment scheme
  • Recipients were deceived into believing the emails originated from NASSCOM
  • NASSCOM filed suit seeking permanent injunction and damages for passing off and tarnishment of reputation

Issues

  1. Whether sending deceptive emails using another entity's name and identity constitutes an actionable wrong in Indian law
  2. Whether the concept of "phishing" (undefined in Indian statute at the time) is covered by existing legal principles
  3. Whether damages and injunction can be granted for online impersonation

Held

  • Phishing is a form of internet fraud where a person misrepresents their identity to collect sensitive personal data
  • Such activity constitutes passing off in the cyber context: the defendant represents their goods/services as connected with the plaintiff
  • Existing tort law principles of passing off extend to online activity without requiring new legislation
  • The defendants' actions tarnished NASSCOM's goodwill and reputation
  • Permanent injunction granted; punitive damages of Rs 16,16,000 awarded (donated by NASSCOM to a charity)

Ratio Decidendi

Indian courts need not wait for specific cyber legislation to address internet fraud. The common law action of passing off adapts to the digital environment: where a party misappropriates another's identity to collect data or solicit business, the misrepresentation and resulting damage complete the cause of action. Phishing is judicially defined as a species of passing off, not merely a criminal offence.

How to use it in an exam

  • Cite as the first Indian judicial definition of phishing
  • Authority for extending traditional passing off principles to cyberspace without statutory basis
  • Relevant in IT Law questions on cyber crimes before and after the IT Act 2008 Amendment
  • Pair with S.66D IT Act (punishment for cheating by personation using computer resource) introduced later
  • Use in questions on judicial creativity in adapting common law to technology

Source

Source: 119 (2005) Delhi Law Times 596

This is an educational summary, not the judgment itself. Cite the reported version in professional or academic work.

Cited in study notes

it-lawE-Commerce Trends and Digital PaymentsPhishing: fraudulently collecting personal data by impersonating legitimate enti