top of page

Legal Remedies Against Brand Impersonation and Digital Fraud in India

  • 2 days ago
  • 9 min read
Eye-level view of a modern office desk with a laptop and legal documents

The digital environment in India has experienced a significant increase in advanced cybercrimes. Brand impersonation used to be limited to counterfeiting physical goods. Now it could be in the form of look-alike websites, fake social media pages, cloned mobile applications, spoofed payment journeys, and myriad other ways of impersonating legitimate businesses. This post sets out legal remedies and strategies that businesses may deploy to counter such impersonation.


In a typical case of brand impersonation, the fraudster not only copies the brand name, but also build an ecosystem around it: a deceptively similar domain name, a fake investment or franchise offer, supporting social media handles, messaging groups and bank accounts to collect money. The victim believes they are dealing with the genuine business, but the money is routed to unrelated third-party accounts. A customer who has been defrauded may complain against the brand whose name was misused. Even law enforcement agencies, when moving quickly in a fraud investigation, may not always distinguish between a legitimate brand and the anonymous actors impersonating it.


This was demonstrated when recently, founders of a major Indian cryptocurrency exchange were briefly arrested after fraudsters used a lookalike domain to defraud a customer, who then filed a complaint naming the exchange itself. A magistrate later found no prima facie case against the founders and granted bail.


Brand protection strategy should be built in this context, taking into consideration relevant intellectual property law and criminal law frameworks.


The Criminal Law Framework: Cheating, Impersonation and Forged Electronic Records


Indian criminal law applies to online fraud. The Bharatiya Nyaya Sanhita, 2023 (BNS) replaced the Indian Penal Code on 1 July 2024, and its provisions on cheating by personation and forgery apply to digital impersonation. Notably, the BNS's forgery provisions expressly cover "electronic records" - which puts cloned websites, fabricated invoices, spoofed screenshots and false appointment letters squarely within the framework used to prosecute brand impersonation.


At a glance, the following provisions of BNS may be relevant:

Crime

Legal provision

Example of how it may arise online

Cheating involves a situation where someone, through deception, fraudulently or dishonestly persuades another person to hand over property to someone, or to agree that someone can keep property. It also includes intentionally convincing the deceived person to act or refrain from acting in a way they wouldn't if they weren't deceived, resulting in or potentially causing damage or harm to their body, mind, reputation, or property.

Section 318, BNS

Customers are deceived into transferring money believing they are dealing with a genuine brand.



Cheating by personation occurs when an individual deceives others by pretending to be someone else, or knowingly substituting one person with another, or claiming that they or someone else is a different person than they truly are.

Section 319, BNS

The fraudster poses as the company, its founder, an employee, an authorised distributor or a support representative.

Forgery or the use of forged electronic records - involves creating "any false document or false electronic record or part of a document or electronic record" with the intention to cause harm or injury, support a claim or title, induce someone to relinquish property, make someone enter a contract, or commit fraud. It becomes forgery aimed at cheating if the forged document or electronic record is intended for the purpose of cheating.

Section 336, BNS

Fake documents such as invoices are created to support the fraud.

One of the most serious consequences of brand impersonation is that a genuine company, its founders or its officers may be named in complaints filed by defrauded customers. In such situations, it is important to note that Indian criminal law does not generally impose automatic criminal liability on directors or officers merely because they hold a position in a company. For the allegation to hold, the complaint or investigation ordinarily needs to point to specific acts, knowledge, intent or participation by that individual.


The Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) provides protection in the form of a procedural check. Section 223 of BNSS governs how a magistrate takes cognizance of an offence on a private complaint, and its proviso provides that : "no cognizance of an offence shall be taken by the Magistrate without giving the accused an opportunity of being heard."


If founders or officers are arrayed as proposed accused in a private complaint merely because their names, photographs, signatures or designations were misused by the impersonator, they may be able to rely on this procedural safeguard to place material before the Magistrate showing that the company and its officers were themselves victims of the impersonation. Producing records such as cybercrime complaints raised by the company, warnings issued to its customers regarding potential fraud, requests sent to intermediaries to take down fraudulent websites etc may assist in substantiating that position.


Where there is a genuine threat of arrest, the right response depends on the facts, the stage of investigation and the nature of the allegations. The options may include cooperating with the investigating officer and submitting documentary evidence of the impersonation, seeking anticipatory bail under Section 482 of BNSS, or approaching the High Court under Section 528 of BNSS for quashing the proceedings, where the complaint is legally unsustainable. Evidence of innocence should be preserved, as a matter of priority. Screenshots, URLs, WHOIS records, payment details, phone numbers, emails, chat messages, bank account information, customer complaints and internal investigation notes should be gathered. The business should also consider filing its own cybercrime complaint so that there is a clear record that it is a victim of impersonation, not the perpetrator behind the fraud.


Intellectual Property Remedies


Traditional intellectual property remedies remain central to digital brand protection. A company can rely on its registered trademarks, copyright in website content and marketing assets, and common law passing off claims to restrain fraudulent use of its brand or domains. These remedies are especially useful where the fraudster has copied the company’s name, logo, website layout, product imagery or customer-facing language, used look-alike domains, etc.


Trademarks and Passing-off


Under Section 2(1)(m) of the Indian Trade Marks Act, 1999, a “mark” can include a word, name, signature, device, brand, heading, label, ticket, letter, numeral, shape of goods, packaging, colour combination, or a combination of these elements. A registered trademark gives the proprietor statutory remedies in the event of infringement. Under Section 29 of the TM Act, infringement occurs where an unauthorised person uses, in the course of trade, a mark that is identical or deceptively similar to a registered trademark in relation to identical or similar goods or services, and such use is likely to cause consumer confusion or create an impression of association with the registered trademark. If a fraudster creates a fake website using the company’s registered trade name, logo or other registered marks, it may amount to infringement of the company's registered marks.


Where urgency, anonymity or concealment is shown, courts may also grant John Doe/Ashok Kumar injunctions against unknown defendants and issue directions to domain registrars, hosting providers, platforms and intermediaries to block infringing domains, disable associated accounts and disclose registrant information.


In INDmoney Tech Pvt. Ltd. v. Ashok Kumar & Ors. (Delhi HC, 2025), the Delhi High Court granted a dynamic Ashok Kumar injunction against unknown fraudsters who were impersonating INDmoney through fake websites, mobile applications, WhatsApp groups, Telegram channels and bank accounts. The Court held that such unauthorised use of INDmoney's trademarks and branding constituted a prima facie case of trademark infringement, passing off and copyright infringement, while also facilitating fraud on consumers. It directed intermediaries, app stores, telecom authorities and banks to block the infringing infrastructure, freeze identified accounts and disclose information to assist in tracing the perpetrators.


Even where a mark is not registered, a passing off claim may be available under Indian law if the claimant can establish that the defendant’s conduct is likely to mislead consumers into believing that the defendant’s goods or services are those of the claimant, or are commercially connected with the claimant. Passing off is a common law remedy, directed at protecting business goodwill and preventing misrepresentation. To determine existence of passing off, Indian courts generally examine whether the claimant has satisfied the following conditions: (i) the existence of goodwill or reputation in the relevant mark, name, get-up, trade dress, brand element or other source identifier; (ii) a misrepresentation by the defendant, whether intentional or not, which is likely to deceive or confuse the relevant public; and (iii) actual or likely damage to the claimant’s goodwill, including diversion of customers, erosion of distinctiveness, dilution of reputation, or loss of control over brand perception (Laxmikant V. Patel v. Chetanbhai Shah, Supreme Court, 2001).


Domain Names


Where fraudsters register lookalike domains, businesses can consider a combination of administrative domain recovery and court-led enforcement.


Indian courts have maintained in several cases, including Yahoo!, Inc. v. Akash Arora & Anr. (Delhi High Court, 1999), and Satyam Infoway Ltd. v. Sifynet Solutions Pvt. Ltd., (Supreme Court, 2004), that a domain name is not a mere technical address but a business identifier deserving trademark-style protection. A claimant would need to establish the conditions of passing-off to succeed in a court action.


In Dabur India Ltd. v. Ashok Kumar & Ors. (Delhi High Court, 2025), the Court went a step further, treating trademark-based brand impersonation through fraudulent domain names as a broader cyber-fraud and consumer protection issue rather than a conventional infringement dispute. The Court recognised that privacy and WHOIS-masking mechanisms cannot shield fraudsters, and imposed stronger obligations on domain name registrars to assist rights holders and comply with court orders. The judgment also endorsed expansive dynamic injunctions and disclosure remedies, significantly enhancing enforcement tools against recurring online impersonation schemes.


Businesses may also consider administrative domain recovery mechanisms such as Uniform Domain Name Dispute Resolution Policy (UDRP) and .IN Domain Name Dispute Resolution Policy (INDRP). The UDRP applies to generic top-level domains such as .com, .net and .org, while the INDRP applies to .in, .co.in and भारत domain names. They are generally faster and narrower than civil court proceedings, and are typically used to seek transfer or cancellation of the disputed domain rather than damages or broader injunctive relief. To succeed, the brand owner usually needs to show that the disputed domain name is identical or confusingly similar to its mark, that the registrant has no rights or legitimate interests in the domain, and that the domain was registered or is being used in bad faith.


Copyright


Copyright law may also assist where a copycat or fraudulent operator reproduces original business content, such as website text, images, interface screens, marketing material, help-centre content, screenshots, videos or app/store listings. Operationally, copyright complaints can be easier to support because the business can identify the original work, the copied material, and the relevant URL, post, listing, app page or account and seek removal, suspension or de-indexing through hosting providers, domain registrars, social media platforms, search engines, app stores, payment platforms or marketplaces.


Payment Safeguards


Brand impersonation often succeeds because the customer does not realise that the account receiving money is unrelated to the genuine business. Payment verification safeguards can therefore play an important role. The RBI’s beneficiary account name look-up framework for electronic fund transfers is relevant in this context because it enables users to verify the name of the account holder before completing certain transfers.


For businesses, this is a reminder to make customer-facing payment instructions extremely clear. Companies should publish verified payment channels, warn consumers not to transfer funds to personal or unrelated accounts, and repeatedly communicate that employees, agents or distributors are not authorised to collect money outside official channels unless expressly verified.


A Quick Checklist for Businesses


  • Register core trademarks, logos, product names and commonly used brand variants early, and maintain records of use to support infringement or passing-off claims.

  • Secure official domain names and obvious typo or look-alike variations, particularly for high-risk extensions such as .com, .in and .co.in.

  • Maintain a public list of official websites, mobile applications, social media handles, support channels and authorised payment channels.

  • Clearly warn customers not to transfer funds to personal, unrelated or unverified accounts, and repeat this warning across customer-facing pages, emails and support scripts.

  • Monitor domain registrations, search results, app stores, social media platforms, messaging groups and online advertisements for impersonation activity.

  • Preserve evidence immediately, including screenshots, URLs, WHOIS records, payment details, bank account information, phone numbers, emails, chats, app listings and customer complaints.

  • File cybercrime complaints promptly so there is a clear record that the business is a victim of impersonation, not the perpetrator behind the fraud.

  • Send takedown and disclosure requests to domain registrars, hosting providers, social media platforms, app stores, search engines, telecom service providers, payment partners and marketplaces, as applicable.

  • Consider UDRP, INDRP or civil court action where look-alike domains misuse the brand, and seek dynamic injunctions where the impersonation is recurring or anonymous.

  • Use copyright complaints where website copy, images, app screenshots, marketing material, help-centre content or store listings have been copied by the impersonator.

  • Keep law enforcement agencies informed of fake domains, fraudulent bank accounts, contact details and evidence showing that the company’s name, officers or brand assets were misused.

  • Maintain an internal incident response protocol.


Conclusion


Digital brand impersonation can expose businesses to customer complaints, law enforcement scrutiny, reputational harm, and operational disruption, even where the company is itself the victim of the fraud. A defensible response, therefore, requires businesses to preserve evidence quickly, distinguish the legitimate business from the impersonator, and use the available legal tools in a coordinated manner.


The most effective strategy combines prevention and enforcement: early trademark and domain protection, clear customer-facing instructions, active monitoring, prompt cybercrime reporting, administrative domain recovery, platform takedowns and, where necessary, court-led remedies such as dynamic injunctions and disclosure orders.

 
 
 

Comments


Select a time below for a 30-minute introductory call.

© 2025 DRN Legal. All rights reserved. 

Disclaimer

In accordance with the rules of the Bar Council of India, DRN Legal and its members are prohibited from soliciting work or advertising in any form or manner. By continuing to use this website, You confirm and acknowledge that:​ 1. There has been no advertisement, personal communication, solicitation, invitation, or inducement of any kind from DRN Legal or its members to solicit work or advertise through this website. 2. The sole purpose of this website is to provide general information about DRN Legal, its areas of practice, and its professionals. 3. You are accessing this website of your own accord for personal or professional information. 4. Any information or materials obtained from this website are accessed at your own initiative, and using this website does not create a lawyer-client relationship. 5. This website is not intended to serve as an advertisement or solicitation, and its content should not be interpreted as legal advice. 6. DRN Legal is not responsible for any consequences arising from actions taken based on the information provided on this website. Users should seek independent legal advice for specific concerns. 7. All content on this website is the intellectual property of DRN Legal.

bottom of page