A customer support ticket flags a strange pattern: hundreds of units of a bestselling SKU show "in stock" on the website but are missing from the warehouse. Around the same time, a competitor launches an eerily similar product. Was this a system glitch, an inside job, or a data breach? The only way to answer that question with certainty, and to make it stand up in court, is cyber forensics. As e-commerce platforms handle growing volumes of transactions, customer data, and inventory records, understanding how digital evidence is uncovered and used has become essential knowledge for anyone studying or working in online retail.
Table of Contents
- What exactly is cyber forensics?
- Why e-commerce businesses cannot afford to ignore it
- Common scenarios that call for a forensic investigation
- The legal backbone: how digital evidence gets its power in India
- How a cyber forensic investigation actually unfolds
- Chain of custody: the evidentiary lifeline
- Building organisational readiness
- Challenges that still slow things down
What exactly is cyber forensics?
Cyber forensics, also called digital forensics, is the application of forensic tools and technical expertise to recover electronic evidence in a manner that satisfies the rules of evidence and is admissible before a court of law. It is not simply about retrieving deleted files. The evidence gathered must trace a perpetrator’s digital footprints through careful preservation, extraction, interpretation, and documentation, as explained in this overview of cyber forensic law and practice.
In simple terms, cyber forensics answers three questions after an incident: what happened, who did it, and can it be proven beyond doubt? For a retail business, that could mean tracing who accessed a customer database, when a server log was altered, or whether an employee exported inventory data before resigning.
Why e-commerce businesses cannot afford to ignore it
Retail and e-commerce operations sit on a goldmine of sensitive data, customer profiles, payment details, vendor contracts, and real-time inventory records. This makes them attractive targets. Cyber forensics becomes critical whenever a business needs to demonstrate what actually happened during a breach, both to satisfy regulators and to support any legal action against the offender.
Common scenarios that call for a forensic investigation
- Inventory fraud: Stock records manipulated to hide theft or divert goods, often by insiders with system access.
- Data theft: Customer databases or pricing algorithms copied and leaked to competitors, which requires digital forensic evidence to prove unauthorised access and copying.
- Payment fraud: Fraudulent transactions or chargebacks that need transaction-log analysis to trace the actual point of compromise.
- Account takeovers: Customer or seller accounts hijacked through credential theft, requiring log correlation to identify the intrusion point.
The legal backbone: how digital evidence gets its power in India
For decades, Indian courts relied on the Indian Evidence Act, 1872, a law drafted long before computers existed. The Information Technology Act, 2000 changed this by granting legal recognition to electronic records and amending the Evidence Act to define what counts as admissible digital evidence. This legal framework introduced Sections 65A and 65B, which specifically govern how electronic records can be presented in court, including the requirement of a certificate confirming the authenticity of the record.
Two Supreme Court judgments shaped how strictly this rule is applied. In Anvar P.V. v. P.K. Basheer (2014), the court held that electronic evidence submitted without following Section 65B procedure cannot be admitted. This was reaffirmed in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020), where the Supreme Court restated that Section 65B certification is mandatory for electronic evidence to even be considered relevant. For a business, this means that simply printing out a server log is not enough. The evidence has to be certified and handled correctly from the moment it is collected.
India has since gone a step further. The Bharatiya Sakshya Adhiniyam, 2023, replaced the colonial-era Evidence Act from July 2024, explicitly recognising electronic and digital records as primary evidence rather than treating them as a special exception. On the technical side, Section 79A of the IT Act empowers the government to notify official Examiners of Electronic Evidence, government-approved forensic labs whose expert opinion carries weight before courts and other authorities.
How a cyber forensic investigation actually unfolds
A forensic investigation is not a single act of “finding the evidence.” It follows a structured sequence designed to protect the integrity of the data at every stage.
| Stage | What happens |
|---|---|
| Identification | Determining which systems, devices, or accounts may hold relevant evidence. |
| Preservation | Securing the evidence in its original state so it cannot be altered, often using write-blockers on storage devices. |
| Collection | Creating exact, bit-for-bit copies of data such as file systems, server logs, or device memory. |
| Examination and analysis | Reviewing the collected data to reconstruct a timeline and identify what happened and who was involved. |
| Documentation and presentation | Preparing a report and, where required, expert testimony that can withstand scrutiny in court. |
Common sources of forensic data include file system records, application logs, and even a device’s random access memory, which can hold traces of activity that never get written to disk, as outlined in this explanation of digital forensics and incident response.
Chain of custody: the evidentiary lifeline
Even a technically perfect investigation is worthless in court if the chain of custody is broken. Chain of custody refers to the unbroken, documented trail showing exactly who collected a piece of evidence, when, how it was stored, and who accessed it afterward. If there is a gap in this record, opposing counsel can argue the evidence was tampered with, and it may be thrown out entirely.
A defensible chain of custody typically involves:
- Identification: Clearly marking and recording the evidence at the point of discovery.
- Documentation: Logging who collected it, along with the exact time, date, and method used.
- Secure storage: Keeping the evidence in a controlled environment that limits access, as detailed in this breakdown of chain of custody in cybersecurity litigation.
- Transfer records: Documenting every handover between individuals, including the reason for the transfer.
Building organisational readiness
Waiting until a breach happens to figure out forensic procedures is a costly mistake. Regulatory expectations in India have also become far stricter. The Indian Computer Emergency Response Team requires covered organisations to report specified cyber incidents within a strict six-hour window of becoming aware of them, along with maintaining system logs for a rolling period of 180 days, as laid out in the CERT-In directions on mandatory incident reporting. For an e-commerce company running payment gateways, seller dashboards, and customer apps, this leaves very little room for improvisation.
Practical readiness for a retail or e-commerce business includes:
- Written data preservation policy: Clear rules on how long logs, transaction records, and access histories are retained, and how they are protected from accidental deletion.
- Access controls and logging: Every system with customer or inventory data should log who accessed what and when, since this becomes the raw material for any future investigation.
- An incident response plan: A predefined escalation path so that when something looks wrong, evidence is preserved immediately rather than after the fact.
- Engaging certified forensic experts: Whether in-house or external, having access to professionals who can testify credibly protects the integrity of any case the business later needs to pursue.
Challenges that still slow things down
Despite a strong legal framework, execution remains uneven. Lower courts in India, particularly at the district level, are often not equipped to interpret complex digital evidence, which can delay proceedings even when the forensic work itself is sound. Encryption, cloud storage spread across multiple jurisdictions, and the sheer volatility of digital data, such as memory contents that vanish once a device is powered off, add further complexity. This is precisely why the “preservation” stage of forensic work matters so much: evidence that is not captured quickly may simply cease to exist.
For a B.Com student stepping into e-commerce, retail operations, or compliance roles, understanding this intersection of technology and law is no longer optional. Businesses increasingly need people who can bridge the gap between the IT team investigating an incident and the legal team building a case around it.
What do you think? If your college’s online examination portal reported a sudden mismatch in submitted assignments, what is the very first piece of digital evidence you would want preserved before anything else? And how prepared do you think most Indian retail businesses actually are to meet a six-hour incident reporting deadline?
References
- https://blog.ipleaders.in/cyber-forensics-law-and-practice-in-india/
- https://www.7boats.com/academy/cyber-law-case-studies-it-act-forensics/
- https://finlawassociates.com/blog/legal-framework-governing-digital-evidence-in-india-an-in-depth-analysis-of-cyber-forensic-law
- https://www.jusscriptumlaw.com/post/digital-evidence-and-cyber-law-integration
- https://www.stqc.gov.in/digital-forensics
- https://www.ibm.com/think/topics/dfir
- https://eviden.com/publications/digital-security-magazine/detect-early-respond-swiftly/chain-of-custody-the-importance-of-correct-evidence-collection-for-the-litigation-process/
- https://natlawreview.com/article/cyber-security-india-revamps-rules-mandatory-incident-reporting-allied-compliances
Leave a Reply