By:
CA Anil K. Jain
Chartered
Accountant | Economist | Policy Researcher | Author
President – Ahimsa Foundation India
Email: CAINDIA@HOTMAIL.COM
1.
Introduction
The
judge is the guardian of the courtroom, the arbiter of facts, and the custodian
of the judicial conscience. In the discharge of these duties, the judge handles
the most sensitive information in society: the evidence in a murder trial, the
financial secrets in a corporate dispute, the intimate details of a matrimonial
breakdown, the classified documents in a national security case. The judge's
chambers, once a sanctum of paper files and physical security, is now a node in
a vast digital network. The eCourts project has digitised case records. Virtual
hearings have become routine. Judgments are drafted on laptops, stored on cloud
servers, and delivered via video conferencing. The judge communicates with the
registry, with colleagues, and with counsel through email and messaging
platforms.
This
digital transformation has made the judiciary more efficient and accessible.
But it has also made the judge a target. A judge's email account, if
compromised, can expose the confidential deliberations of the bench. A judge's
smartphone, if infected with spyware, can become a listening device in
chambers. A ransomware attack on a district court's server can paralyse the
justice delivery system for an entire district. The 2021 Pegasus Project
revelations, which alleged that the phones of sitting Supreme Court judges were
targeted by sophisticated spyware, were a stark warning that the highest
echelons of the judiciary are not immune. A deepfake video of a judge making a
controversial statement can erode public faith in the institution. A phishing
email disguised as a communication from the Supreme Court registry can trick a
judicial officer into handing over his credentials.
Cybersecurity
for judges is therefore not a matter of personal convenience or technical
curiosity. It is a core component of judicial independence and the integrity of
the justice system. This chapter explores the cyber threats facing the Indian
judiciary, outlines the legal and ethical duties of judges in the digital
domain, and provides a practical framework for securing judicial work in an age
of persistent threat.
Quotation:
"The
independence of the judiciary rests on two pillars: the fearlessness of the
judge and the confidentiality of the judicial process. In the digital age, both
are vulnerable to cyber attack. A judge who does not understand cybersecurity
is like a judge who does not understand the law of evidence—incomplete." —
Justice K.S. Puttaswamy (Retd.), in a 2022 lecture on technology and the
judiciary.
2.
The Judge's Digital Ecosystem
The
modern Indian judge interacts with a complex array of digital systems, each of
which represents a potential vulnerability.
- The eCourts
System: The National Judicial Data Grid
(NJDG) and the Case Information System (CIS) form the backbone of the
digital judiciary. Judges access case files, track case status, and upload
orders and judgments through these platforms. The eCourts portal (ecourts.gov.in) provides
public access to case information. A breach of this system could expose
the entire case history of millions of litigants.
- Judgment
Drafting and Storage: Judgments are drafted on
laptops and desktop computers, often using word processing software that
stores metadata—the author's name, the editing history, the time spent on
each paragraph. Draft judgments stored on unencrypted devices or shared
via unsecured email are vulnerable to interception.
- Virtual
Hearing Platforms: The COVID-19 pandemic
accelerated the adoption of virtual courts. Platforms such as Vidyo, Cisco
Webex, and Microsoft Teams are used for hearings. These sessions generate
recordings, chat logs, and metadata. An uninvited participant in a virtual
hearing (a "Zoombombing" equivalent) can disrupt proceedings and
breach confidentiality.
- Email and
Official Communication: Judges
communicate with the registry, with other judges, and with counsel via
email. Official email accounts contain a treasure trove of confidential
information: case lists, administrative orders, correspondence with the
Chief Justice's office, and reference material.
- Personal
Devices: Many judges use personal
smartphones, tablets, and home computers for judicial work. These devices
may be shared with family members, connected to insecure home Wi-Fi
networks, and lack the security controls of official systems.
- Social Media: Some
judges maintain a presence on social media platforms. While this can
enhance public engagement, it also creates a vector for impersonation,
targeted phishing, and reputational attacks.
Example: In
2022, a district judge in Rajasthan found that her official email account had
been accessed from an unfamiliar IP address. The attacker had used a phishing
email disguised as a communication from the High Court registry to obtain her
credentials. The email account contained case-related correspondence and
personal data of litigants. The breach was detected within 24 hours, and the
account was secured, but the incident exposed the vulnerability of judicial
email systems. The High Court subsequently mandated multi-factor authentication
for all judicial email accounts.
Quotation:
"The
judge's laptop is the modern equivalent of the judge's notebook. It contains
the first impressions, the legal reasoning, the tentative conclusions. If it is
not secure, the entire judicial process is laid bare." — Dr. Gulshan Rai,
former National Cyber Security Coordinator, in a 2023 address to judicial
officers.
3.
Cyber Threats Specific to Judges
The
threats facing the judiciary are targeted, sophisticated, and often motivated
by a desire to influence, embarrass, or intimidate the individual judge or the
institution.
3.1.
Phishing and Credential Theft Targeting Judges
Judges
receive a high volume of official communication, making them vulnerable to
phishing. An email that appears to be from the Supreme Court registry, the High
Court administrative office, or the eCourts technical support team can trick a
judge into clicking a malicious link or entering credentials on a fake portal.
The attacker may be a litigant seeking case information, a foreign intelligence
agency conducting espionage, or a criminal syndicate seeking to influence a
trial.
Example: In
2023, a phishing campaign targeted judges of a southern High Court with emails
purporting to be from the "eCourts Security Team," warning of a
compromise of their accounts and providing a link to "reset
credentials." At least two judicial officers clicked the link and entered
their credentials. The High Court administration detected the breach through
anomalous login patterns and forced a password reset for all judicial accounts.
The incident prompted the eCommittee of the Supreme Court to issue a circular
reinforcing cybersecurity protocols.
3.2.
Spyware and Surveillance
The
most sophisticated threat to judicial cybersecurity is targeted spyware. The
Pegasus spyware, developed by the Israeli company NSO Group, was capable of
zero-click infection—meaning it could be installed on a phone without the user
clicking any link. Once installed, it gave the operator access to all messages,
emails, passwords, call logs, and the device's microphone and camera. The
Pegasus Project (2021) revealed that phone numbers of sitting Supreme Court
judges were on a list of potential targets. While the Government of India
neither confirmed nor denied the use of Pegasus, the Supreme Court constituted
an expert committee that found serious privacy concerns. The case, Manoj
Mittal v. Union of India (2022), underscored the vulnerability of even
the most powerful judicial figures to digital surveillance.
Impact: If
a judge's phone is compromised, every conversation in chambers, every draft
judgment, and every private deliberation with a colleague can be monitored by
the attacker. The chilling effect on judicial independence is profound.
3.3.
Ransomware on Court Systems
District
court systems across India are being digitised at a rapid pace, but their
cybersecurity budgets and expertise often lag behind. A ransomware attack on a
district court's server can encrypt case records, cause hearings to be
adjourned, and disrupt justice delivery for weeks. In 2023, the eCommittee of
the Supreme Court issued guidelines for cybersecurity in district courts,
noting that the increasing digitisation of court records made them a prime
target for cybercriminals.
3.4.
Deepfakes and Impersonation
A
deepfake video of a judge making a communal statement or accepting a bribe can
be created in minutes using freely available AI tools. Once released on social
media, it can cause irreparable damage to the judge's reputation and the
public's faith in the judiciary before any fact-check can catch up. Similarly,
fraudsters can create fake social media profiles of judges to solicit money or
information.
3.5.
Doxxing and Personal Threats
The
personal information of judges—home addresses, phone numbers of family members,
school details of children—can be leaked online (doxxed) by disgruntled
litigants or organised hate campaigns. This exposes the judge and his family to
physical danger and psychological harassment.
3.6.
Insider Threats
The
judge's staff—the personal assistant, the stenographer, the bench clerk—have
access to sensitive judicial information. A compromised, disgruntled, or
careless staff member can leak draft judgments, confidential correspondence, or
case records. The risk is amplified in the digital age, where a single USB
drive can carry the entire case load of a judge.
Quotation:
"The
judge who thinks that cybersecurity is only for IT departments is living in a
fool's paradise. The spyware does not discriminate between the IT server and
the judge's personal phone. The attack surface is everywhere." — Justice
R.F. Nariman, in a 2023 lecture on law and technology.
4.
Legal and Ethical Obligations
The
judge's duty to maintain cybersecurity is rooted in constitutional principle,
statutory law, and judicial ethics.
- The
Constitution of India: The independence of the
judiciary is a basic feature of the Constitution. An independent judiciary
requires that judicial deliberations be confidential and free from
external surveillance, influence, or intimidation. A cyber breach that
compromises this confidentiality strikes at the heart of judicial
independence.
- Digital
Personal Data Protection Act, 2023 (DPDP Act): The
judiciary, as a public authority processing personal data of litigants, is
a Data Fiduciary under the Act. While judicial functions may enjoy certain
exemptions under the Act, the court administration—the registry, the IT
cell—is subject to the obligations of data protection. The personal data
of litigants contained in case files must be protected by reasonable
security safeguards.
- Information
Technology Act, 2000: The IT Act criminalises
hacking, identity theft, and unauthorised access. These provisions protect
judicial systems as much as any other computer system. Section 70 allows
the government to declare judicial servers as "protected
systems," with enhanced penalties for breach.
- The Bangalore
Principles of Judicial Conduct, 2002: Endorsed
by the United Nations and adopted by the Indian judiciary, these
principles require judges to uphold the integrity and independence of the
judiciary. Value 4 (Propriety) requires judges to avoid impropriety and
the appearance of impropriety in all their activities. A judge who
negligently allows his digital devices to be compromised, leading to a
leak of confidential judicial information, may be seen as having failed in
this duty.
- The
Restatement of Values of Judicial Life, 1999: Adopted
by the Supreme Court of India, this code of conduct for judges includes
the principle that "a judge should not communicate with lawyers or
litigants in a manner that may give rise to an impression of
impropriety." In the digital context, this requires secure,
professional channels of communication.
- eCommittee of
the Supreme Court: The eCommittee has issued
several circulars and guidelines on the use of technology in courts,
including cybersecurity protocols. These include directives on the use of
official email accounts, the security of virtual hearings, and the
protection of judicial data. These are administrative instructions that
bind the judiciary.
Quotation:
"Judicial
ethics in the digital age must expand to encompass digital hygiene. A judge who
secures his devices, uses strong passwords, and is vigilant against phishing is
not merely protecting himself; he is protecting the institution." — Justice
B.N. Srikrishna, in a 2024 lecture on judicial ethics and technology.
5.
Practical Cybersecurity Measures for Judges
The
following measures are practical, actionable, and should become part of the
standard operating procedure for every judicial officer.
5.1.
Device Security
- Use official
devices for judicial work. Personal devices should not be used for
accessing court systems, drafting judgments, or storing case-related data.
If a personal device must be used, it should be secured to the same
standard as an official device.
- Encrypt the
hard drives of all devices used for judicial work. Full-disk
encryption (BitLocker for Windows, FileVault for Mac) ensures that data is
unreadable if the device is lost or stolen.
- Enable
automatic updates for the operating system and all software. Many
cyber attacks exploit known vulnerabilities for which patches already
exist.
- Install and
maintain reputable antivirus or endpoint protection software.
- Disable
unnecessary features: Bluetooth, Wi-Fi, and location services should
be turned off when not in use. The camera and microphone of a device
should be physically covered when not in active use.
5.2.
Account and Password Security
- Use strong,
unique passwords for every account. A password manager can assist.
- Mandate
multi-factor authentication (MFA) on all official accounts: email,
eCourts portal, video conferencing platforms, and cloud storage. MFA is
the single most effective defence against credential theft.
- Never share
passwords with staff, family, or colleagues.
- Log out of
accounts after each session, especially on shared or public devices.
5.3.
Secure Communication
- Use official
email accounts provided by the court for all judicial communication.
Avoid using personal email accounts (Gmail, Yahoo) for court work.
- Verify the
identity of the sender before opening attachments or clicking links
in emails. Be particularly cautious of emails that create urgency or fear.
- Use secure
video conferencing platforms as designated by the court. Enable all
security features: meeting passwords, waiting rooms, and participant
authentication. Do not record hearings on personal devices without clear
authorisation.
- Do not
discuss confidential case matters over unencrypted channels like
WhatsApp or SMS. Use secure, court-approved communication systems for
sensitive discussions.
5.4.
Handling Case Data and Draft Judgments
- Store case
files and draft judgments on the court's secure servers, not on
personal cloud services (Google Drive, Dropbox) unless explicitly
authorised and secured.
- Do not leave
laptops, tablets, or printed case papers unattended in courtrooms,
chambers, or public places.
- Dispose of
digital data securely. When a device is decommissioned, ensure that
the data is destroyed using certified data destruction methods, not simply
deleted.
- Be aware of
metadata. Word processing files contain hidden metadata that can
reveal the author, editing history, and time spent on a document. Before
sharing a judgment or order electronically, consider whether the metadata
should be removed.
5.5
Training and Awareness
- Undergo
regular cybersecurity awareness training. This should be mandated by
the judicial academy and the High Court administration. Training should be
practical, using real-world examples of threats targeting the judiciary.
- Train the
staff. The stenographer, the PA, and the bench clerk are all part of
the judge's digital perimeter. They must be trained to recognise phishing,
handle sensitive data securely, and report suspected incidents.
- Stay
informed. Cyber threats evolve rapidly. Judicial officers should
receive periodic updates from the court's IT security team or from CERT-In
on emerging threats.
Quotation:
"A
judge who can master the complexities of the Evidence Act and the Civil
Procedure Code can certainly master the simple rules of digital hygiene. It is
a matter of will, not capacity." — Justice D.Y. Chandrachud, in a 2023
address on judicial training.
6.
Incident Response for Judges
Every
judge should know what to do if he suspects a cyber breach. The immediate steps
are:
- Do not
panic. Do not attempt to delete files or "fix" the problem
yourself, as this may destroy evidence.
- Disconnect
the affected device from the internet and from any network
immediately. This prevents the attacker from continuing to access the
device or spreading malware.
- Report the
incident immediately to the court's IT security officer, the High
Court computer cell, and the police cyber cell if appropriate. Do not
delay out of embarrassment. Prompt reporting can contain the damage.
- Preserve
evidence. Do not tamper with the compromised device. It may be needed
for forensic analysis.
- Change
passwords for all accounts that may have been compromised, using a
different, uncompromised device.
- Notify
affected parties if the breach involved litigant data, in accordance
with the DPDP Act and court guidelines.
7.
The Judge as the Gatekeeper of Digital Evidence
The
judge is not only a potential victim of cyber crime; he is the ultimate arbiter
of digital evidence in the courtroom. The quality of justice in cyber crime
cases depends significantly on the judge's ability to understand, evaluate, and
weigh digital evidence. This imposes a duty of digital literacy.
- Understanding
Digital Evidence: The judge must understand
the basic principles of digital evidence: the volatility of electronic
data, the importance of the chain of custody, the role of hash values in
verifying integrity, and the distinction between a forensic image and a
simple copy. Without this understanding, the judge cannot effectively
evaluate the admissibility of digital evidence under the Bharatiya Sakshya
Adhiniyam, 2023.
- Evaluating
Expert Testimony: Cyber crime trials rely
heavily on expert testimony from forensic analysts. The judge must be able
to assess the qualifications of the expert, the validity of the
methodology used, and the reliability of the tools employed. The Supreme
Court's observations in Arjun Panditrao Khotkar v. Kailash
Kushanrao Gorantyal (2020) on the mandatory certification of
electronic records are essential reading.
- Guarding
Against the Technological Mystique: There is a
risk that digital evidence, with its aura of scientific precision, is
either accepted uncritically or rejected out of suspicion. The judge must
steer a middle path: critically evaluating the evidence while not
excluding it simply because it is technical. The evidence must be
explained in terms that the judge, the lawyers, and the litigants can
understand.
- Continuous
Judicial Education: The National Judicial
Academy and the state judicial academies must integrate digital forensics
and cyber law into their core curriculum. Every judge, from the junior
civil judge to the Supreme Court justice, should have a foundational
understanding of digital evidence.
Quotation:
"The
judge who cannot distinguish a WhatsApp chat from a server log is at the mercy
of the expert witness. Judicial independence in the age of digital evidence
requires digital literacy." — Dr. Arun Mohan, Cyber Forensics Expert,
National Forensic Sciences University, in a 2023 training for judges.
8.
Conclusion
The
judge stands at the apex of the justice system, a figure of authority,
impartiality, and trust. That trust is built on the confidence that the judge's
deliberations are his own, that his decisions are uninfluenced by fear or
favour, and that the evidence before him is evaluated with wisdom and
integrity. In the digital age, each of these pillars is under assault. The
spyware that listens in chambers, the phishing email that steals credentials,
the ransomware that locks court records, the deepfake that defames—these are
the new weapons aimed at the heart of the judiciary.
The
response must be multi-layered. At the institutional level, the Supreme Court's
eCommittee, the High Courts, and the government must invest in a secure,
resilient digital infrastructure for the courts, with dedicated cybersecurity
teams, regular audits, and rapid incident response. At the individual level,
every judge must embrace cybersecurity as a personal and professional
discipline. The habits of digital hygiene—strong passwords, multi-factor
authentication, scepticism of unsolicited emails—must become as ingrained as
the habits of punctuality and courtroom decorum.
The
Bangalore Principles of Judicial Conduct state that a judge shall "uphold
the integrity and independence of the judiciary." In the twenty-first
century, that duty is discharged as much through the firewall as through the
judgment. The secure judge is the independent judge. The digitally literate
judge is the just judge.
Quotation:
"The
temple of justice is not built of stone alone; it is built of trust. In the
digital age, the keys to that temple are passwords, encryption, and vigilance.
The judges who hold those keys must guard them with their lives, for they guard
the faith of a billion people in the rule of law." — Justice K.M. Joseph,
in a 2024 convocation address.
Chapter References
1.
Manoj Mittal v. Union of India,
W.P.(C) 1046/2021 (Supreme Court, Pegasus spyware case).
2.
Arjun Panditrao Khotkar v. Kailash
Kushanrao Gorantyal, (2020) 7 SCC 1.
3.
Digital Personal Data Protection Act,
2023, Sections 5, 6, 8, Schedule.
4.
Information Technology Act, 2000, Sections
43, 66, 70.
5.
The Bangalore Principles of Judicial
Conduct, 2002.
6.
Supreme Court of India, Restatement
of Values of Judicial Life, 1999.
7.
eCommittee, Supreme Court of India, Guidelines
for Cybersecurity in District Courts, 2023.
8.
eCommittee, Supreme Court of India, Circular
on the Use of Official Email and Virtual Hearing Security, 2022.
9.
CERT-In, Directions on Information
Security Practices, April 2022.
10. National
Judicial Academy, Cyber Law and Digital Forensics Training Module,
2023.
No comments:
Post a Comment