Banking & Payments · India
Aadhaar & AePS Fraud (India)
Most scams need you to tap something, say something, or send something. This one doesn’t. Money can leave your account using only your Aadhaar number and a copy of your fingerprint — no OTP, no card, and no call to ignore.
Updated Sep 2026 · 7 min read
SMS · Bank Alert
“Rs 10,000.00 debited from A/c XX4821 on 14-09-26 via AEPS at BC terminal. Bal: Rs 2,317.00.”
The Aadhaar-enabled Payment System was built for a good reason. It lets someone in a village withdraw their wages or pension at a local shop-front banking point with nothing but their Aadhaar number and a fingerprint — no card, no smartphone, no branch visit. Millions of people depend on it.
The problem is what that convenience assumes: that your fingerprint is private. It isn’t. It sits on property papers, rent agreements, and forms you filled in years ago, some of which have ended up online. Copy it well enough to fool a cheap scanner, pair it with an Aadhaar number, and cash can be pulled from an account without its owner ever touching a phone.
That sounds hopeless. It isn’t — because UIDAI gives you a free switch that turns the whole attack off.
The one fact that ends this scam
Your fingerprint is a username, not a password — you have been handing out copies of it for years. So lock your Aadhaar biometrics at UIDAI. Locked, your fingerprint authenticates nothing, anywhere, until you choose to unlock it.
myaadhaar.uidai.gov.in or the mAadhaar app → Lock/Unlock Biometrics. It’s free, it takes two minutes, it covers every bank linked to your Aadhaar at once, and you can unlock it whenever you genuinely need to authenticate.
How the Scam Works
Your details leak
Your Aadhaar number and a fingerprint impression sit on documents you handed over long ago — a property or land registration, a rent agreement, a SIM or gas-connection form, a photocopy left at a shop. Some of those records have been published online or resold in bulk.
The fingerprint is copied
A print lifted from a scanned document or a form is reproduced on silicone, rubber, or polymer film — good enough to satisfy a cheap fingerprint scanner. Nobody has to touch your hand, or even meet you.
The withdrawal
At a “Business Correspondent” or micro-ATM kiosk — the small shop-front banking points found in most towns and villages — someone enters your Aadhaar number, picks your bank, and presses the copied print. AePS needs nothing else. There is no OTP to approve and no card to block.
It happens again
Each AePS cash withdrawal is capped, so the amounts look small. They simply repeat it — across days, across banks linked to the same Aadhaar, and often from a district you have never visited.
You find out late
Usually from a debit SMS, a passbook update, or a failed payment weeks later. By then the cash is gone and the kiosk operator is a dead end — which is why the one defence below matters more than anything else on this page.
The Other Half: Aadhaar Phishing
Not every Aadhaar scam is silent. A second, much louder set of them comes straight to your phone, and every one is after the same two things: the OTP sent to your registered mobile, or an app installed on your handset.
- “Your Aadhaar will be deactivated” — an SMS or WhatsApp message with a link to a fake UIDAI page that harvests your Aadhaar number, mobile, and OTP.
- “Free Aadhaar update before the deadline” — a fake site or agent charging a fee for something UIDAI offers through its own official channels.
- An “Aadhaar Update” APK sent on WhatsApp — installing it hands over your SMS, which means every OTP you receive.
- A caller “from the bank” asking you to confirm the Aadhaar OTP you just received, to “re-link” or “re-KYC” your account.
- “Your Aadhaar was used in a money-laundering case” — the opening line of the digital-arrest scam, not a real investigation.
The rule for all five is the same: UIDAI never sends you a link to fix your Aadhaar, and nobody legitimate ever needs the OTP that arrives on your phone.
Red Flags
- A debit SMS mentioning “AEPS”, “BC”, “micro ATM”, or a branch or district you’ve never been to.
- Several small withdrawals you can’t account for, spread over days.
- Anyone asking you to press your finger on a scanner for a “survey”, ration, SIM re-verification, or “government scheme” you didn’t apply for.
- A call, SMS, or WhatsApp saying your Aadhaar is “suspended”, “deactivated”, or “must be re-verified” through a link.
- Anyone asking for the 6-digit Aadhaar OTP — UIDAI and your bank never ask for it.
- An “Aadhaar Update” or “UIDAI” app sent as an APK file instead of from the official app store.
- An agent offering to update your Aadhaar for a fee outside an official Aadhaar Seva Kendra.
- A shop or office keeping a plain photocopy of your Aadhaar with no stated purpose.
Got an “Aadhaar” Message You’re Not Sure About?
Paste the SMS or WhatsApp message in and see the pressure tactics, fake-link tricks, and OTP bait picked apart — before you tap anything.
Open the Scam Message Analyzer →How to Protect Yourself
- Lock your Aadhaar biometrics today at myaadhaar.uidai.gov.in or in the mAadhaar app. Unlock only for the few minutes you actually need to authenticate, then lock it again.
- Check your Aadhaar authentication history on myAadhaar every month or two — it lists where and when your Aadhaar was used, so an entry you don’t recognise is an early warning.
- Turn on SMS and email alerts for every bank account, and read them. AePS fraud is usually caught by one debit message nobody opened.
- Ask your bank to disable AePS, or set its limit to zero, on any account where you never use it.
- Use a Virtual ID (VID) or masked Aadhaar instead of your full number wherever it’s accepted.
- Never share the Aadhaar OTP sent to your registered mobile — not with a caller, an agent, a shop, or anyone claiming to be from your bank or UIDAI.
- Write the purpose and the date across any Aadhaar photocopy you hand over, and never leave a spare copy with a shop.
- Never press your finger on a scanner offered by a stranger — for a survey, a scheme, a SIM check, or a “verification” you didn’t start.
- Use only uidai.gov.in, myaadhaar.uidai.gov.in, the mAadhaar app from the official store, or the 1947 helpline. Never an APK, and never a link that arrived in a message.
Can You Get Your Money Back?
Honest answer: it depends almost entirely on how you paid and how fast you act. Speed is everything — report within hours, not days.
- Credit cardOften
You can dispute the charge (a “chargeback”) through your card network. The strongest protection of any payment type.
- Bank transfer, UPI or debit cardSometimes — if you’re fast
Report within hours so the bank can try to freeze the receiving account before the money is moved on. In India, call 1930 or file at cybercrime.gov.in immediately.
- Payment apps (Zelle, Venmo, Cash App, PayPal)Varies
Often treated like cash. PayPal “Goods & Services” has buyer protection; “friends & family” and most instant transfers usually don’t. Report to the app and your bank.
- Gift cardsRare
Contact the card issuer immediately — occasionally they can freeze an unredeemed balance. After that, it’s almost always gone.
- CryptocurrencyHardest — usually not
Crypto transfers are irreversible and cross-border. Recovery is rare, but act fast: report the transaction (with the wallet address and transaction hash) to the exchange involved and to law enforcement. If the funds land in a regulated exchange, it can sometimes freeze them.
What Actually Helps
- 1Act immediately — the faster you report, the better any chance of a freeze or reversal.
- 2Contact your bank, card issuer, or payment app now and ask them to dispute, recall, or freeze the payment.
- 3Report it to the authorities — here’s who to contact wherever you live. You often need a police or report reference number to pursue a dispute.
- 4Save everything: transaction IDs, wallet addresses, screenshots, phone numbers and usernames.
!Beware “recovery” scams
After you’ve been scammed, you may be contacted by someone promising to recover your money for an upfront fee, a “tax”, or a crypto payment. That is a second scam — often run by the same people, working from lists of known victims. No legitimate agency, lawyer, or service guarantees recovery or asks you to pay up front, and real police and banks never charge you to investigate. Never pay anyone to get your money back.
If Money Has Already Gone
With AePS fraud the clock decides two things — whether the cash can be traced, and who ends up bearing the loss. Do these in order, and do the first two the same day you notice:
- Lock your biometrics now: at myaadhaar.uidai.gov.in or in mAadhaar — it stops any further withdrawal while everything else is in progress.
- Tell your bank in writing: report the unauthorised AePS transactions by email and at the branch, ask for AePS to be disabled on the account, and keep the complaint reference number. Under RBI’s limited-liability rules, reporting within three working days usually means zero liability when you weren’t at fault.
- Report the crime: call the cybercrime helpline 1930 and file at cybercrime.gov.in — the sooner you do, the better the chance of tracing the terminal and freezing funds.
- UIDAI: call 1947 or use the grievance form on uidai.gov.in to flag misuse of your Aadhaar, and download your authentication history as evidence.
- If the bank stalls: escalate to the RBI Ombudsman at cms.rbi.org.in once 30 days have passed without a resolution.
- Preserve evidence: the debit SMS, the statement showing the AePS entries, your written complaint and its reference number, and your Aadhaar authentication history.
- Ignore anyone who contacts you afterwards offering to “recover” the money for an upfront fee — that’s a second scam aimed at victims.
Where to Report — Wherever You Are
In India, lock your Aadhaar biometrics, report the unauthorised transactions to your bank in writing the same day, then call 1930 and file at cybercrime.gov.in — reporting within three working days is what protects you from bearing the loss. Reporting fast gives the best chance of freezing the money before it’s gone. Then file with your national authority:
India — Helpline 1930 · cybercrime.gov.in
Report in the first hours (the “golden hour”) to freeze funds. Run by I4C, Ministry of Home Affairs.
United States — FTC · FBI IC3
reportfraud.ftc.gov and ic3.gov.
United Kingdom — Action Fraud
actionfraud.police.uk · 0300 123 2040 (in Scotland, call Police Scotland on 101).
Australia — Scamwatch (National Anti-Scam Centre)
scamwatch.gov.au.
Canada — Canadian Anti-Fraud Centre
antifraudcentre-centreantifraude.ca · 1-888-495-8501.
Anywhere else: contact your bank and local police right away, and search “report a scam” plus your country. For cross-border cases, econsumer.gov collects international complaints. Beware anyone who later offers to “recover” your money for an upfront fee — that is a second scam.
Frequently Asked Questions
What is AePS, and why is it risky?
The Aadhaar-enabled Payment System lets someone withdraw cash from a bank account at a Business Correspondent or micro-ATM using just an Aadhaar number and a fingerprint. It exists so people without cards or smartphones can bank locally, and it works well for that. The risk is the authentication: a fingerprint is not a secret — it sits on documents you have already signed — and unlike a UPI or card payment, an AePS withdrawal sends you no OTP to approve.
How do I lock my Aadhaar biometrics?
On the official UIDAI site (myaadhaar.uidai.gov.in) or in the mAadhaar app, use “Lock/Unlock Biometrics”. Once locked, your fingerprint and iris can’t authenticate anything until you unlock them — which takes a minute when you genuinely need it. It is free, reversible, and the single most effective step in this guide.
Can someone take my money with only my Aadhaar number?
No. The number alone isn’t enough — an AePS withdrawal also needs your fingerprint, and Aadhaar eKYC needs the OTP sent to your registered mobile. That’s why the two rules are: lock your biometrics, and never read out an Aadhaar OTP to anyone.
Is it safe to give my Aadhaar as ID at all?
Yes, to legitimate bodies — but give as little as possible. Use a Virtual ID (VID) or a masked Aadhaar (it hides the first eight digits) wherever they’re accepted, and write the purpose and the date across any photocopy you hand over.
Money was withdrawn through AePS. Will my bank refund it?
Often, yes — but speed decides it. Under RBI’s rules on unauthorised electronic transactions, a customer who isn’t at fault and reports within three working days generally bears zero liability; delay increases what you may have to bear. Report in writing to your bank the same day, keep the complaint reference, and escalate to the RBI Ombudsman (cms.rbi.org.in) if it isn’t resolved in 30 days.
I got a message saying my Aadhaar will be deactivated. Is it real?
No. UIDAI doesn’t send deactivation warnings by SMS or WhatsApp with a link to fix it. Ignore the link, and check anything Aadhaar-related only on uidai.gov.in or through the 1947 helpline.
I never use AePS. Can I switch it off?
Ask your bank — many now let you disable AePS or set its limit to zero on your account, and some let you do it in the banking app. Locking your biometrics at UIDAI protects every bank linked to your Aadhaar at once, so do that first either way.
Related: the “KYC update” scam, UPI scams (India), or the “digital arrest” scam.
Informational only — not legal or financial advice. Sources: UIDAI guidance on biometric locking, Virtual ID and masked Aadhaar (uidai.gov.in, helpline 1947), NPCI documentation on the Aadhaar-enabled Payment System, RBI directions on customer liability in unauthorised electronic banking transactions, and the national cybercrime helpline (1930) and cybercrime.gov.in. Rules and limits change — verify against primary sources.