No agency suspends your Aadhaar over a phone call, and UIDAI never asks you to update Aadhaar through an SMS link, a WhatsApp message, or an APK download. The dangerous new twist is the Aadhaar-enabled Payment System (AePS): criminals harvest Aadhaar numbers and fingerprints from leaked land records, clone the fingerprint in silicone, and withdraw cash from your bank account with no OTP and no PIN. The single most effective protection is to lock your Aadhaar biometrics on the UIDAI myAadhaar portal or mAadhaar app. If you have already lost money, call 1930 and report at cybercrime.gov.in the same day.
Key facts
- The Aadhaar-enabled Payment System (AePS) authenticates cash withdrawals with your Aadhaar number and a fingerprint only. There is no OTP and no PIN, so a cloned fingerprint is enough to drain an account. (Axis Bank)
- India’s Home Ministry cyber nodal agency (I4C) warned states that cybercriminals are cloning Aadhaar biometric data to commit AePS fraud. (ThePrint)
- Fingerprints are being lifted from Aadhaar numbers embedded in publicly downloadable land and property registration records. (MediaNama)
- UIDAI has publicly stated it does not solicit identity or address documents through email or WhatsApp for Aadhaar updates. (DNA India)
- Locking your biometrics blocks every fingerprint and iris authentication, including AePS, until you unlock it yourself. It is free and reversible. (UIDAI myAadhaar)
Who this is for
Any Indian who has an Aadhaar number, which is effectively everyone. AePS fraud hits people who have never used the payment system and often never gave anyone their fingerprint knowingly, because their biometrics leaked through land records or a Business Correspondent point. The fake-update-link and fake-suspension-call scams target a wider group: pensioners, students, gig workers, homemakers, and busy professionals who see an official-looking Aadhaar message and act before they think. If you have elderly parents in a smaller town, they are in the highest-risk group for AePS withdrawals.
The five Aadhaar scams to know in 2026
| Scam | How it reaches you | What they are after |
|---|---|---|
| AePS biometric fraud | Silent. Your Aadhaar number and fingerprint are cloned from leaked records. No message arrives. | Cash withdrawn from your bank via Aadhaar plus a fake fingerprint |
| Fake Aadhaar update link | SMS, WhatsApp, or email: “Update your Aadhaar before the deadline or it will be deactivated.” | You enter Aadhaar, OTP, and bank details on a lookalike site |
| Fake update APK | A message posing as your bank tells you to install an app to update Aadhaar | Malware that reads OTPs and drains accounts |
| Aadhaar misuse or suspension call | A caller claims your Aadhaar is linked to a crime or will be suspended | An OTP, a fee, or a remote-access app install |
| mAadhaar or officer impersonation | A caller or a fake app poses as UIDAI staff or the official mAadhaar app | Login credentials, OTPs, or a download of a fake app |
What AePS fraud is and why it drains accounts silently
The Aadhaar-enabled Payment System was built to bring banking to rural India. At a Business Correspondent point, a customer can withdraw cash, check a balance, or transfer money by entering an Aadhaar number and scanning a fingerprint. There is no debit card, no OTP, and no PIN. That convenience is the vulnerability. Anyone who holds your Aadhaar number and a copy of your fingerprint can authenticate a withdrawal in your name. (Axis Bank)
The fingerprints are not usually stolen from you in the moment. They are harvested at scale. Investigators in Kolkata found fraudsters downloading land and property deeds from a state registration website, where Aadhaar numbers and fingerprint images sat in publicly accessible documents. Those prints are then reproduced as silicone molds or 3D-printed finger caps. (MediaNama)
In January 2026, Mumbai Cyber Police seized a consignment of silicone fingerprint molds and 3D-printed finger caps sold for roughly INR 8,000 to INR 25,000 on encrypted channels, built specifically to fool AePS fingerprint readers, as reported by The420.in. India’s Home Ministry cyber agency has formally warned states that this biometric cloning is now an organised fraud pattern, not a one-off (ThePrint).
The result is money leaving accounts with no phishing message, no suspicious link, and no OTP for the victim to ignore. Many people learn about it only from a debit SMS, which is why locking biometrics before anything happens matters so much.
What the regulator changed in 2025 and 2026
The Reserve Bank of India tightened AePS rules with a direction (RBI/2025-26/63) issued on 27 June 2025, which took effect on 1 January 2026. It requires banks to run proper due diligence on the touchpoint operators who run AePS terminals and to monitor them the way they monitor an individual account holder (AuthBridge, Business Standard).
NPCI, which runs the AePS rails, has also set transaction ceilings. A November 2023 NPCI circular recommended a monthly cumulative cap for AePS cash withdrawals, and the daily withdrawal limit sits at INR 25,000 (TeamLease RegTech). These caps limit the damage per incident, but they do not stop a cloned fingerprint from being used. The lock does.
How to lock your Aadhaar biometrics (the real AePS defence)
Locking your biometrics tells UIDAI to refuse every fingerprint and iris authentication tied to your Aadhaar, across all services including AePS. It is free, reversible, and takes a few minutes. You need a mobile number linked to your Aadhaar.
On the mAadhaar app (official UIDAI app):
- Install mAadhaar from the Google Play Store or the Apple App Store. Confirm the developer is the Unique Identification Authority of India.
- Add your Aadhaar profile inside the app.
- Open your profile, tap the three-dot menu at the top right, and select Biometric Settings.
- Enable the biometric lock and approve the OTP, which the app reads automatically.
- The lock activates shortly after. Allow up to a few hours for it to take full effect.
On the UIDAI website:
- Go to myaadhaar.uidai.gov.in.
- Log in with your 12-digit Aadhaar number, enter the captcha, and enter the OTP sent to your registered mobile.
- Open the Lock/Unlock Biometrics service and confirm to enable the lock.
Once locked, a fingerprint scan at any AePS point will simply fail. When you have a genuine need for biometrics, such as a real KYC at a bank, you unlock temporarily for 10 minutes and it re-locks by itself. If your mobile number is not linked to Aadhaar, update it at an Aadhaar Seva Kendra first, or call the UIDAI helpline on 1947.
You can also ask your bank whether it lets you disable AePS on your specific account if you never use it. Locking biometrics is the universal step, since it protects every account tied to your Aadhaar at once.
Fake Aadhaar update links and APKs
The second family of Aadhaar scams reaches you through a message. The pretext is urgency: your Aadhaar will be deactivated, your KYC has expired, or your Aadhaar must be re-verified before a deadline. The link leads to a site that copies the UIDAI logo and layout, on a near-real domain such as a variation of “aadhaar-update” or “uidai-update” rather than the official uidai.gov.in.
A sharper version tells you to install an app. In January 2026, the PIB Fact Check unit flagged a fake message posing as SBI that told users to download an APK file to update their Aadhaar or lose access to their banking app. The government confirmed the message was fake and told people not to download any APK or share personal, banking, or Aadhaar details (Government of India, newsonair.gov.in). An APK from a message is malware. It can read the OTPs that arrive on your phone and empty an account in minutes, which is the same mechanism we broke down in our WhatsApp APK scam explainer.
The rule is simple. UIDAI does not ask you to update Aadhaar by SMS, WhatsApp, email link, or app download, and it has said so publicly (DNA India). Update Aadhaar only at uidai.gov.in, at myaadhaar.uidai.gov.in, or in person at an Aadhaar Seva Kendra.
Fake misuse and suspension calls
The third scam is a call. A voice claiming to be from UIDAI, your bank, or the police tells you your Aadhaar has been linked to a crime, a money-laundering case, or a fraudulent SIM, and that it will be suspended unless you verify yourself right now. It is the same authority-and-fear script behind the digital arrest scam and the KYC account-block scam.
Aadhaar is not suspended over a phone call. UIDAI does not make these calls. The goal is to get you to read out an OTP, install a screen-sharing or remote-access app, or pay a fee to “clear” your name. Every one of those actions hands over control of your money. The moment a caller invokes Aadhaar misuse and demands urgency, treat it as a scam and disconnect.
Red flags any reader can apply
Any single one of these is enough to stop and verify.
1. A deadline to update Aadhaar or lose it
There is no sudden deactivation deadline delivered by SMS or WhatsApp. Urgency is the manipulation.
2. A link or an APK to “update” Aadhaar
UIDAI updates never happen through a message link or an app you install from a message. Only uidai.gov.in and myaadhaar.uidai.gov.in are official.
3. Any request for your Aadhaar OTP
No genuine UIDAI, bank, or government process needs you to read out the OTP that arrives on your phone. Sharing it is what completes the fraud.
4. A call claiming Aadhaar misuse or suspension
Aadhaar is not policed by phone. A threat of suspension plus a demand to act now is a scam script.
5. A debit you cannot explain
An AePS withdrawal you did not make is a sign your biometrics leaked. Lock your biometrics and report the same day.
What to do if you are targeted or hit
- If it is a message or call, do not act on it. Do not tap the link, do not install the app, do not share the OTP, do not pay.
- Lock your Aadhaar biometrics using the steps above. Do this even before you have lost anything. It is the cheapest insurance you have.
- If money moved, tell your bank in writing today. Ask for the transaction to be reversed and note the date and time of your report, because the reporting window decides your liability.
- Call 1930, the national cybercrime helpline operated 24x7 by I4C under the Ministry of Home Affairs.
- File a complaint at cybercrime.gov.in the same day, and raise a complaint with NPCI for AePS withdrawals.
- Report the phishing message. For bank-impersonation messages, forward to your bank’s phishing address. The PIB advisory for the fake SBI Aadhaar message pointed users to report.phishing@sbi.co.in.
Under the RBI customer-liability framework, reporting an unauthorised electronic transaction within three working days, where you did not share your own credentials, can bring your liability to zero, with the bank expected to shadow-credit the amount while it investigates. The window closing is what raises your liability, so the same-day report is not a formality. It is the recovery.
Got a message or call? Send it to us, we verify free
If an Aadhaar message, a call, or a link feels off and you want a sanity check before doing anything, send it to us privately.
WhatsApp / Call: +91 99644 43350
Send a screenshot, the sender number, the link, or whatever details you have. We tell you whether it is a real UIDAI or bank contact or a scam, and what to do next.
What we do:
- Check the link, domain, and any named app against publicly available official records
- Look for the Aadhaar scam tells (update deadline, APK install, OTP request, suspension threat)
- Tell you whether it is real or fake, in plain language
What we do not do:
- Charge you for the verification
- Ask for your Aadhaar number, OTP, biometrics, or bank details
- Pretend to be UIDAI, a bank, or any government agency
Verification is free. We also publish related guides on the UPI QR code fraud pattern and on what to do in the first hour of a cyber fraud for the same broad audience these scammers target.
Save this number now
If you ever get a call claiming your Aadhaar is misused, a message telling you to update Aadhaar through a link, or a debit you did not make: WhatsApp +91 99644 43350. Save it now. During an active scam, you will not have time to search. Lock your biometrics today, before anyone tries.
Frequently asked questions
Can someone steal money from my bank account using only my Aadhaar number?
Not with the number alone, but the Aadhaar-enabled Payment System (AePS) lets anyone withdraw cash using your Aadhaar number plus a fingerprint, with no OTP and no PIN. Fraudsters harvest Aadhaar numbers and fingerprints from leaked land and property registration records, then make silicone or 3D-printed finger replicas to authenticate withdrawals. The single strongest defence is to lock your Aadhaar biometrics on the UIDAI myAadhaar portal or mAadhaar app. Once locked, no fingerprint can authenticate any AePS transaction until you temporarily unlock it yourself.
How do I lock my Aadhaar biometrics?
Two official ways, both free. On the mAadhaar app: add your Aadhaar profile, tap the three-dot menu, open Biometric Settings, enable the lock, and approve the OTP. On the UIDAI website: go to myaadhaar.uidai.gov.in, log in with your Aadhaar number and the OTP sent to your registered mobile, then open the Lock/Unlock Biometrics service and confirm. Once locked, fingerprint and iris authentication is blocked for every Aadhaar service, including AePS. When you genuinely need biometrics, you unlock for 10 minutes and it re-locks automatically.
Is the SMS asking me to update my Aadhaar before a deadline real?
Almost always fake. UIDAI does not ask you to update Aadhaar through SMS, WhatsApp, email links, or APK files, and there is no sudden deactivation deadline. In January 2026 the PIB Fact Check unit flagged a fake message posing as SBI that told people to download an APK to update Aadhaar. Never install an APK from a message. Only update Aadhaar at uidai.gov.in, myaadhaar.uidai.gov.in, or a physical Aadhaar Seva Kendra.
Someone called saying my Aadhaar is misused and will be suspended. What do I do?
Hang up. UIDAI does not make calls threatening suspension, and Aadhaar is not suspended over the phone. This is a pressure script to make you share an OTP, install an app, or pay a fee. Do not share the OTP that lands on your phone, do not install any app the caller names, and do not pay anything. If you already shared details or money moved, call 1930 and file a complaint at cybercrime.gov.in immediately.
Money was withdrawn from my account through AePS. Can I get it back?
Often yes, if you act fast. Report to your bank in writing and to 1930 or cybercrime.gov.in the same day, and raise a complaint with NPCI. Under the RBI customer-liability framework, if you report an unauthorised electronic transaction within three working days and did not share your credentials, your liability can be zero and the bank is expected to shadow-credit the amount while it investigates. Speed is everything, since the reporting window directly decides how much you are liable for.