Top News

What is the Aadhaar scam that's draining bank accounts without OTPs or PINs?
Siddhi Jain | January 18, 2026 11:15 PM CST

Imagine someone stealing your money using only your Aadhaar number and fingerprint, without any OTP or password. This is the story of the AEPS fraud (Aadhaar Scam), which is particularly targeting people in rural areas.

How does this Aadhaar fraud work?

The fraudsters first steal your Aadhaar data and biometric details (like fingerprints). This data is often obtained from leaked records. Then, the scammers create fake fingerprints and use them on AEPS micro-ATMs. The result – money is withdrawn from your account as if someone had secretly obtained the key to your vault.

Aadhaar Scam: The role of mule accounts

Now, the question is, where does the money go? For this, scammers use "mule accounts." These are accounts that are either rented out by people or hacked and fall into the hands of fraudsters. Money is laundered through these accounts to make it difficult to trace the real culprits.

GPS devices to put a stop to it

Experts suggest that the most effective way to stop this type of fraud is through GPS-enabled devices. This means that transactions will only be possible from the location where the machine is registered. If someone tries to make a transaction from elsewhere, the payment will fail. This also benefits banks as GPS data helps identify fraud hotspots.

The future is even smarter

In the future, these devices may incorporate technologies like AI and biometric liveness checks. This will make the use of fake fingerprints impossible. Remember – these devices don't track your location, but rather the location of the machine. This means increased security while maintaining privacy.

Aadhaar Scam: How can you protect yourself?

The most important thing is to be aware. Lock your Aadhaar and biometrics on the UIDAI website. Do not get your Aadhaar updated at any unknown or fake center. Be careful when providing a photocopy of your Aadhaar card – try to make the copy from the physical card itself, and if you send a digital photo, delete it immediately afterward.


READ NEXT
Cancel OK