Guide
Aadhaar or PAN leaked in a data breach? How to lock it down and check for misuse

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
You cannot change a leaked Aadhaar or PAN, but you can limit how it is used. Check your authentication history, lock your biometrics, share only masked Aadhaar or a VID, and watch your credit reports and AIS for anything you don't recognise.
01 / Start by checking your Aadhaar authentication history
A leaked Aadhaar or PAN number cannot be changed like a password. What leaks enable is impersonation: attempts at KYC or credit in your name, and scam calls that sound convincing because the caller knows your details. Your first job is to find out whether anyone has already used your Aadhaar.
- UIDAI's Aadhaar app (Android and iOS) includes Authentication History, which shows when your Aadhaar was used for authentication. UIDAI lists the same check among its online services, alongside the myAadhaar portal at myaadhaar.uidai.gov.in.
- Look for authentications at times, places or organisations you don't recognise.
- If something looks wrong, contact UIDAI on its toll-free number 1947 or at help@uidai.gov.in, then lock your biometrics (section 02).
Most of these services send an OTP to your Aadhaar-registered mobile number, so make sure that number is current and in your control.
02 / Lock your biometrics, and consider locking your Aadhaar
Biometric lock. UIDAI says locking your biometrics stops your fingerprints, iris and face from being used for Aadhaar authentication by any entity. It stays locked until you unlock it temporarily or turn the lock off, which you can do on the UIDAI website, in the Aadhaar app, or at an enrolment centre or Aadhaar Seva Kendra. You need a registered mobile number to use it.
Aadhaar (UID) lock goes further: it blocks biometric, demographic and OTP authentication using your Aadhaar number. You can set it on myAadhaar or by SMS to 1947 from your registered mobile. Before you lock, make sure you have your latest 16-digit Virtual ID (VID), because UIDAI requires it to unlock. UIDAI's SMS FAQ says you can still authenticate with your latest VID while the number is locked. If you forget the VID, send RVID followed by the last four digits of your Aadhaar to 1947.
If a bank or other service needs biometric authentication, unlock temporarily for that visit.
03 / Share less: masked Aadhaar and VID
- Masked Aadhaar replaces the first eight digits with "xxxx-xxxx", so only the last four show. Download it free from myAadhaar and use it wherever the full number is not required.
- A VID is a temporary, revocable 16-digit number that can be used in place of your Aadhaar number for authentication and e-KYC. UIDAI says your Aadhaar number cannot be worked out from a VID and agencies should not store it. Only you can generate one, on myAadhaar, in the app, or by sending GVID and the last four digits of your Aadhaar to 1947. Generating a new VID deactivates the old one.
04 / Check for PAN misuse: credit reports and AIS
One common misuse of a leaked PAN is applying for loans or credit cards in your name. India has four RBI-registered credit information companies: TransUnion CIBIL, Equifax, Experian and CRIF High Mark.
- Under RBI's directions, each must give you one free full credit report with score every calendar year (January to December). Get one from each company and check for loans, cards or enquiries you did not make.
- The same directions require credit bureaus to alert you by SMS or email when a lender pulls your report, where they hold your contact details. An unexpected alert may mean someone is applying for credit in your name.
- If you find wrong entries, raise them through the credit bureau's online dispute and correction process, and contact the lender.
- On the income tax e-filing portal, open your Annual Information Statement (AIS). It shows TDS and high-value transactions reported against your PAN, and you can submit feedback on any entry that is not yours.
We could not find a US-style credit freeze in RBI's rules. The free reports and access alerts are the closest tools available in India.
05 / Beware the follow-up scams, and report misuse
Leaked details make scams more convincing. Callers may read out your Aadhaar, PAN or address and then ask for an OTP, a payment or an app install to "secure" your account. Never share OTPs or PINs. RBI warns that fraudsters also plant fake customer-care numbers online and use remote-access apps to take over phones.
- If you lose money, call 1930 and file on cybercrime.gov.in.
- Report suspected fraud calls, SMS and WhatsApp messages on Sanchar Saathi's Chakshu within 30 days.
06 / Your rights under the DPDP law
The Digital Personal Data Protection Act, 2023 and the DPDP Rules notified on 14 November 2025 make you a data principal. You can ask an organisation what personal data it holds and how it uses it, have that data corrected, updated or erased in some cases, and nominate someone to exercise these rights for you. Organisations must respond within 90 days. Complaints go to a fully digital Data Protection Board.
After a breach, the Rules require the organisation to tell affected people without delay, in plain language: what happened, the likely impact, what it is doing about it, and who to contact for help. It must also send the Board a detailed report within 72 hours. Failing to notify can bring a penalty of up to ₹200 crore. Note the timing: the Rules phase in over 18 months, and the breach-notification duties take effect in May 2027. Until then, you may not get a formal notice, so act on credible reports yourself.
07 / Your checklist
- Check Authentication History in the Aadhaar app.
- Lock your biometrics; save your VID, then consider an Aadhaar lock.
- Share masked Aadhaar or a VID instead of the full number.
- Get your free report from all four credit bureaus and watch for access alerts.
- Review your AIS for transactions that aren't yours.
- Never share OTPs; report fraud to 1930 or cybercrime.gov.in and suspicious calls to Chakshu.
- Use your DPDP rights to ask breached organisations what they hold.
Source log / 2026-0929-GA
- UIDAI — FAQs: Aadhaar Online Services (biometric lock, Aadhaar lock, VID, masked Aadhaar) Primary
- UIDAI — Aadhaar App FAQs (authentication history) Primary
- UIDAI — My Aadhaar services Primary
- RBI — Reserve Bank of India (Credit Information Companies) Directions, 2025 (updated 1 Jul 2026) Primary
- Income Tax Department — AIS (Annual Information Statement) FAQs Primary
- PIB (MeitY) — Government notifies DPDP Rules to empower citizens and protect privacy (14 Nov 2025) Primary
- PIB — DPDP Rules, 2025 Notified: explainer (17 Nov 2025) Primary
- MediaNama — Data breach reporting timeline of DPDP Rules 2025 explained (14 Nov 2025) Secondary
- RBI — Consumer Awareness: Cyber Threats and Frauds (28 Jan 2022) Primary
- Sanchar Saathi (DoT) — Chakshu: report suspected fraud communication Primary