Guide
Money withdrawn with your fingerprint, no OTP? AePS fraud explained, and how to stop it

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
AePS lets you withdraw cash with your Aadhaar number and a fingerprint. Criminals do the same with cloned fingerprints, which can be lifted from property papers, so no card, PIN or OTP is needed. How to spot it, what to do the same day, and how to lock it down.
01 / The short answer
AePS, the Aadhaar Enabled Payment System, is a genuine payment system that RBI says plays 'a prominent role' in financial inclusion. At a banking agent's counter, your Aadhaar number and a fingerprint scan are enough to withdraw cash from your Aadhaar-linked bank account, with no card, PIN or OTP. If you use it, keep using it, with the habits in section 05.
Criminals exploit the same simplicity. With your Aadhaar number and a copy of your fingerprint, which can be lifted from a registered property document, they can withdraw money without ever contacting you. The finance ministry, citing RBI, told Parliament in July 2024 that the Aadhaar numbers and fingerprints behind these frauds come mainly from land and property registration records. If it has happened to you, you were not careless: putting your thumb on a registered document is normal.
No OTP and no call does not mean no fraud.
Spotted a withdrawal you did not make? Today: call 1930, tell your bank in writing and lock your Aadhaar biometrics. Section 04 has the steps.
02 / How the fraud works
AePS is run by the National Payments Corporation of India (NPCI). RBI describes it as a way to withdraw or deposit cash, transfer money or check a balance using an Aadhaar number with biometrics or an OTP. The agents who run AePS points for banks are called touchpoint operators.
The fraud needs your Aadhaar number and your fingerprint. Axis Bank's fraud-awareness page sets out the steps: the fingerprint is 'illegally obtained from land records and / or physical documents', copied onto a silicone replica, and used to authenticate AePS withdrawals from the victim's account. In a written reply in the Rajya Sabha on 30 July 2024, the Minister of State for Finance said that, according to RBI, AePS frauds most often happen because Aadhaar numbers and fingerprints have been compromised elsewhere, mainly from land and property registration records. Two police cases:
- Bengaluru: agents registered on Karnataka's Kaveri 2.0 land-registration portal downloaded land documents carrying owners' thumb impressions, and criminals copied the prints onto silicone sheets, The South First reported in January 2024, citing police. After a police letter, the state's revenue department removed the biometric pages from the portal and stopped showing Aadhaar numbers, the report said.
- Aligarh: police seized 689 cloned fingerprints from a man accused of taking about ₹35 lakh through AePS with sale-deed PDFs downloaded from government revenue portals, The420 reported in February 2026. We found no second report of this case, so we name no one.
A different risk sits at the counter. Dvara Research, a policy research institution, found that some dishonest agents blame a server failure or a thumbprint mismatch, say the transaction failed and keep the cash after a successful debit, MediaNama reported in September 2024. Elderly customers, and people without access to the mobile number linked to their account, were among those targeted.
03 / Signs it has happened to you
- a withdrawal in your passbook, statement or bank SMS that you did not make;
- no OTP, PIN or card details shared, and no suspicious call or link;
- an Aadhaar authentication in your history that you do not recognise (section 04, step 3).
With no OTP involved, the first sign may be a debit SMS, if your mobile number is registered with the bank, or only a passbook entry. Investigators cited by The420 said victims of such frauds often do not know until the money has gone. Check your passbook each time you update it, and act the day you notice.
04 / Money gone: what to do today
Do steps 1 and 2 the same day, in whichever order you can. How fast you report decides what you can get back.
- Call 1930, the national cyber-fraud helpline, then complete the complaint on cybercrime.gov.in and keep the acknowledgement number. How to report.
- Write to your bank. At your branch, or through the fraud-reporting link on the bank's official website, list each withdrawal's date, amount and reference. Say you did not make it and gave no fingerprint or OTP for it, and ask the bank to stop further AePS debits and to tell you where each withdrawal was made. Keep the complaint number. Under RBI's rules on unauthorised electronic banking transactions, you owe nothing where neither you nor the bank was at fault (RBI calls this a third-party breach), on a transaction made up to 31 December 2026, if you tell your bank within three working days of its alert; from 1 January 2027 the window is five calendar days from the transaction. Neither RBI text names AePS, so ask the bank in writing to apply these rules. RBI's refund rules, explained.
- Lock your Aadhaar biometrics and check your authentication history. UIDAI says that while your fingerprint, iris and face are locked, no entity can use them for Aadhaar authentication 'by any means'. Lock them on UIDAI's website or in the Aadhaar app; you need the mobile number registered with Aadhaar. Look through your authentication history, in the app or on UIDAI's website, and report any use you do not recognise to UIDAI on 1947 or help@uidai.gov.in. The lock does not block OTP-based authentication, so never share an Aadhaar OTP. Step by step.
- Ask your bank about turning AePS off. The government said in July 2024 that NPCI had advised banks to give customers 'multiple options' to enable or disable AePS debits. Ask your branch what yours offers.
- Bank not resolving it? Keep its reply and your complaint number, and go to the RBI Ombudsman.
05 / If you use AePS yourself
Banking agents bring banking to places with few branches, and you do not need to stop using them. These habits help:
- Lock your biometrics and unlock them only when needed. A lock also stops genuine uses, such as an AePS withdrawal or your LPG e-KYC. UIDAI says you can unlock temporarily on its website, in the Aadhaar app or at an Aadhaar centre.
- Register your mobile number with your bank, so withdrawals reach you by SMS. RBI requires banks to send SMS alerts for electronic banking transactions.
- Give your thumb only for a transaction you asked for, then count the cash and check the amount in the SMS.
- Told it failed? Before you give your thumb again, check for a debit SMS or ask for a balance enquiry, which AePS also offers.
- Share a masked Aadhaar, which shows only the last four digits, where the full number is not needed. More ways to protect your Aadhaar.
- Check older relatives' passbooks, especially if no phone is linked to their account.
06 / What changed for AePS agents on 1 January 2026
On 27 June 2025 RBI issued directions citing 'reports of frauds perpetuated through AePS due to identity theft or compromise of customer credentials'. From 1 January 2026, the bank that onboards an AePS touchpoint operator must:
- check the agent with the same due diligence it uses for individual customers, unless it already did so when appointing the agent as a business correspondent, and update the agent's KYC periodically;
- repeat the KYC before an agent who has done no transaction for three months in a row can transact again;
- monitor agents through its transaction-monitoring systems, with operating parameters based on each agent's risk, such as location, type of agent and the volume and speed of transactions, reviewed as fraud trends change;
- make sure technical links such as APIs are used only for AePS.
Earlier measures, listed by the government in July 2024, include biometric authentication for each transaction by banking agents and a cumulative limit of ₹50,000 a month on AePS cash withdrawals and BHIM Aadhaar Pay. The new rules make banks check and watch their agents. They do not change your rights or remove the need to report. The biometric lock is the step in your own hands.
07 / How big is it? The numbers, and their limits
- About 29,000 complaints. Citizens have reported around 29,000 AePS fraud incidents on the National Cyber Crime Reporting Portal 'so far', the Ministry of Home Affairs told the Rajya Sabha in a written reply published on 31 July 2024. The reply gives no cut-off date for the count. The National Crime Records Bureau does not keep separate data on biometric cloning, it added.
- 3,319 bank-reported frauds. Banks reported 3,319 'AEPS/Other Aadhaar related' frauds worth ₹2.19 crore in 2025-26, against 366 worth ₹0.32 crore in 2024-25, according to RBI data in a Lok Sabha answer of 3 August 2026.
The second figure is not a total. Since RBI's revised fraud directions of 15 July 2024, the answer notes, banks report only payment frauds concluded to have been 'committed on bank(s)'. The two figures measure different things; do not add them up or compare them. The AePS category appears in the table only from 2024-25, and over the same two years the table's total for all digital payment frauds fell from 1,44,855 to 5,997. With only two years of data and a change in what banks report, do not read the rise from 366 to 3,319 as a trend either.
08 / What we confirmed, and what we could not
Confirmed (official documents): RBI's AePS directions and the date they took effect (RBI); the 29,000 complaints and the government's measures, including NPCI's advice on switching AePS debits on and off (Ministry of Home Affairs, on PIB); RBI's assessment that the Aadhaar numbers and fingerprints behind AePS frauds come mainly from land and property registration records (the Minister of State for Finance's written reply in the Rajya Sabha, 30 July 2024); the bank-reported figures (Lok Sabha answer, 3 August 2026); the biometric lock, authentication history and UIDAI's complaint channels (UIDAI); and the liability rules (RBI). Bank advisory: how the fraud works, step by step (Axis Bank's fraud-awareness page, which speaks of 'sporadic instances'), consistent with two police cases reported in the media. Reported (media): the Bengaluru case (The South First); the Aligarh case (The420 only); Dvara Research's findings that some agents falsely say a transaction failed and keep the cash (MediaNama). Not available: a current official count of all AePS frauds or money lost, and a list of banks that let you turn AePS off.
09 / What to do now
- Money has gone: call 1930 now, then your bank on its official number and in writing, then complete the complaint on cybercrime.gov.in. Our lost-money checklist and UPI fraud guide cover the first hour.
- Unknown use in your authentication history, but no money gone: lock your biometrics, complain to UIDAI on 1947 and check your bank statement. How to lock and check.
- Worried your fingerprint is on a property document: you cannot take it back, but while your biometrics are locked it cannot be used for Aadhaar authentication. How to lock down your Aadhaar.
- Told a withdrawal failed, but the money left: genuine failures are usually reversed automatically, though delays are common, Dvara found. If yours is not, report it to your bank in writing and on 1930, with the place, date and time.
- Bank not helping: complain in writing, keep the complaint number, then go to the RBI Ombudsman. Ignore anyone who offers to 'recover' your money for a fee: what recovery really looks like.
Source log / 2026-1002-AE
- RBI — Aadhaar Enabled Payment System: Due Diligence of AePS Touchpoint Operators, RBI/2025-26/63 (27 Jun 2025; in force 1 Jan 2026) Primary
- PIB (Ministry of Home Affairs) — Cases of biometric cloning for financial fraud, Rajya Sabha reply (31 Jul 2024) Primary
- Rajya Sabha — Unstarred Question No. 872, Cyber Fraud: written answer by the Minister of State for Finance (30 Jul 2024) Primary
- Lok Sabha — Unstarred Question No. 2432, Rise in Digital Payment Frauds: answer and annex with RBI data (3 Aug 2026) Primary
- UIDAI — FAQs: Aadhaar Online Services (biometric lock and unlock, authentication history, masked Aadhaar), accessed 2 Oct 2026 Primary
- UIDAI — Aadhaar App FAQs (biometric lock, authentication history), accessed 2 Oct 2026 Primary
- UIDAI — Grievance redressal channels (1947, help@uidai.gov.in), accessed 2 Oct 2026 Primary
- Axis Bank — Fraud awareness: Aadhaar Enabled Payment System (AePS) frauds, accessed 2 Oct 2026 Primary
- RBI — Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, RBI/2017-18/15 (6 Jul 2017; for commercial banks, since consolidated in the Responsible Business Conduct Directions, 2025) Primary
- RBI — RBI issues amendment directions on 'Review of Framework of Limiting Customer Liability in Digital Transactions' (24 Jun 2026) Primary
- RBI — Commercial Banks (Responsible Business Conduct) Third Amendment Directions, 2026 (in force 1 Jan 2027) Primary
- MediaNama — Dvara Research opposes RBI's single bank limit for AePS operators, citing downtime and fraud risks (17 Sep 2024) Secondary
- The South First — Bengaluru cops clamp down on cybercrime using biometrics from land records, Aadhaar-enabled payments (18 Jan 2024) Secondary
- The420.in — Rubber thumb used to execute Aadhaar-based withdrawals: police seize 689 cloned fingerprints in Aligarh case (13 Feb 2026) Secondary
- National Cyber Crime Reporting Portal Primary