Table of Contents

AePS / Aadhaar Biometric Fraud Recovery 2026 — Bank Account Drained? Get It Back

AePS Aadhaar biometric fraud recovery — RTI Wiki guide 2026

⚠️ DPDP Rules, 2025 (14 Nov 2025) amended Section 8(1)(j) of the RTI Act — public-interest override now under Section 8(2). Read the note →

· 2026/04/19 05:02

Your bank account was emptied via the Aadhaar Enabled Payment System (AePS) without an OTP, without a card, without a phone alert — sometimes from a banking correspondent shop hundreds of kilometres away. This is AePS fraud — the fastest-growing biometric crime in India, with over 6 lakh complaints logged at NCRP in 2024 alone. The RBI's “Customer Liability Framework, 2017” + the 3-day rule says you get 100% refund if you report within 3 working days. Here is the exact, working recovery sequence — by the clock.

Quick Answer

🔔 Track AePS fraud trends + UIDAI biometric updates by email. Free notifications. Subscribe →

Quick Action Steps

  1. Lock Aadhaar biometrics NOW at uidai.gov.in (or m-Aadhaar app → Biometric Lock toggle). Stops further fraud instantly.
  2. Take screenshots of: bank SMS/email of the debit, account statement, any AePS terminal location info.
  3. Call your bank on its registered helpline → log bank-side fraud complaint with a written acknowledgement number. Tell them: “Section 6.3 of RBI Customer Liability Framework — zero liability.”
  4. Dial 1930 — Cyber Crime helpline. Lock the destination account.
  5. File at https://cybercrime.gov.in within 24 hours.
  6. Get FIR copy at the cyber police station within 48 hours.
  7. NPCI dispute at npci.org.in — for AePS-specific transaction reversal.
  8. Bank must reply in 10 working days, refund in 90 days (RBI rule).
  9. If bank stalls — RBI Banking Ombudsman at cms.rbi.org.in.
  10. RTI to UIDAI for transaction logs (which agency / device used your fingerprint).
  11. Update Aadhaar mobile at the nearest enrolment centre — keep it linked.

What is AePS Fraud?

AePS (Aadhaar Enabled Payment System) is a financial product run by NPCI that lets a citizen withdraw cash, deposit, or transfer using only Aadhaar number + fingerprint at any Banking Correspondent (BC) shop or micro-ATM. No card, no PIN, no OTP.

Fraud happens when your biometric is silently captured and replayed on an AePS terminal:

You may discover the fraud only when you check your bank balance. No SMS is sent in many AePS transactions because the BC is offline.

Recent Patterns (2023-2026)

A. RBI Customer Liability Framework, 2017

Source: RBI/2017-18/15 dated 06 Jul 2017.

B. NPCI AePS Dispute Resolution Mechanism

C. Aadhaar Act, 2016

D. IT Act, 2000 + DPDP, 2023

E. BNS, 2023

F. UIDAI Right to Privacy

Right to lock/unlock biometrics is a statutory right under §8(2)(b), Aadhaar Act, 2016 — UIDAI must comply.

Step-by-Step Recovery Process

Step 1 — Lock biometrics (within minutes)

  1. Open m-Aadhaar app (Android / iOS, free, official) OR https://uidai.gov.inMy Aadhaar.
  2. Login with Aadhaar number + OTP to your mobile.
  3. Lock/Unlock Biometrics → tap Lock.
  4. Your biometric is now disabled for AePS, eKYC, all third-party authentications. You can unlock temporarily for genuine eKYC.

Step 2 — Bank complaint (within 3 working days)

  1. Visit branch or call helpline. Get complaint number in writing (not just verbal).
  2. Mention specifically: “AePS unauthorised debit. Section 6.3 RBI Customer Liability Framework, 2017. Zero liability. I have reported within 3 working days.”
  3. Submit a written letter + bank statement + ID proof. Get a receiving stamp with date/time.
  4. Demand shadow credit within 10 working days (RBI rule).

Sample bank complaint letter (use the RTI Drafter to auto-generate):

To, Branch Manager, [Bank], [Branch].
Sub: AePS Unauthorised Debit — RBI Customer Liability Framework Claim.
Account no: … I noticed unauthorised AePS debits totalling ₹… on dates… I confirm I did not authorise these transactions; I did not share my Aadhaar / biometric. As per RBI/2017-18/15 dated 06 Jul 2017 §6.3, I am reporting within 3 working days; my zero-liability claim attaches. Kindly: (a) issue a shadow credit within 10 working days, (b) raise an AePS dispute at NPCI, © provide a copy of the AePS terminal log + BC ID. — [Signature, Date].

Step 3 — NCRP + 1930 (within 24 hours)

  1. Dial 1930 (24×7) — give bank account, transaction details. Scammer's destination account is frozen.
  2. File at https://cybercrime.gov.inFinancial fraud → AePS / Biometric fraud. Save Acknowledgement Number.

Step 4 — FIR (within 48 hours)

  1. Cyber police station (or your area police if no separate cyber cell).
  2. Sections to cite: IT Act §66C, §66D, BNS §318, §321, §336.
  3. Carry: ID proof, bank statement, NCRP acknowledgement, screenshots.

Step 5 — NPCI dispute

  1. The acquirer bank (BC location's bank) is required to provide: BC ID, terminal MAC, GPS coordinates, biometric capture timestamp.
  2. TAT: 10 working days for chargeback. Penalty ₹100/day if delayed.

Step 6 — RBI Ombudsman (Day 30 if bank stalls)

  1. File at https://cms.rbi.org.inBanking Ombudsman Scheme, 2021.
  2. Free. No advocate required.
  3. Order in 60-90 days. Compensation: actual loss + interest + ₹1 lakh max for mental harassment.

Step 7 — RTI escalation (Day 30+)

File RTIs to track investigation: