Table of Contents

DigiLocker safety and fraud response — citizen guide 2026

DigiLocker safety, document verification and fraud-response guide — RTI Wiki

DigiLocker is accessed through its official website or app—not through an unsolicited caller who asks for your OTP, security PIN, screen share or payment. Understand whether a document is issuer-provided or uploaded by you, review the Activity log, and use official support and cybercrime channels if account activity looks wrong.

Quick answer: Open DigiLocker only at digilocker.gov.in or its official app. Never disclose an OTP or security PIN to a caller. Issued documents come from registered issuers; uploaded files are user-provided. Review the Activity log and secure the linked mobile account if anything is unfamiliar. Report financial loss through 1930 and cybercrime.gov.in, and account issues through official DigiLocker support.

DigiLocker safety — in 50 words

DigiLocker provides access to digital documents through a mobile-number login, OTP and security PIN process described in its official FAQ. Its security depends partly on protecting your phone, SIM, OTP and PIN. A document's presence in a chat, email or screenshot does not prove it came from DigiLocker or its issuer.

Is DigiLocker safe?

Searches for is DigiLocker safe and DigiLocker safety PIN are asking whether the platform, or the way people use it, is the weak point. DigiLocker's official FAQ states that the service is designed to be safe and lists practices including SSL encryption, multifactor sign-in via mobile OTP or biometric authentication combined with PIN validation, timed logout, CERT-In empanelled audits, and user-consent-based sharing with activity logged. That architecture does not make an OTP read aloud to a stranger safe.

Treat DigiLocker as safe when:

Treat it as compromised when a caller, SMS or APK asked for OTP, PIN, screen share or payment, or the Activity log shows a device or document event you did not start. Issued versus uploaded is explained in DigiLocker issuer reality. If a driving licence or RC will not fetch, use documents not showing and verification failed — those are fetch problems, not automatically fraud.

Issued documents and uploaded documents are different

Type How it reaches the account What to check
Issued document A registered issuer makes or pushes it available through DigiLocker Issuer name, document type, identifiers and QR/verification route
Uploaded document The user uploads a file to DigiLocker storage Source file, signer/eSign status if any, and whether the receiving authority accepts it
Shared document The user uses an available sharing or consent flow Exact document, recipient, purpose and activity record

DigiLocker's official FAQ distinguishes issued and uploaded documents. Its circular explaining Rule 9A says documents made available by issuers through a citizen's Digital Locker account are at par with physical originals when used electronically. Do not extend that statement to every photograph or PDF uploaded by a user.

For an issued document, use the QR or verification method provided by DigiLocker or the issuer instead of trusting a screenshot. A cropped image can hide the issuer, document URI, QR code or altered fields.

Never share these with an unsolicited person

An official-looking caller ID, logo or WhatsApp profile does not authenticate the person. End the contact and independently open the official service. DigiLocker does not become unsafe merely because a scammer uses its name; the practical risk is credential theft, impersonation or misuse of documents.

How to reset the DigiLocker safety PIN

The official FAQ describes Forget Security PIN on the sign-in page. If you still control the Aadhaar-registered mobile:

  1. Open digilocker.gov.in yourself. Click Sign In, then the current Forget Security PIN link.
  2. Follow the Aadhaar number and date-of-birth fields the form actually shows.
  3. If the DigiLocker-linked mobile is dead, the FAQ currently points to Try using Aadhaar OTP instead, so the OTP goes to the Aadhaar-registered number.
  4. Set a new PIN only on that official page. Do not tell the PIN to a caller who offered to “reset it for you”.

If both the DigiLocker mobile and the Aadhaar mobile are gone, that is a SIM-control problem first: SIM stopped / swap recovery and Sanchar Saathi / TAFCOP connection check. DigiLocker support cannot issue you a stranger's SIM.

Safe everyday use

  1. Type or bookmark the official address. Use digilocker.gov.in or the official mobile app linked from the service.
  2. Protect the linked phone number. Use a device lock and contact your telecom provider immediately if the SIM stops working unexpectedly.
  3. Keep OTP and security PIN private. Enter them only in the official login or recovery flow you initiated.
  4. Review the Activity log. The official FAQ describes an Activity section where account activity can be reviewed. Investigate unfamiliar access or document action.
  5. Fetch only what you need. Confirm the issuer and requested consent before retrieving or sharing a document.
  6. Verify received documents. Use DigiLocker's QR verification or the issuer's official validation channel.
  7. Limit distribution. Share the least data required and use a masked document where the receiving process permits it.
  8. Use official support. Create a ticket at support.digilocker.gov.in rather than calling a search-result number.
① Official app ② Private OTP/PIN ③ Check issuer ④ Review activity ⑤ Report safely
Start at DigiLocker Never disclose Issued is not uploaded Investigate unknown events Support plus cybercrime if needed

How to check DigiLocker activity

There is no public “DigiLocker activity” tracker for other people. How to check DigiLocker activity means opening your account:

  1. Sign in at the official site or app using a flow you started.
  2. Open the Activity section the current app/FAQ shows (wording moves; look under the account / privacy / security area).
  3. Note unfamiliar logins, document views, downloads, shares or consent grants, with date and time.
  4. Screenshot the row without exposing full document numbers or QR codes.
  5. If the account will not open, use official PIN-reset / Aadhaar-OTP steps above, then the support ticket below.

Do not email the full Activity export to a “recovery agent”. Attach a masked excerpt only to official DigiLocker support or to a police/cybercrime complaint you filed.

Warning signs of impersonation

Stop when a caller or message:

Do not test the supplied link. Preserve the message, sender, time and displayed URL, then use the correct official reporting channel. Report the number via report a scam call.

If you suspect account compromise

Work in this order. Do not invent a DigiLocker “helpline” from ads.

  1. Stop interacting with the caller or message. Do not approve another OTP or login.
  2. Use a trusted device and network. Type the official address; do not click the SMS.
  3. Review the Activity log and document activity. Note unfamiliar dates, actions or documents. Mask screenshots.
  4. Revoke sessions if the current Security / device list shows a session you do not recognise. Change the security PIN through the official reset flow.
  5. Secure the linked mobile account. If the SIM is missing, inactive or unexpectedly replaced, follow SIM swap recovery in parallel.
  6. Open a DigiLocker support ticket at support.digilocker.gov.in. State the account identifier safely, time of suspected activity, affected document and evidence; do not put OTPs or passwords in the ticket.
  7. Secure related services separately. PAN, licence, bank and loan apps each have their own channel. Instant-loan misuse often follows a PAN download — see loan-app harassment.
  8. Report fraud. For financial loss: bank/payment provider, 1930, cybercrime.gov.in. For suspicious communication without loss: Chakshu on Sanchar Saathi. Track the cyber complaint via cybercrime complaint status. Use the 1930 script and payment-fraud response if money moved.

Do not claim that changing one PIN automatically cancels loans, blocks every downloaded copy or secures an unrelated bank account. Each affected service needs its own protective action.

Support-ticket template

Subject: Unrecognised DigiLocker account/document activity

Registered mobile: [masked number]
Date/time first noticed: [date and time]
Activity observed: [exact Activity-log entry or document event]
Affected document/issuer: [type and issuer; mask document number]

I did not initiate [specific action]. Please investigate the account activity,
advise the official recovery steps and preserve the relevant logs. I have not
included any OTP, security PIN or password.

Evidence: masked screenshots, device/SIM incident reference and cybercrime/bank
acknowledgement if applicable.

Use the support portal itself. DigiLocker's FAQ and terms are the source for official help paths; avoid “customer care” numbers in ads, comments or forwarded messages.

Recovering from document theft

If Activity shows documents viewed or downloaded that you did not share:

  1. Credit watch. Pull your free annual credit report from each bureau's official portal and dispute unknown enquiries. A fraud alert tells lenders to verify you; it is not a police case by itself.
  2. PAN / tax. On the Income Tax e-filing portal, look for TDS/TCS or loan-linked activity you did not earn. A GST search on your PAN that shows a registration in a State you do not operate in is a separate cancellation request on the GST portal — attach the cybercrime acknowledgement.
  3. Driving licence and RC. Write to the issuing RTO through its official grievance route that the document may have been misused; ask it to note an alert on the record. Fetch issues are different: DigiLocker documents not showing.
  4. Banks. Tell each bank, through its official fraud desk, that identity documents may have been copied. Ask it to flag new Aadhaar-based account opening and new cards against your CIF. If an account is already frozen see bank freeze after cyber fraud.
  5. SIM. If Aadhaar was in the locker, treat a sudden dead SIM as a possible follow-on swap. Complete the operator block and the TAFCOP connection check.
  6. Do not pay anyone who offers to “delete the documents for a fee”. That is a second offence; forward the messages to the cyber complaint.

Before accepting a document said to be from DigiLocker:

A verified DigiLocker document can be legally useful, but that does not authorise unlimited copying or reuse of personal data. Organisations should collect only what their lawful process needs and protect the record after use.

Sample police / cyber complaint skeleton

File at cybercrime.gov.in first. Add a written complaint at the local cyber cell if a loan, SIM or bank account has already been opened in your name. Cite facts you can prove. The Information Technology Act includes section 66C (identity theft) and section 66D (cheating by personation using a computer resource). Do not invent a section number you have not read.

To: Station House Officer, [Cyber Crime Police Station]

Subject: Unauthorised access / attempted access to DigiLocker account

I, [name], resident of [address], mobile [masked], state:

1. On [date time] I received a call/SMS from [number] claiming to be
   DigiLocker support / eKYC and asking for OTP or security PIN.
2. I [did / did not] share the OTP. I then opened DigiLocker myself at
   digilocker.gov.in / the official app.
3. The Activity section shows [exact event, date, time]. I did not initiate it.
4. I revoked access / reset the PIN through the official flow and filed
   DigiLocker support ticket [id] and NCRP acknowledgement [id].
5. [If applicable:] Bank / loan / SIM event [facts].

I request registration of the complaint, preservation of telecom and
platform logs, and investigation. OTP, PIN and passwords are not enclosed.

Attachments: masked Activity screenshot, NCRP ack, support ticket,
call/SMS screenshot.

If the station refuses a cognizable complaint, give a written copy and use the superintendent / magistrate route your State actually provides. See cybercrime complaint and 1930.

Cybercrime law and realistic outcomes

The Information Technology Act includes section 66C on fraudulent or dishonest use of another person's electronic signature, password or unique identification feature, and section 66D on cheating by personation using a communication device or computer resource. The facts and evidence determine which offences or remedies authorities apply.

Neither a support ticket nor a cybercrime acknowledgement guarantees an instant account restoration, deletion of stolen copies, loan cancellation or recovery of money. Preserve evidence, notify every affected issuer or financial institution and track each reference separately.

Preventive checklist (official FAQ, not a mystery menu)

DigiLocker's FAQ is the source for what the service actually offers. On a device you control:

There is no sourced public “premium DigiLocker wallet” and no official GST-refund IVR. Anyone selling those is not DigiLocker.

Common mistakes

Worked example — illustrative, not a reported case

A caller says a driving licence in DigiLocker will expire unless the user shares an OTP. The user ends the call, opens DigiLocker from a bookmark and finds no notice. He checks the Activity log, preserves the caller's message and reports the suspicious communication through Chakshu. Because he shared no credential and lost no money, he does not invent a financial-fraud claim.

Frequently asked questions

What is the official DigiLocker website?

Use https://www.digilocker.gov.in/ and the official app linked by the service. Do not enter credentials through a link sent by an unknown caller.

What is the difference between issued and uploaded documents?

Issued documents come from registered issuers through DigiLocker. Uploaded documents are files placed in storage by the user and are not automatically issuer-authenticated.

Are DigiLocker-issued documents legally valid?

DigiLocker's official Rule 9A circular states that issuer-provided documents available through the Digital Locker system are at par with physical originals when used electronically.

Will DigiLocker support ask for my OTP or security PIN?

Never disclose either to an unsolicited caller or in a support ticket. Enter credentials only in an official flow you initiated.

Where can I see account activity?

The official FAQ identifies an Activity section for account activity. Review unfamiliar events and preserve a masked screenshot for support.

What if my registered mobile number changed?

Follow DigiLocker's current official FAQ and account flow for the situation. If the SIM was lost or taken over, contact the telecom provider first.

Where do I report financial fraud linked to DigiLocker impersonation?

Contact the bank/payment provider immediately, call 1930 and file at cybercrime.gov.in. Also open an official DigiLocker support ticket if the account is affected.

Can someone verify a DigiLocker document from a screenshot?

A screenshot alone is weak evidence. Use the secure QR or official issuer/DigiLocker verification method and check whether the document is issued or uploaded.

Official sources