DigiLocker is accessed through its official website or app—not through an unsolicited caller who asks for your OTP, security PIN, screen share or payment. Understand whether a document is issuer-provided or uploaded by you, review the Activity log, and use official support and cybercrime channels if account activity looks wrong.
Quick answer: Open DigiLocker only at digilocker.gov.in or its official app. Never disclose an OTP or security PIN to a caller. Issued documents come from registered issuers; uploaded files are user-provided. Review the Activity log and secure the linked mobile account if anything is unfamiliar. Report financial loss through 1930 and cybercrime.gov.in, and account issues through official DigiLocker support.
DigiLocker provides access to digital documents through a mobile-number login, OTP and security PIN process described in its official FAQ. Its security depends partly on protecting your phone, SIM, OTP and PIN. A document's presence in a chat, email or screenshot does not prove it came from DigiLocker or its issuer.
Searches for is DigiLocker safe and DigiLocker safety PIN are asking whether the platform, or the way people use it, is the weak point. DigiLocker's official FAQ states that the service is designed to be safe and lists practices including SSL encryption, multifactor sign-in via mobile OTP or biometric authentication combined with PIN validation, timed logout, CERT-In empanelled audits, and user-consent-based sharing with activity logged. That architecture does not make an OTP read aloud to a stranger safe.
Treat DigiLocker as safe when:
Treat it as compromised when a caller, SMS or APK asked for OTP, PIN, screen share or payment, or the Activity log shows a device or document event you did not start. Issued versus uploaded is explained in DigiLocker issuer reality. If a driving licence or RC will not fetch, use documents not showing and verification failed — those are fetch problems, not automatically fraud.
| Type | How it reaches the account | What to check |
|---|---|---|
| Issued document | A registered issuer makes or pushes it available through DigiLocker | Issuer name, document type, identifiers and QR/verification route |
| Uploaded document | The user uploads a file to DigiLocker storage | Source file, signer/eSign status if any, and whether the receiving authority accepts it |
| Shared document | The user uses an available sharing or consent flow | Exact document, recipient, purpose and activity record |
DigiLocker's official FAQ distinguishes issued and uploaded documents. Its circular explaining Rule 9A says documents made available by issuers through a citizen's Digital Locker account are at par with physical originals when used electronically. Do not extend that statement to every photograph or PDF uploaded by a user.
For an issued document, use the QR or verification method provided by DigiLocker or the issuer instead of trusting a screenshot. A cropped image can hide the issuer, document URI, QR code or altered fields.
An official-looking caller ID, logo or WhatsApp profile does not authenticate the person. End the contact and independently open the official service. DigiLocker does not become unsafe merely because a scammer uses its name; the practical risk is credential theft, impersonation or misuse of documents.
The official FAQ describes Forget Security PIN on the sign-in page. If you still control the Aadhaar-registered mobile:
If both the DigiLocker mobile and the Aadhaar mobile are gone, that is a SIM-control problem first: SIM stopped / swap recovery and Sanchar Saathi / TAFCOP connection check. DigiLocker support cannot issue you a stranger's SIM.
| ① Official app | ② Private OTP/PIN | ③ Check issuer | ④ Review activity | ⑤ Report safely |
|---|---|---|---|---|
| Start at DigiLocker | Never disclose | Issued is not uploaded | Investigate unknown events | Support plus cybercrime if needed |
There is no public “DigiLocker activity” tracker for other people. How to check DigiLocker activity means opening your account:
Do not email the full Activity export to a “recovery agent”. Attach a masked excerpt only to official DigiLocker support or to a police/cybercrime complaint you filed.
Stop when a caller or message:
Do not test the supplied link. Preserve the message, sender, time and displayed URL, then use the correct official reporting channel. Report the number via report a scam call.
Work in this order. Do not invent a DigiLocker “helpline” from ads.
Do not claim that changing one PIN automatically cancels loans, blocks every downloaded copy or secures an unrelated bank account. Each affected service needs its own protective action.
Subject: Unrecognised DigiLocker account/document activity Registered mobile: [masked number] Date/time first noticed: [date and time] Activity observed: [exact Activity-log entry or document event] Affected document/issuer: [type and issuer; mask document number] I did not initiate [specific action]. Please investigate the account activity, advise the official recovery steps and preserve the relevant logs. I have not included any OTP, security PIN or password. Evidence: masked screenshots, device/SIM incident reference and cybercrime/bank acknowledgement if applicable.
Use the support portal itself. DigiLocker's FAQ and terms are the source for official help paths; avoid “customer care” numbers in ads, comments or forwarded messages.
If Activity shows documents viewed or downloaded that you did not share:
Before accepting a document said to be from DigiLocker:
A verified DigiLocker document can be legally useful, but that does not authorise unlimited copying or reuse of personal data. Organisations should collect only what their lawful process needs and protect the record after use.
File at cybercrime.gov.in first. Add a written complaint at the local cyber cell if a loan, SIM or bank account has already been opened in your name. Cite facts you can prove. The Information Technology Act includes section 66C (identity theft) and section 66D (cheating by personation using a computer resource). Do not invent a section number you have not read.
To: Station House Officer, [Cyber Crime Police Station] Subject: Unauthorised access / attempted access to DigiLocker account I, [name], resident of [address], mobile [masked], state: 1. On [date time] I received a call/SMS from [number] claiming to be DigiLocker support / eKYC and asking for OTP or security PIN. 2. I [did / did not] share the OTP. I then opened DigiLocker myself at digilocker.gov.in / the official app. 3. The Activity section shows [exact event, date, time]. I did not initiate it. 4. I revoked access / reset the PIN through the official flow and filed DigiLocker support ticket [id] and NCRP acknowledgement [id]. 5. [If applicable:] Bank / loan / SIM event [facts]. I request registration of the complaint, preservation of telecom and platform logs, and investigation. OTP, PIN and passwords are not enclosed. Attachments: masked Activity screenshot, NCRP ack, support ticket, call/SMS screenshot.
If the station refuses a cognizable complaint, give a written copy and use the superintendent / magistrate route your State actually provides. See cybercrime complaint and 1930.
The Information Technology Act includes section 66C on fraudulent or dishonest use of another person's electronic signature, password or unique identification feature, and section 66D on cheating by personation using a communication device or computer resource. The facts and evidence determine which offences or remedies authorities apply.
Neither a support ticket nor a cybercrime acknowledgement guarantees an instant account restoration, deletion of stolen copies, loan cancellation or recovery of money. Preserve evidence, notify every affected issuer or financial institution and track each reference separately.
DigiLocker's FAQ is the source for what the service actually offers. On a device you control:
There is no sourced public “premium DigiLocker wallet” and no official GST-refund IVR. Anyone selling those is not DigiLocker.
A caller says a driving licence in DigiLocker will expire unless the user shares an OTP. The user ends the call, opens DigiLocker from a bookmark and finds no notice. He checks the Activity log, preserves the caller's message and reports the suspicious communication through Chakshu. Because he shared no credential and lost no money, he does not invent a financial-fraud claim.
Use https://www.digilocker.gov.in/ and the official app linked by the service. Do not enter credentials through a link sent by an unknown caller.
Issued documents come from registered issuers through DigiLocker. Uploaded documents are files placed in storage by the user and are not automatically issuer-authenticated.
DigiLocker's official Rule 9A circular states that issuer-provided documents available through the Digital Locker system are at par with physical originals when used electronically.
Never disclose either to an unsolicited caller or in a support ticket. Enter credentials only in an official flow you initiated.
The official FAQ identifies an Activity section for account activity. Review unfamiliar events and preserve a masked screenshot for support.
Follow DigiLocker's current official FAQ and account flow for the situation. If the SIM was lost or taken over, contact the telecom provider first.
Contact the bank/payment provider immediately, call 1930 and file at cybercrime.gov.in. Also open an official DigiLocker support ticket if the account is affected.
A screenshot alone is weak evidence. Use the secure QR or official issuer/DigiLocker verification method and check whether the document is issued or uploaded.