AePS / Aadhaar Biometric Fraud Recovery 2026
Last reviewed: 1 September 2026.
Quick Reply: AePS fraud recovery 2026 — bank account drained by Aadhaar biometric clone? Lock biometrics, NPCI dispute, RBI 3-day rule, FIR + RTI.
RBI Ombudsman as of 1 July 2026: Bank, certain NBFC, prepaid-instrument and credit-information complaints go under the Reserve Bank - Integrated Ombudsman Scheme, 2026, which replaced RB-IOS 2021 from 1 July 2026. First complain to the entity. If there is no reply in 30 days (or the longer NPCI/card-network window, if it applies) or you reject the reply, file free at cms.rbi.org.in within 90 days. The Ombudsman can award up to Rs 30 lakh for consequential loss and up to Rs 3 lakh for time, expenses and harassment. Complaints received before 1 July 2026 stay under the 2021 scheme. Source: RBI FAQ, updated 1 July 2026 and the RB-IOS 2026 FAQ PDF dated 1 July 2026.
Your bank account was emptied via the Aadhaar Enabled Payment System (AePS) without an OTP, without a card, without a phone alert — sometimes from a banking correspondent shop hundreds of kilometres away. This is AePS fraud — AePS accounted for about 11% of cyber-financial frauds analysed by I4C in 2023, and roughly 29,000 AePS fraud incidents had been logged on the NCRP by early 2024 (MHA reply to Parliament). The RBI's “Customer Liability Framework, 2017” + the 3-day rule says you get 100% refund if you report within 3 working days. Here is the exact, working recovery sequence — by the clock.
Quick Answer
- First action — within 1 hour: Lock your Aadhaar biometrics at https://uidai.gov.in → My Aadhaar → Lock/Unlock biometrics. Free, instant, 24×7.
- Within 3 working days: file a written complaint to your bank citing RBI Customer Liability Framework, 2017 — full refund mandatory if reported in 3 days.
- Within 24 hours: dial 1930 + file at https://cybercrime.gov.in under Financial fraud → AePS / Biometric fraud.
- Within 48 hours: register an FIR at the cyber police station — IT Act §66C/§66D + BNS §318(4)/§319(2).
- NPCI dispute: ask your bank to raise an AePS dispute with the acquirer bank via NPCI (https://www.npci.org.in/product/aeps) for inter-bank transactions.
- RBI Banking Ombudsman: https://cms.rbi.org.in if bank does not respond in 30 days. Free.
- Recovery chances: best inside 3 working days — the RBI framework then fixes your liability at zero. Beyond that the limited-liability slabs (₹5,000–₹25,000) apply, and every extra day of delay weakens both the bank credit and police recovery.
- Cost: ₹0 anywhere in the process.
🔔 Track AePS fraud trends + UIDAI biometric updates by email. Free notifications. Help RTI Wiki yearly →
Quick Action Steps
- Lock Aadhaar biometrics NOW at uidai.gov.in (or m-Aadhaar app → Biometric Lock toggle). Stops further fraud instantly.
- Take screenshots of: bank SMS/email of the debit, account statement, any AePS terminal location info.
- Call your bank on its registered helpline → log bank-side fraud complaint with a written acknowledgement number. Tell them: “Section 6.3 of RBI Customer Liability Framework — zero liability.”
- Dial 1930 — Cyber Crime helpline. Lock the destination account.
- File at https://cybercrime.gov.in within 24 hours.
- Get FIR copy at the cyber police station within 48 hours.
- NPCI dispute — ask your bank to raise it via NPCI for AePS-specific transaction reversal.
- Bank must credit the refund within 10 working days of its decision, and resolve the complaint within 90 days (RBI rule).
- If bank stalls — RBI Banking Ombudsman at cms.rbi.org.in.
- RTI to UIDAI for transaction logs (which agency / device used your fingerprint).
- Update Aadhaar mobile at the nearest enrolment centre — keep it linked.
What is AePS Fraud?
AePS (Aadhaar Enabled Payment System) is a financial product run by NPCI that lets a citizen withdraw cash, deposit, or transfer using only Aadhaar number + fingerprint at any Banking Correspondent (BC) shop or micro-ATM. No card, no PIN, no OTP.
Fraud happens when your biometric is silently captured and replayed on an AePS terminal:
- Property registry biometric leaks — sub-registrar offices in MH, RJ, UP, KA, AP have leaked thumbprint scans into the public registry portal. Crooks lift these.
- eKYC trap — fake “Aadhaar update” stalls capture your fingerprint with a rogue biometric scanner.
- Rubber-finger clone — a 3D-printed or silicone replica using a scanned biometric.
- Compromised BC operator — a corrupt Banking Correspondent shop runs ghost transactions with stolen biometrics from public registry leaks.
- Telecom KYC trap — your biometric was captured for a fake new SIM, then reused.
You may discover the fraud only when you check your bank balance. No SMS is sent in many AePS transactions because the BC is offline.
Recent Patterns (2023-2026)
- Losses often run into the lakhs — fraudsters chain withdrawals across days.
- 3-7 successive ₹10,000 withdrawals — AePS per-transaction limit is ₹10,000; criminals chain multiple.
- Geographically distant — victims in Delhi see withdrawals in Bihar, Telangana, West Bengal.
- Sub-registrar leak clusters — police in Karnataka and Telangana have traced AePS fraud rackets to fingerprints lifted from property-registration records (e.g. the 2023-24 Mangaluru sub-registrar office cases).
- Concentration — reported clusters include Telangana, Andhra Pradesh, Karnataka, Bihar and Maharashtra, mostly tied to leaked registration-portal biometrics.
Legal Framework
A. RBI Customer Liability Framework, 2017
Source: RBI/2017-18/15 dated 06 Jul 2017.
- Zero liability if reported within 3 working days (Banks: §6.3).
- Limited liability up to ₹25,000 if reported within 4-7 working days.
- Bank must credit shadow / temporary refund within 10 working days.
- Final resolution: 90 days from complaint.
- The burden of proof to show customer negligence is on the bank, not the customer.
B. NPCI AePS Dispute Resolution Mechanism
- Inter-bank AePS disputes are raised by your bank against the acquirer bank through NPCI's dispute system — insist in writing that your bank raise one.
- NPCI's AePS Operating and Settlement Guidelines fix turnaround times per dispute type; hold your bank to them.
- Compensation: delay beyond the prescribed turnaround attracts ₹100/day compensation under NPCI's settlement rules and RBI's harmonised TAT framework.
C. Aadhaar Act, 2016
- §7 — Aadhaar authentication for benefit / service.
- §8 — conditions for authentication: informed consent and specified purpose before every authentication. UIDAI separately offers a biometric lock facility (myAadhaar / m-Aadhaar).
- §29(4) — biometric data is classified personal data, can never be shared in public domain.
- §35, §38 — penalties for impersonation (§35) and unauthorised access to the CIDR (§38), each up to 3 years.
D. IT Act, 2000 + DPDP, 2023
- §43A IT Act — body corporate liable for negligence with sensitive personal data.
- §66C — identity theft (3 years).
- DPDP §8 — data fiduciaries must implement security safeguards against personal-data breaches; failure attracts penalties of up to ₹250 crore.
E. BNS, 2023
- §318(4) — cheating and dishonestly inducing delivery of property (up to 7 years).
- §319(2) — cheating by personation (up to 5 years).
- §336(3) — forgery for cheating (up to 7 years).
F. UIDAI Right to Privacy
Every Aadhaar holder can lock/unlock biometrics through UIDAI's myAadhaar portal or the m-Aadhaar app — a free, 24×7 facility UIDAI operates for all holders.
Step-by-Step Recovery Process
Step 1 — Lock biometrics (within minutes)
- Open m-Aadhaar app (Android / iOS, free, official) OR https://uidai.gov.in → My Aadhaar.
- Login with Aadhaar number + OTP to your mobile.
- Lock/Unlock Biometrics → tap Lock.
- Your biometric is now disabled for AePS, eKYC, all third-party authentications. You can unlock temporarily for genuine eKYC.
Step 2 — Bank complaint (within 3 working days)
- Visit branch or call helpline. Get complaint number in writing (not just verbal).
- Mention specifically: “AePS unauthorised debit. Section 6.3 RBI Customer Liability Framework, 2017. Zero liability. I have reported within 3 working days.”
- Submit a written letter + bank statement + ID proof. Get a receiving stamp with date/time.
- Demand shadow credit within 10 working days (RBI rule).
Sample bank complaint letter (use the RTI Drafter to auto-generate):
To, Branch Manager, [Bank], [Branch].
Sub: AePS Unauthorised Debit — RBI Customer Liability Framework Claim.
Account no: … I noticed unauthorised AePS debits totalling ₹… on dates… I confirm I did not authorise these transactions; I did not share my Aadhaar / biometric. As per RBI/2017-18/15 dated 06 Jul 2017 §6.3, I am reporting within 3 working days; my zero-liability claim attaches. Kindly: (a) issue a shadow credit within 10 working days, (b) raise an AePS dispute at NPCI, © provide a copy of the AePS terminal log + BC ID. — [Signature, Date].
Step 3 — NCRP + 1930 (within 24 hours)
- Dial 1930 (24×7) — give bank account, transaction details. Scammer's destination account is frozen.
- File at https://cybercrime.gov.in → Financial fraud → AePS / Biometric fraud. Save Acknowledgement Number.
Step 4 — FIR (within 48 hours)
- Cyber police station (or your area police if no separate cyber cell).
- Sections to cite: IT Act §66C, §66D, BNS §318(4), §319(2), §336(3).
- Carry: ID proof, bank statement, NCRP acknowledgement, screenshots.
Step 5 — NPCI dispute
- Your bank raises the dispute with the acquirer bank through NPCI's AePS dispute system (AePS rules at https://www.npci.org.in/product/aeps).
- The acquirer bank (BC location's bank) is required to provide: BC ID, terminal MAC, GPS coordinates, biometric capture timestamp.
- Fixed turnaround times apply per NPCI's AePS rules — delay beyond TAT attracts ₹100/day compensation. Follow up with your bank in writing.
Step 6 — RBI Ombudsman (Day 30 if bank stalls)
- File at https://cms.rbi.org.in — Reserve Bank - Integrated Ombudsman Scheme, 2026.
- Free. No advocate required.
- Order in 60-90 days. Compensation: actual loss + interest + up to ₹3 lakh for mental harassment under RB-IOS 2026.
Step 7 — RTI escalation (Day 30+)
File RTIs to track investigation:
- To UIDAI: Authentication logs for my Aadhaar number on dates X-Y; AUA / Sub-AUA names; OTP / biometric flag; outcome.
- To your bank (public sector): Status of complaint number Z; date NPCI dispute raised; reply received from acquirer bank; reason for delay if past 90 days.
- To Police: FIR number A — investigating officer, date of next investigation step, action taken on banking correspondent.
Use the RTI Drafter — drafts these 3 RTIs from your case description.
Documents Required
| Document | Purpose |
| Aadhaar card + masked Aadhaar | ID proof (use masked for FIR/online filings). |
| PAN card | KYC at bank. |
| Bank statement — 90 days | Proof of unauthorised debits. |
| Mobile number registered with Aadhaar | For OTPs during UIDAI lock. |
| NCRP acknowledgement | Generated when filed at cybercrime.gov.in. |
| FIR copy | After cyber police station registration. |
| NPCI dispute reference | Once bank raises chargeback to acquirer. |
| m-Aadhaar lock screenshot | Evidence biometrics were locked at time T. |
Common Mistakes to Avoid
- Waiting “to see if money comes back” — every day costs you the zero-liability ceiling.
- Calling bank on a non-registered number from Google search — can be a scam helpline. Use the number on your debit card / passbook.
- Sharing OTP with “bank verification officer” — banks never ask for OTP. Hang up.
- Going to a “cyber cell agent” who promises 100% recovery for a fee — they are second-stage scammers.
- Not locking biometrics — fraud continues even while complaint is pending.
- Skipping NPCI dispute — bank handles chargeback only via NPCI for AePS.
- Settling for partial refund — RBI 3-day rule mandates full refund. Push back.
FAQs
Can the bank refuse refund saying "you must have shared biometrics"?
No. Under RBI Customer Liability Framework §6.3, the burden of proof is on the bank to demonstrate customer negligence. Mere assertion is not enough. If the fraud was via leaked sub-registrar biometric, you shared no credential at all — that is squarely a third-party breach under the RBI framework, which strengthens your zero-liability case even after 3 days.
Should I close my bank account?
Don't close immediately — refund depends on the same account. Freeze AePS only by writing to your bank (Disable AePS-out facility on my account). Switch to a Jan Dhan account ONLY for AePS-needed benefits.
How does Aadhaar locking affect my regular life?
It only blocks biometric authentication (AePS, eKYC). Your Aadhaar OTP, demographic verification, ration card, IT filings all work normally. You can unlock temporarily for genuine eKYC.
What if I'm a senior citizen / illiterate / from a village?
Your Banking Correspondent or Common Service Centre (CSC) can lock Aadhaar for you. Or call UIDAI helpline 1947. The local District Legal Services Authority (DLSA) can help file FIR + bank complaint for free.
My biometric was leaked from a sub-registrar office. Who is liable?
The State Government (Stamp & Registration Department) can be pursued under Article 21 (privacy) and the DPDP Act's security-safeguard duty (§8) — UIDAI itself advised citizens to lock biometrics after these leaks. Class action is possible (a group complaint under CPA §35, or a PIL).
Can the BC operator be arrested?
Yes — police invoke IT Act §66C + §66D with BNS §318(4) + §319(2), and organised rings additionally attract BNS §111 (organised crime).
What's the difference between AePS fraud and UPI fraud?
UPI: needs your OTP / device + UPI PIN. Loss reverses through 1930 → bank freeze. AePS: needs only your Aadhaar + biometric. Loss reverses through bank complaint → NPCI dispute. The 3-day rule applies to both.
Will RBI compensate me directly?
RBI is the regulator, not the payer. Your bank pays — RBI orders it. The RBI Ombudsman can award up to ₹3 lakh under RB-IOS 2026 for loss of time, expenses and mental anguish, in addition to the refund.
Can I claim mental distress?
Yes — through Consumer Court (District Commission) for deficiency in service (CPA §2(11)) + Banking Ombudsman award. Typical: ₹25,000-₹2,00,000.
I haven't filed FIR but I want to. Am I too late?
No deadline for FIR filing under §173 BNSS. But every day weakens evidence. File even at Day 60 — the FIR triggers police investigation that may still recover money via inter-bank reversals.
What if my bank ignores my complaint?
After 30 days of silence: file at RBI Banking Ombudsman (https://cms.rbi.org.in) → Mobile or Internet Banking → Customer Liability Framework violation. Order compels bank action.
Is AePS being phased out?
Not phased out, but tightening through 2026: UIDAI-certified liveness detection for biometric devices, NPCI step-up OTP for AePS cash withdrawals above ₹5,000, and RBI's due-diligence directions for AePS touchpoint operators (effective 1 January 2026) are all coming in. Until they fully bite, lock biometrics by default is the safest stance.
Can NRIs use AePS / be affected?
NRIs can have NRO/NRE accounts. AePS uses Aadhaar — if you don't have Aadhaar, no exposure. If you do, lock biometrics. Same RBI rules apply.
Internal Linking Suggestions
External References
- RBI Customer Liability Framework, 2017 — https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11040
- NPCI AePS — https://www.npci.org.in/product/aeps
- UIDAI Lock/Unlock Biometric — https://uidai.gov.in
- National Cyber Crime Reporting Portal — https://cybercrime.gov.in
- RBI Banking Ombudsman (CMS) — https://cms.rbi.org.in
- m-Aadhaar app — Google Play / App Store (UIDAI official).
Conclusion
AePS fraud is preventable: lock your Aadhaar biometric today, even before any incident. If you've been hit, the 3-day window to bank + 24-hour window to NCRP is what determines whether you get 100% back or 0%. The law is unambiguously on your side — RBI, UIDAI, NPCI, NALSA all converge on protecting the citizen. The only failure mode is delay.
If your bank stalls, file an RTI to extract the AePS terminal log + BC ID — that single document forces internal action. The RTI Drafter auto-generates this.
Sources
- RBI Customer Liability Framework, 2017 (RBI/2017-18/15).
- NPCI AePS Operating and Settlement Guidelines (dispute management).
- Aadhaar Act, 2016 — §7, §8, §29(4), §35, §38.
- Information Technology Act, 2000 — §43A, §66C, §66D.
- Bharatiya Nyaya Sanhita, 2023 — §318(4), §319(2), §336(3).
- Reserve Bank - Integrated Ombudsman Scheme, 2026.
- Digital Personal Data Protection Act, 2023.
