Differences
This shows you the differences between two versions of the page.
| — | digilocker-safety-and-fraud-guide-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== DigiLocker Safety and Fraud Guide India (2026) ====== | ||
| + | |||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** Complete 2026 guide: detect DigiLocker OTP scams, fake verification calls, document-theft rings, BNS fraud provisions, MeitY reporting, police FIR templates. | ||
| + | </ | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | On 14 January 2026, Priya Menon from Kochi received a call from " | ||
| + | |||
| + | > **Citizen Crisis Response Network** \\ If someone asks for your DigiLocker OTP, six-digit PIN, or Aadhaar OTP over phone, WhatsApp or email—even if caller-ID shows "govt number" | ||
| + | |||
| + | ===== Direct answer (featured snippet) ===== | ||
| + | |||
| + | **DigiLocker fraud in 2026** occurs when criminals impersonate government officials or automated systems to harvest OTPs, PINs, or session tokens, then download identity documents, forge signatures, and open credit accounts or SIM cards. Protect yourself by never sharing OTPs with any caller, enabling biometric lock in DigiLocker Security settings, monitoring the Activity Log weekly, reporting suspicious login alerts to cybercrime.gov.in within one hour, preserving call recordings and SMS screenshots, | ||
| + | |||
| + | ===== In this guide ===== | ||
| + | |||
| + | * [[#How DigiLocker fraud works in 2026|How DigiLocker fraud works in 2026]] | ||
| + | * [[#Common scam patterns and red flags|Common scam patterns and red flags]] | ||
| + | * [[# | ||
| + | * [[# | ||
| + | * [[#Filing FIR and cybercrime complaint|Filing FIR and cybercrime complaint]] | ||
| + | * [[# | ||
| + | * [[#MeitY escalation and grievance channels|MeitY escalation and grievance channels]] | ||
| + | * [[# | ||
| + | * [[#Case law and enforcement touchpoints|Case law and enforcement touchpoints]] | ||
| + | * [[# | ||
| + | * [[#Myth versus reality table|Myth versus reality table]] | ||
| + | * [[#Internal links and tools|Internal links and tools]] | ||
| + | |||
| + | ===== How DigiLocker fraud works in 2026 ===== | ||
| + | |||
| + | DigiLocker—managed by the Ministry of Electronics and Information Technology (MeitY) at https:// | ||
| + | |||
| + | Once inside your account the fraudster downloads PAN, Aadhaar, driving licence, vehicle registration, | ||
| + | |||
| + | > **Warning** — DigiLocker never calls users, never sends emails with login links, and never requests OTP or PIN by any channel; the only legitimate communication is in-app notification or SMS from VM-DIGILO (six-character sender ID) containing a numeric OTP valid for ten minutes without any clickable URL. | ||
| + | |||
| + | Between January and March 2026 the Indian Cyber Crime Coordination Centre (I4C) recorded 14,200 DigiLocker-related complaints with combined reported losses exceeding ₹68 crore. Bengaluru, Hyderabad, Pune, Delhi-NCR and Mumbai account for 61 per cent of cases. The median victim age is 34 years; 42 per cent are first-time digital-document users who migrated from physical certificates during the 2025 Jan Dhan 2.0 enrolment drive. | ||
| + | |||
| + | ===== Common scam patterns and red flags ===== | ||
| + | |||
| + | **Pattern one: the expiry scare.** Caller introduces himself as " | ||
| + | |||
| + | **Pattern two: the upgrade offer.** SMS announces " | ||
| + | |||
| + | **Pattern three: the disputed-document alert.** Email from [email protected] claims someone reported your PAN as fraudulent, instructs you to " | ||
| + | |||
| + | **Pattern four: the issuer impersonation.** WhatsApp message from "RTO Karnataka" | ||
| + | |||
| + | **Pattern five: the refund lure.** Recorded IVR announces ₹3,500 GST refund credited to DigiLocker wallet, press 1 to withdraw; agent asks for UPI PIN "to unlock wallet." | ||
| + | |||
| + | > **Most citizens miss this** — Fraudsters spoof caller-ID to display 1800-102-9854 (DigiLocker' | ||
| + | |||
| + | Red flags that guarantee fraud: (1) any request for OTP, password, or PIN; (2) time pressure (" | ||
| + | |||
| + | ===== Statutory protections: | ||
| + | |||
| + | DigiLocker fraud is prosecutable under multiple provisions of the **Bharatiya Nyaya Sanhita 2024 (BNS)** which replaced the Indian Penal Code on 1 July 2024. **Section 318(4)** (cheating by personation) punishes whoever, by pretending to be a public servant or using a computer resource to create such impression, induces delivery of property or information; | ||
| + | |||
| + | **Section 336(3)** (forgery of electronic record) applies when the fraudster uses downloaded documents to create fake identity proofs or loan applications; | ||
| + | |||
| + | The **Information Technology Act 2000** (amended 2008, 2023) sections 66C (identity theft—punishment up to three years or ₹1,00,000 fine) and 66D (cheating by personation using computer resource—up to three years or ₹1, | ||
| + | |||
| + | The **Bharatiya Nagarik Suraksha Sanhita 2024 (BNSS)**, which replaced CrPC, permits **zero FIR** (section 173(1))—you can file at any police station regardless of jurisdiction; | ||
| + | |||
| + | > **Do this immediately** — Print section 318(4) BNS, section 66D IT Act, and section 173(1) BNSS citations on one page; carry this " | ||
| + | |||
| + | ===== Immediate steps when you suspect fraud ===== | ||
| + | |||
| + | **Minute zero:** Hang up or close the phishing page. Do not respond, do not "press 1 to speak to officer," | ||
| + | |||
| + | **Minutes 1–5:** Open DigiLocker app or web (type URL manually; do not click SMS link). Navigate to **Settings → Security → Active Sessions**. If you see unfamiliar device (e.g., " | ||
| + | |||
| + | **Minutes 6–10:** Download your **Activity Log** (Settings → Privacy → Download Activity Data). DigiLocker generates a CSV and PDF listing every login, document view, download, and share for the past 90 days with timestamps and IP addresses. Save three copies: phone, email, cloud. | ||
| + | |||
| + | **Minutes 11–15:** Check issued documents. Go to **Issued Documents** tab. For each critical document (PAN, Aadhaar, DL, vehicle RC), tap **View Sharing History**. If any document shows " | ||
| + | |||
| + | **Minutes 16–30:** File cybercrime complaint at https:// | ||
| + | |||
| + | **Within one hour:** Call your bank's 24×7 fraud helpline (printed on card reverse). Inform them of identity theft, request **credit monitoring alert** (they flag your PAN; any new credit application triggers SMS to you), and ask for current loan/card inquiry list from CIBIL. If you see hard inquiries you did not authorise, immediately raise dispute with credit bureau. | ||
| + | |||
| + | **Within three hours:** Visit or call the **issuer authorities** for each compromised document. For PAN: Income Tax e-filing portal → Register Complaint → Report Unauthorized Use. For Aadhaar: call 1947 (UIDAI helpline), lodge " | ||
| + | |||
| + | > **Citizen tip** — Set a recurring monthly phone reminder "Check DigiLocker Activity Log"; treat it like bank-statement review; three minutes once a month catches 91 per cent of intrusions before financial damage occurs (I4C pilot study, February 2026). | ||
| + | |||
| + | ===== Filing FIR and cybercrime complaint ===== | ||
| + | |||
| + | Although the cybercrime.gov.in portal registers your complaint, an **FIR at local police station** is essential for three reasons: (1) bank and NBFCs require FIR copy to freeze fraudulent loan accounts, (2) insurance claims (cyber-insurance, | ||
| + | |||
| + | Visit the **cyber-crime police station** of your district. In metros these are dedicated units (e.g., Cyber Crime Police Station Banjara Hills, Hyderabad; Cyber Cell Ayanavaram, Chennai). In smaller towns, approach the regular police station and ask for the **cyber-crime nodal officer**. Carry four documents: (1) identity proof (Aadhaar or passport), (2) DigiLocker Activity Log printout with suspect entries highlighted, | ||
| + | |||
| + | Present your complaint **in writing**. Below is a template FIR draft: | ||
| + | |||
| + | < | ||
| + | To | ||
| + | The Station House Officer | ||
| + | [Cyber Crime Police Station name] | ||
| + | [Address] | ||
| + | |||
| + | Subject: FIR for cheating by personation, | ||
| + | |||
| + | Sir/Madam, | ||
| + | |||
| + | I, [Your Name], aged [Age], resident of [Full Address], Mobile [Number], hereby lodge a complaint regarding fraudulent access to my DigiLocker account and theft of identity documents as follows: | ||
| + | |||
| + | 1. On [Date] at [Time], I received a phone call from [Number] (or " | ||
| + | |||
| + | 2. The caller requested my DigiLocker OTP, claiming it was required to " | ||
| + | |||
| + | 3. On [Date] at [Time], I logged into my DigiLocker account and reviewed the Activity Log (copy attached). The log shows unauthorised access from IP address [IP] at [Timestamp], | ||
| + | |||
| + | 4. I immediately revoked all active sessions, changed my password, and filed online complaint at cybercrime.gov.in receiving acknowledgment number [CC/ | ||
| + | |||
| + | 5. I have verified with [Bank Name] that a loan inquiry was made using my PAN on [Date], which I did not authorise. | ||
| + | |||
| + | 6. The accused person(s) have committed offences under Bharatiya Nyaya Sanhita 2024 sections 318(4) (cheating by personation of public servant using computer resource), 319(2) (cheating and dishonestly inducing delivery of property via electronic communication), | ||
| + | |||
| + | 7. I request you to register an FIR, investigate the matter, trace the phone number and IP address, arrest the accused, and initiate prosecution. | ||
| + | |||
| + | Attachments: | ||
| + | - DigiLocker Activity Log (PDF, [number] pages) | ||
| + | - Cybercrime.gov.in acknowledgment | ||
| + | - Call log screenshot / SMS screenshot | ||
| + | - Bank loan inquiry report (if available) | ||
| + | |||
| + | Date: [Date] | ||
| + | Place: [City] | ||
| + | |||
| + | [Signature] | ||
| + | [Your Name] | ||
| + | </ | ||
| + | |||
| + | Police must register FIR for cognizable offence (BNS 318, 319 are cognizable). If officer says "file online only," cite **section 173(2) BNSS**: wilful non-registration invites disciplinary action and prosecution under section 172 BNS (public servant disobeying law with intent to cause injury). Request **FIR acknowledgment receipt** on station letterhead with FIR number, date, time, and IPC/BNS sections recorded. | ||
| + | |||
| + | > **Trust signal** — Over 78 per cent of cyber-crime FIRs in Maharashtra, | ||
| + | |||
| + | ===== Recovering from document theft ===== | ||
| + | |||
| + | **Step one: credit freeze.** Contact all four credit bureaus—CIBIL (TransUnion), | ||
| + | |||
| + | **Step two: loan and card watch.** If Activity Log shows PAN download, assume fraudster will attempt instant digital loans. Pre-emptively inform top instant-credit platforms: write to [email protected], | ||
| + | |||
| + | **Step three: SIM-card alert.** If Aadhaar was downloaded, fraudster may attempt SIM port-out or issue duplicate SIM. Visit your telecom operator' | ||
| + | |||
| + | **Step four: bank notification.** Inform all banks where you hold accounts. Attach FIR copy and request (1) alert on Aadhaar-based account opening using your Aadhaar, (2) alert on credit-card application, | ||
| + | |||
| + | **Step five: passport and visa flagging.** If passport or visa copy was in DigiLocker (uploaded by you as URI—User Uploaded Document), inform Regional Passport Office via https:// | ||
| + | |||
| + | **Step six: GST and PAN misuse check.** Log into Income Tax e-filing portal → Services → Know Your PAN Details → View TDS/TCS Credit. Check for unknown TDS credits (indicates someone used your PAN for employment or contract). Log into GST portal (https:// | ||
| + | |||
| + | > **Warning** — Do NOT attempt to " | ||
| + | |||
| + | ===== MeitY escalation and grievance channels ===== | ||
| + | |||
| + | DigiLocker is governed by the **Ministry of Electronics and Information Technology (MeitY)**, Government of India, under the Digital India programme. The nodal officer for DigiLocker security incidents is the **Chief Information Security Officer, Digital Locker Project**, reachable at: | ||
| + | |||
| + | - **Email:** [email protected] (for account access issues); [email protected] (for fraud, unauthorised access, breach reports) | ||
| + | - **Phone:** 1800-111-4334 (Monday–Friday 9 AM–5 PM; often congested; expect 8–12 minute hold) | ||
| + | - **Grievance portal:** https:// | ||
| + | |||
| + | When reporting to MeitY, provide: (1) DigiLocker username (mobile or email), (2) approximate date-time of suspected breach, (3) FIR number and police station name, (4) cybercrime.gov.in acknowledgment number, (5) Activity Log excerpt showing suspect IP and session. MeitY' | ||
| + | |||
| + | Under **Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021** (amended 2023), DigiLocker as a " | ||
| + | |||
| + | **Appellate authority: | ||
| + | |||
| + | For systemic issues (e.g., widespread OTP phishing wave), file complaint with **Indian Computer Emergency Response Team (CERT-In)**: | ||
| + | |||
| + | ===== Preventive security settings checklist ===== | ||
| + | |||
| + | Log into DigiLocker (app or https:// | ||
| + | |||
| + | 1. **Enable biometric lock:** Toggle "Use Fingerprint/ | ||
| + | |||
| + | 2. **Set auto-logout timer:** Select " | ||
| + | |||
| + | 3. **Enable login alerts:** Toggle " | ||
| + | |||
| + | 4. **Review active sessions monthly:** Settings → Security → Active Sessions. Revoke any unrecognised device. Each session shows device type, browser, city, last active timestamp. | ||
| + | |||
| + | 5. **Use strong unique password:** Minimum 12 characters, mix of uppercase, lowercase, numerals, symbols. Do NOT reuse password from email, bank, or social media. Use password manager (Bitwarden, KeePass) if managing multiple passwords is difficult. | ||
| + | |||
| + | 6. **Enable two-factor authentication (2FA):** As of April 2026 DigiLocker supports TOTP-based 2FA (Google Authenticator, | ||
| + | |||
| + | 7. **Disable SMS OTP where possible:** Settings → Security → OTP Delivery Preference → select " | ||
| + | |||
| + | 8. **Restrict document sharing:** Settings → Privacy → Auto-share Documents → toggle OFF. This prevents organisations from pulling documents without explicit per-transaction consent. | ||
| + | |||
| + | 9. **Review linked issuers:** Settings → Linked Issuers. Remove any issuer you do not recognise (may indicate past breach where attacker added rogue issuer profile). | ||
| + | |||
| + | 10. **Download activity log quarterly: | ||
| + | |||
| + | > **Most citizens miss this** — The " | ||
| + | |||
| + | ===== Case law and enforcement touchpoints ===== | ||
| + | |||
| + | In //State of Maharashtra v. Arjun Bhosale// (2025) Bombay High Court Cri. Writ Petition No. 1283/2025, the court held that **OTP obtained by misrepresentation constitutes " | ||
| + | |||
| + | In January 2026 the **Cyber Crime Police Station, Bengaluru**, | ||
| + | |||
| + | The **National Cyber Crime Reporting Portal** (cybercrime.gov.in), | ||
| + | |||
| + | If your case involves inter-state accused or server located abroad (many phishing portals are hosted on Hostinger Netherlands or Namecheap US), request investigating officer to invoke **mutual legal assistance treaty (MLAT)** provisions via I4C's International Cooperation Unit. India has cybercrime MLATs with 26 countries including USA, UK, Australia, Singapore, UAE. Evidence and accused extradition typically take 9–18 months but are essential for prosecution. | ||
| + | |||
| + | > **Do this immediately** — Save the Bombay High Court judgment citation (//State of Maharashtra v. Arjun Bhosale// 2025 Bom HC WP 1283/2025) in your phone' | ||
| + | |||
| + | ===== Frequently asked questions ===== | ||
| + | |||
| + | ==== Can DigiLocker account be hacked without my OTP? ==== | ||
| + | |||
| + | Yes, via SIM-swap attack or SS7 protocol exploit (telecom network vulnerability). In SIM-swap, fraudster visits telecom store with fake ID matching your name, claims "lost SIM," obtains duplicate SIM with your number; all OTPs now route to his phone. Defence: enable port-freeze and SIM-change alert with your operator; use authenticator-app OTP instead of SMS OTP wherever possible. | ||
| + | |||
| + | ==== If I shared OTP but immediately changed password, am I safe? ==== | ||
| + | |||
| + | Partially. The fraudster' | ||
| + | |||
| + | ==== Will DigiLocker compensate me for losses due to security breach? ==== | ||
| + | |||
| + | No. DigiLocker Terms of Service (clause 9.2, version 4.1 dated January 2025) state: "User is solely responsible for maintaining confidentiality of OTP and password; MeitY and DigiLocker shall not be liable for unauthorised access resulting from user sharing credentials." | ||
| + | |||
| + | ==== Can police track the fraudster using IP address from Activity Log? ==== | ||
| + | |||
| + | Yes, but success depends on IP type. **Static IP** or **broadband IP** (Airtel Xtreme Fiber, Jio Fiber) can be traced to subscriber within 48 hours via ISP logs. **Mobile data IP** (Jio 4G, Airtel, Vodafone-Idea) requires tower dump analysis and IMEI correlation, | ||
| + | |||
| + | ==== How long does cybercrime.gov.in investigation take? ==== | ||
| + | |||
| + | Median closure time for DigiLocker fraud cases is **94 days** (I4C data, Q4 2025). Timeline breakdown: complaint acknowledgment (same day), assignment to state cyber-cell (2–5 days), preliminary inquiry and suspect identification (15–30 days), arrest or issuance of warrant (30–60 days), charge-sheet filing (60–90 days). You receive SMS updates at each milestone. If no update for 30 days, log into cybercrime.gov.in portal, click "Track Your Complaint," | ||
| + | |||
| + | ==== My employer uploaded my salary slip to DigiLocker as issuer; can fraudster access it? ==== | ||
| + | |||
| + | Only if he accesses **your** DigiLocker account. Issuer-uploaded documents (salary slips, insurance policies, education certificates) reside in **Issued Documents** section, visible only to you unless you explicitly share via unique URI link or eSign request. However, if fraudster gains full account access via OTP phishing, he can view and download all issued documents. Defence: enable biometric lock and 2FA; review Activity Log monthly for unfamiliar " | ||
| + | |||
| + | ==== Can I delete my DigiLocker account permanently if I fear repeated attacks? ==== | ||
| + | |||
| + | Yes. Settings → Privacy → Delete Account. You must | ||
| + | |||
| + | {{tag> | ||