Online Threat Alerts (OTA) - Alerting you to scams and frauds.

AEPS Scam Bank Security - Protect Yourself

AEPS Scam Bank Security - Protect Yourself

The Aadhaar Enabled Payment System (AePS) is a banking service that allows transactions (cash withdrawals, deposits, etc.) using only an Aadhaar number and biometric authentication (fingerprint or iris scan). While convenient, it has become a target for scams because it typically does not require a PIN or OTP.

Common AePS Scams

  • Biometric Cloning: Fraudsters obtain fingerprints from public documents (like land records) and create silicon or glue replicas to authorize transactions.
  • Impersonation: Scammers pose as bank agents or government officials to trick victims into providing their Aadhaar number and scanning their finger on a fake device.
  • Device Tampering: Fraudsters use compromised biometric scanners that secretly record biometric data while appearing to perform a legitimate transaction.
  • Phishing/Vishing: Deceptive calls or messages urge users to "verify" their account by clicking a link or providing details to avoid account suspension.

Essential Security Measures

The most effective way to prevent these scams is by locking your Aadhaar biometrics.

  1. Lock Your Biometrics: Use the UIDAI Website or mAadhaar app to disable biometric authentication. Once locked, no one can use your fingerprint for transactions until you temporarily unlock it.
  2. Transact at Authorized Points Only: Only use AePS services at official bank branches or through registered Banking Correspondents (BCs) with clear identification.
  3. Enable Transaction Alerts: Ensure your mobile number is linked to your bank account to receive immediate SMS alerts for every debit.
  4. Use Masked Aadhaar: Share a "Masked Aadhaar" (which hides the first 8 digits) instead of your full Aadhaar card for routine identity verification.
  5. New 2026 RBI Security Rules: The Reserve Bank of India (RBI) has mandated stricter security effective January 1, 2026, including:
    • Liveness Detection: Technology to ensure a biometric scan is from a live person, not a clone.
    • Two-Factor Authentication (2FA): OTP-based verification for withdrawals exceeding ₹5,000.

What to do if scammed?

If you notice an unauthorized transaction, act within 48 to 72 hours to minimize liability.

  • Bank: Immediately call your bank's fraud helpline to block your account.
  • Cybercrime Portal: File a complaint at the National Cybercrime Reporting Portal or call the helpline at 1930.
  • Police: File a First Information Report (FIR) at your local police station.

More From OTA

Check the comment section below for additional information, share what you know, or ask a question about this article by leaving a comment below.

Comment sectionComments / Answers

To protect your privacy, please remove sensitive or identifiable information from your post. Your IP address will be used to display your estimated location in your post.

waiting

CommentsPost Comment / Answer