We have been taught one rule for banking safety: “Never share your OTP.”
But what if I told you that hackers can empty your bank account without your OTP, without your Debit Card, and without hacking your password?
In 2025, this is the reality of AePS (Aadhaar Enabled Payment System) Fraud. Criminals are using stolen fingerprint data to withdraw money from your account while you are sleeping.
In this CSNR Cyber Awareness guide, we explain how this “Silent Scam” works and the single most important setting you must change on the UIDAI portal today to protect your life savings.
What is AePS? (The Loophole)
AePS was designed to help people in rural India withdraw money using just their Aadhaar Number and Fingerprint. No card or PIN is needed.
The Scam:
-
Data Theft: Scammers buy fingerprint data from hacked land registry offices or property document leaks.
-
Cloning: They create a “Silicone Thumb” using your stolen fingerprint image.
-
Theft: They go to any rural CSP (Customer Service Point), enter your Aadhaar number, use the fake thumb, and withdraw cash.
-
No Alert: Since the system thinks you are authenticating the transaction with your finger, no OTP is sent to your phone. You only get an SMS saying “Rs. 10,000 Debited.”
While securing your biometrics, ensure your digital identity is safe too. Read about the Digital Arrest Scam where scammers impersonate police.
The Solution: “Lock” Your Biometrics
The Unique Identification Authority of India (UIDAI) provides a “Lock” switch. When enabled, your fingerprint and iris scan cannot be used for authentication. Even if a hacker has your silicone thumbprint, the system will reject the transaction saying “Biometric Locked.”
Step-by-Step Guide: How to Lock It (Takes 2 Minutes)
You can do this via the mAadhaar App or the UIDAI Website. We recommend the App for ease of use.
Method 1: Using the mAadhaar App (Recommended)
-
Download: Install the official mAadhaar app from the Play Store or App Store.
-
Login: Register with your mobile number linked to Aadhaar.
-
Go to Profile: Tap on “My Aadhaar” and enter your 4-digit PIN.
-
Find the Switch: Scroll down to find “Biometric Lock”.
-
Activate: Tap it. You will receive an OTP. Enter it to confirm.
-
Status: Your screen will show a “Red Padlock” icon. 🔒
-
Result: Your biometrics are now disabled for AePS.
-
Method 2: Using the UIDAI Website
-
Go to
myaadhaar.uidai.gov.in. -
Login with Aadhaar Number + OTP.
-
Click on the card that says “Lock/Unlock Biometrics”.
-
Follow the instructions to confirm the lock.
When Should You “Unlock”?
You only need to unlock it when YOU need to use your fingerprint. Examples:
-
Buying a new SIM card.
-
Registering a property.
-
Giving attendance at a government office.
How to Unlock: Open the App > Click “Unlock Biometrics”.
-
Temporary Unlock: Opens for 10 minutes (Good for SIM KYC).
-
Disable Lock: Permanently removes the lock (Not Recommended).
How to Check if You Are Already a Victim?
If you suspect foul play, check your bank statement for transaction codes like:
-
AePS WDL(Withdrawal) -
CW Dr(Cash Withdrawal Debit)
If you see these and you didn’t make the withdrawal:
-
Lock Biometrics Immediately.
-
Call 1930: Report the financial fraud.
-
Visit Bank: Dispute the transaction under “Unauthorized Electronic Banking Transaction” rules.
CSNR Verdict: Convenience vs. Security
For city dwellers who use Debit Cards and UPI, AePS is a liability, not a feature. You rarely use your fingerprint for payments.
Leaving your biometrics “Unlocked” is like leaving your house door open because you might want to walk out someday. It makes no sense.
Take Action Now: Pick up your phone, download mAadhaar, and LOCK your biometrics. It is the only firewall between your hard-earned money and a silicone thumb.









