Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
AePS fraud is not, by itself, evidence that Aadhaar’s central database was hacked. Reported cases point to risks across a wider chain: exposed identity documents, biometric devices, business correspondent (BC) touchpoints, payment operators and banks’ fraud controls. A transaction authenticated with a biometric can still be disputed; it does not automatically prove that the account holder was present or authorised a withdrawal.
Aadhaar Enabled Payment System (AePS) brings basic banking to customers who may be far from a branch or ATM. That access matters. So do safeguards, clear records and a complaint process that does not leave a customer to chase several institutions alone. Here is how the system works, what is known about fingerprint misuse, and what to do if an account is debited without your permission.
What AePS does—and what it does not do
AePS is a bank-led, interoperable payment system operated by NPCI. At a participating Bank Mitra, BC or Customer Service Point, a customer can use Aadhaar-linked authentication to access services including cash withdrawal, cash deposit, fund transfer, balance enquiry and mini statement. Depending on the service and transaction flow, the customer may provide account-bank details and authenticate biometrically. The precise process and limits can vary by bank and product. NPCI’s AePS overview lists the system’s services and describes its bank-led model.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →AePS is not UPI, an ATM withdrawal, or the Aadhaar Payment Bridge System (APBS), which is used for certain benefit payments. Nor does Aadhaar itself hold or debit a bank account. UIDAI says that ordinary Aadhaar authentication returns a response to the requesting entity and that UIDAI does not receive bank-account details in that process. The bank, acquiring bank, BC/CSP, payment-processing chain and Aadhaar authentication service have distinct roles. UIDAI’s explanation of its security system is useful context, but it does not settle whether downstream devices, operators or transaction controls worked properly in a particular case.
#1 Best Overall
- Target Applications - Desktop PC security, Mobile PCs, Custom applications
- Indoor, home and office use
- Blue LED - soft, cool blue glow fits into any environment; doesn't compete in low light environments
- Small form factor - conserves valuable desk space
- Rugged construction - high-quality metal casing weighted to resist unintentional movement
The basic chain is: customer → BC/CSP and biometric device → acquiring bank/payment service → NPCI payment switch → customer’s bank, with Aadhaar authentication supporting the relevant step. A failure or abuse can occur at different points. Saying simply “Aadhaar was hacked” obscures those distinctions.
How an unauthorised withdrawal might happen
Reported cases describe a possible fraud chain, not a universal recipe and not a mechanism proven in every complaint:
- Identity details are obtained. Information such as a person’s name, Aadhaar number or bank linkage may be exposed through documents, social engineering, improper access or other data leaks.
- A fingerprint image or impression is obtained. In cases reported by police and journalists, fingerprints visible on publicly accessible land or property records were allegedly copied and turned into replicas. The reports describe allegations and case-specific investigations, not proof that every AePS fraud uses a copied print. See the Scroll investigation and an Indian Express report on a Haryana police investigation.
- A transaction channel is accessed. That may involve a BC/CSP, operator account, payment-service provider or a badly controlled or compromised touchpoint. An investigation needs to identify who onboarded and operated the point.
- A biometric is presented to a device. Whether a replica or other spoof can succeed depends on the device, software, liveness checks, authentication route and operator controls. A copied fingerprint is not automatically accepted by every scanner.
- The linked account is debited. The customer may notice only through an SMS, passbook, balance enquiry or later visit to the bank.
These stages should not be collapsed into the claim that fingerprints were definitively cloned. A bank employee’s initial explanation is not forensic proof. Establishing the mechanism requires transaction and device records, operator details, authentication information and, where relevant, police or forensic findings.
Can fingerprints be stolen?
A fingerprint cannot be replaced like a password. But an image, impression or template can potentially be copied or misused. A biometric match is only one part of an authentication system: device quality, liveness detection, software, operator access and monitoring all matter. Even a technically successful biometric check does not by itself establish that the customer was physically present or knowingly authorised the specific amount and transaction.
A 2023 investigation quoted experts who said fingerprints on public property documents could be copied and raised concerns about liveness controls on some privately operated scanners. Those claims should be attributed to the experts and reports; they are not a finding that every device lacks anti-spoofing measures or that each reported transaction used a replica. UIDAI describes protections in its own authentication ecosystem, but readers should not assume that an enrolment-centre control applies identically at every BC touchpoint.
Who is responsible for which part?
| Actor | Role in the chain | What a customer or investigator should establish |
|---|---|---|
| Customer’s bank | Holds the account and records the debit. | What transaction was authorised, what controls were applied, whether AePS can be restricted, and the written complaint decision. |
| Acquiring bank | May service or onboard the transaction touchpoint. | Which BC/CSP, operator and terminal were involved, and whether onboarding and monitoring requirements were followed. |
| BC/CSP or Bank Mitra | Customer-facing point that handles the service and device. | Who operated the device, at what location and time, and what receipt or transaction record exists. |
| NPCI | Operates the payment-system infrastructure and publishes AePS rules and complaint information. | What fraud-reporting and liability processes apply across the participating institutions. |
| UIDAI | Provides Aadhaar authentication services and biometric controls. | What modality was used and whether a biometric lock was active at the relevant time. |
| Police and cybercrime authorities | Investigate suspected crime and pursue fund tracing. | Whether device, operator and recipient-account evidence was preserved and examined. |
| RBI | Regulates banks and issues relevant banking directions. | Whether regulated entities met applicable due-diligence and fraud-risk requirements. |
What has changed by January 1, 2026?
RBI issued directions on June 27, 2025 covering due diligence of AePS touchpoint operators and fraud-risk management. The directions took effect on January 1, 2026. Their focus is significant because a secure payment system depends not just on the customer’s credential but also on trustworthy, monitored points of access. The circular is available here.
Rank #2
- FIDO U2F certified, and FIDO2 WebAuthn compatible for expanded authentication options, including strong single-factor (passwordless), dual, multi-factor, and Tap-and-Go support across major browsers (for services leveraging the older FIDO U2F standard, instead of using biometric authentication, Tap-and-Go allows the user to simply place their finger on the VeriMark Desktop Fingerprint Key to enable a security token experience).
- Windows Hello certified (includes Windows Hello for Business) for seamless integration. Also compatible with additional Microsoft services including Office365, Microsoft Entra ID, Outlook, and many more. Windows ARM-based computers are currently not supported. Please check back for future updates on compatibility
- Encrypted end-to-end security with Match-in-Sensor Fingerprint Technology combines superior biometric performance and 360° readability with anti-spoofing technology. Exceeds industry standards for false rejection rate (FRR 2%) and false acceptance rate (FAR 0.001%).
- Long (3.9 ft./1.2m) USB Cable provides the flexibility to be placed virtually anywhere on or near the desktop.
- Can be used to support cybersecurity measures consistent with (but not limited to) such privacy laws and regulations as GDPR, BIPA, and CCPA. Ready for use in U.S. Federal Government institutions and organizations.
That effective date is not proof that fraud has ended or that every outlet has implemented controls flawlessly. The meaningful test is measurable enforcement: operator verification, ongoing monitoring, device and transaction records, prompt investigation, and consequences when a touchpoint fails the rules.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesOther measures described in a government response include stronger onboarding KYC, biometric authentication for each BC transaction, integration of NPCI fraud management with cybercrime reporting, customer options to disable AePS debits, and cumulative limits for certain withdrawal categories. The response described a monthly cumulative figure up to ₹50,000 for certain services; it should not be treated as a universal current AePS limit. Limits and controls can differ by bank, service and later rule changes, so ask your bank for the applicable account-specific setting. The government response is here. NPCI also has a 2022 AePS fraud-liability addendum covering listed transactions involving BCs, BC agents and CSPs.
If you see an unauthorised AePS debit: act immediately
- Call your bank using an official number from its website, passbook or card documentation. Say: “This is an unauthorised AePS transaction. Please block further AePS debits if available, register my complaint and give me the complaint/reference number in writing.”
- Call 1930 promptly to report the financial cyber fraud. Speed can matter when funds may still be traceable or held.
- File or complete the complaint online at the National Cybercrime Reporting Portal.
- Ask the bank to preserve and disclose the transaction trail: transaction ID, time, amount, transaction type, authentication modality, BC/CSP identity, acquiring bank, terminal/device and operator details, and any location or response information it can provide.
- Ask about account-level AePS controls. Request the narrowest available restriction on further AePS debits. Do not assume that locking Aadhaar automatically disables every AePS route.
- Keep evidence: SMS alerts, a full statement or passbook entries, complaint acknowledgements, call logs, names and designations of officials, and police/cybercrime references. If the registered mobile number is old or inaccessible, tell the bank and update it through the bank’s official process.
- Escalate in writing. If the transaction chain or decision is not explained, use the bank’s grievance and nodal-officer process. You can also submit a complaint through NPCI’s complaint route. Consider police assistance and, where applicable, the RBI Integrated Ombudsman route.
Do not rely on a verbal statement that “the fingerprint matched” as a complete investigation. Ask for the bank’s findings and the reason for any rejection in writing. A zero balance alone also does not identify the transaction: obtain the full statement and transaction reference.
Biometric lock, Aadhaar lock and bank-level AePS control are different
| Control | What it does | Trade-off |
|---|---|---|
| Bank-level AePS debit disablement | Where offered, targets AePS debit transactions on the bank account. | Ask the bank exactly which services and transaction routes are blocked and how to restore access. |
| UIDAI biometric lock | Prevents biometric authentication using fingerprint, iris or face while active. UIDAI says a locked-biometric authentication should fail; it identifies response code 330 for this condition. | It can interrupt legitimate biometric Aadhaar services, not only banking. It is not a general account freeze or a guarantee that every debit channel is disabled. |
| Aadhaar/UID lock | Broader: blocks Aadhaar number, UID token and VID authentication across biometric, demographic and OTP modalities. | May disrupt more Aadhaar-based services. UIDAI says the latest VID is needed to unlock through its stated process. |
UIDAI’s biometric lock is available through its online services and m-Aadhaar, or with help at an Aadhaar Seva Kendra; an online user needs a registered mobile number. Biometrics can be temporarily unlocked for a legitimate authentication or the lock can be disabled. See UIDAI’s guides on what biometric locking is, what happens when it is active and how to unlock it. If you depend on biometric services and lack a registered mobile number, weigh the access impact and ask for assistance before relying on the online route.
For many customers, the bank’s AePS-specific control—if available—is more targeted than locking all Aadhaar biometrics. Locking biometrics is a defensive measure, not proof that an earlier fraud involved a cloned print. It also cannot change the fingerprint itself, and it does not close or unlink the bank account.
Will the bank refund the money?
There is no safe blanket promise that every AePS victim automatically gets a full refund. RBI’s framework for unauthorised electronic banking transactions generally considers whether the loss arose from bank negligence or deficiency, a third-party breach, or the customer’s own negligence, as well as how quickly the customer notified the bank. The applicable rules and account/product terms matter.
Rank #3
- 📱 QR CODE SETUP GUIDE: Scan the QR code on the packaging to access the setup page with Windows drivers and installation instructions. The package includes the main item and a Japanese manual. On the website, tap the 🌐 World icon to switch to English, then scroll down to download the English manual.
- 🚀 INSTANT ACCESS: Login 10x faster than typing passwords - Under 1 second!
- 🛡️ HIGH-LEVEL SECURITY: Match-On-Chip technology = Your fingerprint NEVER leaves the device
- 🎯 WORKS EVERY TIME: 99.999% accuracy with 360° recognition - Touch from any angle!
- 💻 PLUG & PLAY MAGIC: Zero software installation - Works instantly with Windows 10/11 Hello
RBI’s customer-protection guidance says that in a third-party breach where neither bank nor customer is at fault, reporting within three working days of receiving the bank’s communication can result in zero customer liability under the framework; later reporting can mean limited liability. Where a customer’s own negligence caused the loss, the customer may bear the loss until reporting, with subsequent loss borne by the bank. See RBI’s notification. Whether and how this framework applies to a particular AePS dispute depends on the facts and the relevant bank/product rules.
“Biometric authenticated” is not synonymous with “customer authorised.” The investigation should examine the device, operator, transaction type, authentication record, location and compliance with applicable rules. Ask the bank to state its liability category, evidence and reasoning in writing. If a response is unsatisfactory, escalate through the bank’s grievance mechanism and consider the RBI Ombudsman route where eligible. Keep records of when the debit occurred and when each report was made.
Why the burden often falls hardest on the customer
Many AePS users depend on a nearby touchpoint because a branch or ATM is distant, or because they lack reliable internet, a smartphone or easy transport. Those same circumstances can make a fraud harder to detect and contest: an alert may go to an old number; the account holder may see only a generic debit description; the relevant operator may be far away; and the customer may not know which institution controls the outlet. A person with limited time or mobility can struggle to make repeated branch visits and preserve a paper trail.
Meanwhile, the logs needed to establish what happened are largely held by institutions. A fair process should not treat the biometric response as conclusive while requiring the customer to prove a negative. Banks should be able to identify the touchpoint and operator quickly, preserve records, coordinate with the acquiring institution, and explain a decision in accessible language. Security that excludes people who rely on assisted banking is not a complete solution; neither is access without meaningful recourse when the safeguards fail.
What stronger protection should look like
Useful improvements would make the transaction and its accountability visible to the customer, not just to the payment chain:
- Consistent liveness and device-security requirements at relevant touchpoints, with certification and tamper evidence.
- Operator verification, periodic re-checks and monitoring for unusual locations, volumes or patterns.
- Receipts and alerts that identify the transaction type, outlet/operator, terminal or acquiring institution where appropriate, rather than a bare debit label.
- Simple customer controls to disable and re-enable AePS debits, with clear explanations of what the setting blocks.
- Practical limits or additional checks for unusual, repeated or high-risk activity, designed so that legitimate rural cash access remains usable.
- Clear liability rules and timely interim relief when a customer disputes a transaction and the institution controls the evidence needed to investigate it.
- Protection of biometric information appearing in public records, including consideration of redaction or safer document handling.
- Published, anonymised reporting on complaints, resolution and reimbursement rates, time to trace or freeze funds, disputed biometric cases, and operators suspended or removed.
Those measures would let regulators, banks and the public assess whether the January 2026 requirements are working rather than infer success from the existence of a circular.
Questions to ask when a bank investigates
- What was the precise transaction type and authentication modality?
- Which BC/CSP, acquiring bank, terminal and operator processed it? What operator KYC and device records exist?
- Was the operator active and compliant with the applicable RBI requirements on the date of the transaction?
- What location, timestamp, device and authentication response information can be disclosed?
- What fraud-liability category has the bank applied, and what evidence supports its decision?
- When was the complaint received, when were funds traced or placed on hold, and what recovery steps were taken?
- Does the bank offer an AePS debit-disable setting, and exactly which services does it affect?
These are also the questions that matter at system level. Banks and NPCI should be able to publish meaningful complaint and outcome data, while UIDAI should explain how customers can obtain relevant authentication information and how biometric locking relates to the transaction routes used in practice.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

