Skip to content
India Impulse
Aadhaar, PAN & IDHow to14 min read · verified

How to lock your Aadhaar biometrics and check for misuse

Locking your fingerprints takes two minutes on myAadhaar and costs nothing. This guide covers the lock, the Virtual ID, reading your own authentication history, and getting money back after an AePS withdrawal.

Short answer

Lock your Aadhaar biometrics free on the myAadhaar portal or the mAadhaar app — fingerprint and iris authentication then fails with error 330 until you temporarily unlock it. Check your authentication history on the UIDAI resident portal for the last six months. If money has gone through AePS, call 1930 and notify your bank the same day.

Most Aadhaar guidance treats the number as something you protect by keeping the card in a drawer. That is the wrong mental model. Aadhaar is a live authentication service: somewhere in the country, at any moment, a device can present your number and a fingerprint image to UIDAI and get back a yes. If the yes comes back, a business correspondent's micro-ATM will pay out cash from your bank account without a card, a PIN, an OTP or any message to you until the balance moves. That is the attack surface, and it is the one this page is about.

The defences are already built and they are free. UIDAI lets you switch your own biometrics off, so that every fingerprint and iris attempt against your number fails at UIDAI's end rather than at the bank's. It lets you generate a sixteen-digit Virtual ID so that you never have to hand the Aadhaar number itself to a shop, a hotel or a gas agency. And it lets you read your own authentication log — six months of it, showing which agency authenticated you, by which method, and whether it worked. Almost nobody uses any of the three.

The second half of this page is the part people arrive looking for at two in the morning: the money has already gone. Here the law that matters is not the Aadhaar Act but the Reserve Bank's customer-protection framework on unauthorised electronic banking transactions, which puts the burden of proving that you were liable on the bank, not on you, and requires the disputed amount to be credited back within ten working days of your notifying the bank. Banks do not volunteer this. You have to invoke it, in writing, and quickly.

None of this is exotic. Every step below happens on a government portal, a mobile app, a helpline or a branch counter, and every timeline quoted comes from a published UIDAI FAQ or a Reserve Bank circular that is linked at the foot of the page. Policing is a state subject, so the FIR half of the recovery route varies by where you live — a cyber crime police station in one city, a district cyber cell in another. The Aadhaar controls and the banking entitlements are national and identical everywhere.

Lock your biometrics first — it is the two-minute step that closes the door

Go to the myAadhaar portal, log in with your Aadhaar number and the OTP sent to your registered mobile, and open the Lock/Unlock Biometrics service. UIDAI also offers the same service through the mAadhaar mobile app, at an enrolment centre and at an Aadhaar Seva Kendra, so a person who cannot manage the portal can have it done across a counter. There is no fee at any of the four channels, and nothing about your Aadhaar number, name, address or photograph changes when you use it.

The registered mobile number is not optional here. UIDAI states plainly that a registered mobile number is essential to avail the service, and that anyone whose number is not registered with Aadhaar has to visit the nearest enrolment centre or mobile update end point first. This is the same wall that blocks every other online Aadhaar service, and it is the reason the mobile update should be treated as the prerequisite for all of this rather than as a chore to do later.

What locking actually does is narrow. UIDAI's own wording is that locked biometrics confirm the Aadhaar holder will not be able to use biometrics — fingerprints, iris or face — for authentication. A device that tries anyway does not get a soft failure it can retry around: the authentication returns error code 330, which is UIDAI telling the requesting agency that the holder has locked this modality. The refusal happens at UIDAI, before the bank, the telecom operator or the business correspondent ever sees a result.

What locking does not do matters just as much. It is a biometric lock, not a lock on the Aadhaar number, so demographic authentication and OTP authentication continue to work normally. Your bank can still run an OTP-based e-KYC, the income tax portal will still send you an Aadhaar OTP, DigiLocker will still fetch documents, and your PAN linkage is untouched. Nothing in your everyday digital life breaks. The only thing that stops working is the one thing you almost never do voluntarily: pressing a finger onto a stranger's scanner.

When you genuinely need a fingerprint — registering a property, an EPFO or pension life certificate, a new SIM at a store, drawing a ration under an Aadhaar-authenticated ePoS — UIDAI gives you two options at the unlock screen. You can unlock temporarily, which opens a short window for the authentication you are about to do and then returns to the locked state, or you can disable the locking system entirely, which switches biometrics back on permanently until you lock them again. Use the temporary option and let it close by itself.

Do the same exercise for every dependent whose Aadhaar you manage — an elderly parent drawing a pension, a spouse who does not use a smartphone, an adult child studying elsewhere. Each of them needs their own registered mobile for the OTP, but the mAadhaar app carries multiple profiles, so one phone in the family can hold and lock several people's biometrics. Pensioners and rural account holders are, on the published fraud pattern, exactly the group whose fingerprints turn up on cloned pads.

Biometric lock and Aadhaar lock are two different switches

UIDAI runs a second, blunter control that is easy to confuse with the first. The Aadhaar Lock/Unlock service locks the Aadhaar number itself, and UIDAI's description is unambiguous: once locked, the holder cannot perform any sort of authentication using the UID, the UID token or the VID, across biometric, demographic and OTP modalities. It is a full stop, not a filter, and it should be reached for in a different situation from the biometric lock.

The mechanics are also different in a way that catches people out. To lock the Aadhaar number you must already hold a current sixteen-digit Virtual ID, and to unlock it again you need the latest VID — not the Aadhaar number. UIDAI provides SMS shortcuts for both: send GVID followed by the last four or eight digits of your Aadhaar to 1947 from the registered mobile to generate a VID, and RVID followed by the same digits to retrieve the one you already have. Generate and note the VID before you lock, not after.

The locking flow on the UIDAI site asks for the UID, your full name, your PIN code and a security code, then confirms with an OTP or a time-based one-time password from the mAadhaar app. Unlocking mirrors it, but takes the VID in place of the Aadhaar number. The TOTP route is useful when you are somewhere the SMS will not arrive, but it depends on having set the app up beforehand — another argument for installing mAadhaar while nothing is wrong.

The practical consequence of a full Aadhaar lock is that a great deal of ordinary administration stops. Bank e-KYC, a new SIM, an income tax OTP, an EPF claim, DigiLocker document pulls and scheme authentication all fail while the lock is on. That is appropriate if you believe your identity is being actively worked on — a SIM issued in your name, repeated authentications you cannot account for, a demographic e-KYC you did not authorise — and disproportionate as a permanent setting.

For most readers the sensible steady state is the narrower one: biometrics locked, Aadhaar number unlocked, VID used in place of the number wherever a service will take it. That combination shuts the fingerprint channel, which is the one being exploited at scale, while leaving the OTP channel open — and the OTP channel is at least one you see, because the message arrives on your phone before anything happens.

Both locks are reversible at any time and neither leaves a mark on your record. Nothing about locking your Aadhaar is reported to a bank, an employer or a credit bureau, and no institution can require you to keep biometrics unlocked as a condition of service — if a fingerprint is genuinely needed, the temporary unlock exists for exactly that moment.

The three controls, and what each one actually blocks
ControlWhat it blocksWhat still worksHow to reverse it
Biometric lockFingerprint, iris and face authentication — attempts return error 330OTP and demographic authentication, e-KYC, PAN linkage, DigiLockerTemporary unlock for one window, or disable the locking system
Aadhaar lockAll authentication using the UID, UID token or VID — biometric, demographic and OTPNothing; the number is dormant for authentication until unlockedUnlock using the latest 16-digit VID plus OTP or TOTP
Virtual IDNothing — it substitutes for the Aadhaar number so the number is never disclosedEverything the Aadhaar number does, using the VID insteadGenerate a new VID; only one VID is valid at a time

Compiled from UIDAI's Biometric Lock/Unlock, Aadhaar Lock/Unlock and Virtual ID FAQ sets, cited below.

Stop handing over the number itself: Virtual ID and masked Aadhaar

The Virtual ID is UIDAI's answer to the fact that you are asked for your Aadhaar number a dozen times a year by entities with no business retaining it. UIDAI describes it as a temporary, revocable sixteen-digit random number mapped to your Aadhaar. You give the VID, the agency authenticates against it exactly as it would against the Aadhaar number, and the agency ends the transaction without ever holding your actual twelve digits.

Only the Aadhaar number holder can generate a VID — an agency cannot mint one for you, and it cannot work backwards from a VID to your Aadhaar number. Generate it through the VID generator on the myAadhaar portal, through the mAadhaar app, during an e-Aadhaar download, or by SMS with GVID and the last four or eight digits of your Aadhaar to 1947. At any given moment only one VID is valid for an Aadhaar number, so generating a new one silently retires the old one.

That single-valid-VID rule is the thing to plan around. If you gave a VID to a gas agency last month and generate a fresh one today, the agency's stored value is dead. For repeat relationships, either let the existing VID stand or expect to supply the new one. For one-off interactions — a hotel check-in, a courier, a coaching centre, a private employer's onboarding file — regenerating afterwards is a feature, not a nuisance: it renders the copy in their file useless.

Where a physical or scanned copy is unavoidable, use masked Aadhaar rather than the full e-Aadhaar. The masked version, downloadable from myAadhaar, shows only the last four digits of the number while carrying the rest of the identity detail, and it is accepted for most identification purposes. UIDAI also publishes Aadhaar paperless offline e-KYC, a signed, shareable XML that lets a verifier confirm your details offline without any authentication call and without seeing the number.

UIDAI's own position is that just by knowing your Aadhaar number, no one can harm you, because authentication requires one of the prescribed modes under the Aadhaar Act. Read carefully, that is a statement about the design, not about the ecosystem. It is true that the number alone opens nothing. It is also true that the number plus a biometric — and biometrics have been lifted from registered property deeds and from casually collected fingerprint records — opens a bank account at a micro-ATM. Both things are true at once, which is why the lock and the VID exist.

The UIDAI homepage also carries a bank seeding status service, and it is worth five minutes while you are there. It tells you which bank account your Aadhaar is currently mapped to for Aadhaar-based payments — often a Jan Dhan or cooperative account opened years ago and forgotten. An account you have stopped watching is precisely the account an AePS withdrawal will hit without anyone noticing for months.

Read your own authentication history — the forensic half

UIDAI hosts an Aadhaar authentication history service that gives you the transaction log for every authentication performed against your number. It is reached from the UIDAI resident portal at resident.uidai.gov.in/aadhaar-auth-history and from the mAadhaar app. You authenticate with your Aadhaar number or a VID plus the security code, and confirm with an OTP to the registered mobile — which, again, is why the registered mobile is the master key to all of this.

The window is six months and the display is capped: UIDAI states that the service provides detailed authentication transaction logs for the last six months, with a maximum of fifty records viewable at one time. For a lightly used Aadhaar six months is plenty. For a heavily used one — a scheme beneficiary authenticating at a fair price shop twice a month, a worker on an attendance system — you will need to page through in date ranges rather than expecting a single list.

Each row carries more than a timestamp. UIDAI's log shows the authentication method used, the date and time, the UIDAI response code and any error code, the name of the Authentication User Agency and its transaction ID, and whether the attempt succeeded or failed. The AUA name is the field that does the work: it tells you which regulated entity asked the question, and it is the thread you pull if you did not ask it to.

Read the log against your own memory of the period. A demographic or OTP authentication you can place — a bank, an insurer, a telecom operator you dealt with — is fine. A biometric authentication on a day you touched no scanner is not. Failed attempts are as informative as successful ones: a cluster of failures against a locked or mismatched biometric is somebody trying, and it is the earliest warning you will get that your number is circulating with a fingerprint attached.

UIDAI's instruction when you find an entry you did not perform is to contact the respective Authentication User Agency for further details, using the AUA name and transaction ID from the log. That is the correct first move and it is often enough — the AUA has to be able to say what the authentication was for. Where the AUA will not engage, or where the pattern spans several agencies, escalate to UIDAI on 1947, by email to [email protected], or by filing a complaint through the myAadhaar complaint form.

Make this a calendar habit rather than a crisis response. Because the log only reaches back six months, an authentication from last August is simply gone by February, along with the AUA name you would have needed. Checking twice a year — and immediately after you have handed a copy of your Aadhaar to anyone you did not choose — costs about four minutes and is the only visibility into your own identity that anyone gives you.

What AePS is, and why a fingerprint is enough to empty an account

The Aadhaar Enabled Payment System lets a person withdraw cash, check a balance or move money at a small local touchpoint operated by a business correspondent, using an Aadhaar number, the name of the bank and a fingerprint on a micro-ATM. It was built for financial inclusion and it works: it is how a very large number of rural account holders reach their money without a branch or a card. It also means the fingerprint is doing the job that a card and a PIN do everywhere else.

That design has one consequence worth stating plainly. A withdrawal at an AePS touchpoint does not require your card, your PIN, your phone or an OTP. If a fingerprint good enough to satisfy UIDAI's matcher is presented alongside your Aadhaar number, the transaction completes and the first you know of it is the balance. This is the exact gap that biometric locking closes, because a locked biometric fails at UIDAI with error 330 before the bank is ever asked to pay.

The Reserve Bank has moved on the operator side of the same problem. Its circular Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators, RBI/2025-26/63 dated 27 June 2025, requires acquiring banks to run customer due diligence on every AePS touchpoint operator before onboarding, following the same procedure as customer due diligence for individuals under the RBI KYC framework, and to keep that KYC current. The directions took effect from 1 January 2026.

The circular also closes the dormant-operator route. Where a touchpoint operator has been inactive for a continuous period of three months, the bank must complete KYC afresh before transactions can resume — which attacks the pattern of an operator ID lying idle and then being used in a burst. Acquiring banks must monitor operator activity through transaction monitoring systems with parameters set on the operator's business risk profile, taking in location, transaction volume and velocity, and must ensure at system level that APIs are used only for enabling AePS operations.

The Reserve Bank consolidated its know-your-customer requirements into a fresh set of KYC Directions issued in November 2025 for commercial banks, small finance banks, payments banks, regional rural banks, urban and rural co-operative banks and non-banking financial companies. That matters here because the AePS due-diligence obligation is expressed by reference to the KYC framework, so the standard an acquiring bank must apply to a touchpoint operator is the ordinary individual customer standard, not something lighter.

None of that is a defence you can deploy yourself, and it does not undo a withdrawal that has already happened. It does two things for a victim: it establishes that the operator through whom the money left is supposed to be a KYC-verified, monitored, identifiable person, and it gives you something concrete to put in a written representation to the bank. Ask which touchpoint operator ID processed the transaction, at what location, and when that operator was last KYC-verified.

One more national point with local texture. Policing in India is a state subject, so where you take a criminal complaint depends on where you live: a dedicated cyber crime police station in some cities, a district cyber cell elsewhere, and an online complaint accepted centrally everywhere. The Aadhaar controls and the banking entitlements described on this page do not vary by state at all — the myAadhaar services, the UIDAI helpline and the Reserve Bank's customer-protection rules are identical in every state and union territory.

If money has already gone: what to do on day one

Notify the bank before you do anything else, and do it through a channel that creates a record. The Reserve Bank requires banks to give customers 24x7 access to report an unauthorised transaction through multiple channels — at a minimum the website, phone banking, SMS, email, IVR, a dedicated toll-free helpline and reporting to the home branch. Use whichever you can reach fastest at the hour it happens; the clock that decides your liability starts at notification, not at the branch opening.

Then get the acknowledgement. The Reserve Bank requires banks to send an immediate acknowledgement of the complaint carrying a complaint reference number, and that number is the single most valuable thing you will hold. It fixes the date and time on which you reported, which is what the entire liability framework turns on. If the helpline agent does not give you one, say you are reporting an unauthorised electronic banking transaction and ask for the reference number explicitly.

Report the fraud in parallel to the police. Financial cyber fraud is reported on the Government of India's National Cyber Crime Reporting Portal at cybercrime.gov.in and on the national cyber crime helpline, 1930, which operates around the clock. Reporting early matters for a practical reason as well as a legal one: the faster the money is traced through the receiving account, the better the odds that some of it is still sitting there to be held.

Lock your biometrics now if you had not already, and lock them before you start arguing with anyone. An AePS withdrawal that succeeded once will be attempted again, and every hour the biometric channel stays open is another opportunity. Locking takes two minutes on mAadhaar and does not interfere with any of the OTP-based steps you are about to take with the bank.

Pull the authentication history the same day and save it. It is the only record you can obtain yourself that shows the biometric authentication behind the withdrawal, with the AUA name, the transaction ID and the response code. Take screenshots, note the AUA transaction IDs, and keep them with your bank complaint reference number, the SMS alerts and the account statement extract. Because the log only runs six months, evidence that is not captured is evidence that expires.

Put the complaint in writing to the branch as well, even after a phone report, and keep a stamped copy or an email in your sent folder. The written version should say what was debited and when, that you did not authorise it, that you are reporting it as an unauthorised electronic banking transaction, when and how you first reported it, and the complaint reference number you were given. Ask in the same letter for the touchpoint operator ID and location for each disputed transaction.

File the police complaint locally as well as online. Where a state police force offers an online FIR or complaint service for cyber offences, use it; where it does not, the cyber cell or the local station is the route, and the acknowledgement is what banks and insurers will ask to see later. Do not wait for the police process to finish before pressing the bank — the two run in parallel and the banking timeline is much shorter.

Getting the money back: RBI's limited liability framework

The instrument that governs this is the Reserve Bank's circular RBI/2017-18/15, DBR.No.Leg.BC.78/09.07.005/2017-18, dated 6 July 2017, on customer protection and limiting the liability of customers in unauthorised electronic banking transactions. It replaced a much older and weaker position, and its central move is to shift the default: a customer is not presumed to have been careless, and the bank has to make its case.

You bear zero liability where the unauthorised transaction arises from contributory fraud, negligence or deficiency on the part of the bank — whether or not you reported it — and also where it arises from a third-party breach in which neither the bank nor you are at fault, provided you notify the bank within three working days of receiving the communication about the transaction. An AePS withdrawal using a fingerprint you never gave is squarely a third-party breach, which is why the three-working-day report is the pivot of the whole exercise.

Delay narrows the protection rather than destroying it. Where the third-party breach is reported four to seven working days after the communication, your liability is capped at an amount that depends on the type of account, running from ₹5,000 on a basic savings account up to ₹25,000 on higher-value accounts and credit cards, per the schedule in the circular. Beyond seven working days, the outcome is governed by the bank's own board-approved policy, which is a materially worse place to be standing.

The reversal obligation is specific and it is not conditional on the investigation finishing. On being notified, the bank must credit — shadow reverse — the amount involved in the unauthorised electronic transaction to your account within ten working days, value-dated to the date of the transaction, and it must do so without waiting for the settlement of any insurance claim. If a branch tells you that nothing can move until the investigation concludes, that is not what the circular says.

The burden of proof is the provision to quote when the conversation turns adversarial. The circular states that the burden of proving customer liability in the case of unauthorised electronic banking transactions lies on the bank. In an AePS dispute the practical form this takes is that the bank has to show you were negligent — that you shared your biometric or your credentials — rather than you having to prove a negative about a fingerprint you never gave to anyone.

Expect the contributory-negligence argument anyway, usually in the form of a claim that a successful biometric match is proof that you were present. Answer it in writing: a match proves that a biometric template satisfying UIDAI's matcher was presented, not that you presented it, and the operator through whom it was presented is a KYC-verified, monitored person the acquiring bank is required to be able to identify. Ask for the operator ID, the terminal location and the KYC status of that operator.

Keep escalating inside the bank in a straight line: branch, then the bank's nodal or principal nodal officer for grievance redressal, each in writing, each referencing your original complaint reference number and the date you first reported. Almost every successful recovery is a paper trail with dates on it, and almost every failed one is a series of phone calls nobody logged.

Customer liability by how quickly you report — unauthorised electronic banking transactions
When you notify the bankYour liabilityWhat the bank must do
Bank's own fraud, negligence or deficiencyZero, whether or not you reported itFull reversal
Third-party breach, reported within 3 working daysZeroCredit the amount within 10 working days of notification, value-dated
Third-party breach, reported 4 to 7 working days afterCapped by account type — ₹5,000 on a basic savings account up to ₹25,000 on higher-value accountsCredit the balance within 10 working days of notification
Reported beyond 7 working daysDetermined by the bank's board-approved policyPolicy must be published and disclosed to customers

Reserve Bank of India, RBI/2017-18/15 DBR.No.Leg.BC.78/09.07.005/2017-18, 6 July 2017. Amounts are those in the circular's schedule and are subject to revision; confirm with your bank.

When the bank stalls: the ombudsman, UIDAI and the fallbacks

The Reserve Bank runs an ombudsman scheme for exactly this deadlock, and it has a gate you have to pass through first. You must have complained to the regulated entity itself, and you may approach the ombudsman if no reply arrives within thirty days — or within the timeline specified by the Reserve Bank, NPCI or the card network where one applies, whichever is higher — or if you received a reply and are dissatisfied with it. Complaining before that point gets the complaint returned.

Once the gate opens there is a deadline on the other side of it. A complaint to the ombudsman must be filed within ninety days from the date on which that timeline expired, and the original complaint to the bank must itself have been within the period allowed by the Limitation Act 1963. Ninety days sounds generous and disappears quickly when a bank is stringing out an investigation, so diarise the date rather than waiting to see what happens.

Filing is free and can be done three ways: online through the Reserve Bank's complaint management system at cms.rbi.org.in, by email to [email protected], or on paper to the Centralised Receipt and Processing Centre, Reserve Bank of India, Central Vista, Sector 17, Chandigarh 160017. The scheme's contact centre on the toll-free number 14448 runs an IVRS around the clock, with staff available across English, Hindi and ten regional languages during working hours; it will help you file but does not take the complaint itself.

Attach the pack you have been building since day one. The ombudsman is assessing a deficiency in service, so what persuades is the sequence: the transaction alerts, the date and time you first reported, the complaint reference number the bank issued, the written complaint, the bank's reply or its silence, and the authentication history extract showing the biometric authentication with its AUA name and transaction ID. A complaint with dates and reference numbers is a different document from a complaint with a narrative.

Run the Aadhaar side in parallel with UIDAI, because the bank cannot investigate what happened inside the authentication system. UIDAI takes grievances on the toll-free number 1947, by email at [email protected], and through the complaint form on the myAadhaar portal, and maintains regional offices across the country — Bengaluru, Chandigarh, Delhi, Guwahati, Hyderabad, Lucknow, Mumbai and Ranchi among them — for matters that need a physical address. Quote the AUA name, the AUA transaction ID and the UIDAI response codes from your history extract.

The statutory backdrop is the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 as amended by the Aadhaar and Other Laws (Amendment) Act 2019, sitting above a live body of regulations — the Aadhaar (Authentication and Offline Verification) Regulations, amended most recently in December 2025, and the Aadhaar (Sharing of Information) Regulations, amended in November 2025. Those instruments are what govern how an AUA may authenticate you and what it may do with the result, and they are the frame for any complaint about an agency's conduct.

Where the ombudsman route runs out or the loss is large, the remaining civil options are a consumer commission complaint for deficiency in service against the bank and, in a serious case, a writ petition. Both are slower and neither is a substitute for the bank timeline, which is why the first day matters so much. In practice, the cases that end well are the ones where the customer notified inside three working days, held the reference number, and never let the dispute drift out of writing.

Key takeaways

  • Locking your Aadhaar biometrics is free, takes two minutes on myAadhaar or mAadhaar, and makes every fingerprint, iris and face authentication against your number fail with error 330 until you temporarily unlock it.
  • Biometric lock is not the same as Aadhaar lock: the first blocks only biometrics and leaves OTP and demographic authentication working, while the second stops all authentication and needs a current 16-digit Virtual ID to reverse.
  • Your authentication history on the UIDAI resident portal shows six months of activity, fifty records at a time, with the AUA name, method, response codes and success or failure — check it twice a year, because older entries simply disappear.
  • If money has gone through AePS, notify the bank within three working days and get the complaint reference number: under RBI's 2017 circular that keeps your liability at zero and obliges the bank to credit the amount back within ten working days.
  • The burden of proving you were liable sits on the bank, not on you, and the Reserve Bank's June 2025 directions require every AePS touchpoint operator to be KYC-verified and monitored — ask for the operator ID behind the disputed withdrawal.

Who to contact

At a glance

Cost of locking biometrics
FreeLock, temporary unlock and disabling the lock are all free on myAadhaar and mAadhaar
Error code when locked
330What a device returns when it tries fingerprint, iris or face against a locked Aadhaar
Authentication history
Last 6 months, 50 records at a timeShows the AUA name, method, date and time, and the response and error codes
Virtual ID
16 digits, revocableOnly one VID is valid for an Aadhaar number at any time
SMS shortcuts
GVID and RVID to 1947Generate or retrieve a VID from the registered mobile number
Report an unauthorised debit
Within 3 working daysRBI's zero-liability window for a third-party breach; delay narrows your protection
Bank must credit back
Within 10 working daysShadow reversal, value-dated to the transaction date, per RBI's 2017 circular
Helplines
1947 and 1930UIDAI for Aadhaar, the national cyber crime helpline for money already lost
Questions people also ask

How to lock your Aadhaar biometrics and check for misuse — FAQ

How do I lock my Aadhaar biometrics?

Log in to the myAadhaar portal with your Aadhaar number and the OTP to your registered mobile, open Lock/Unlock Biometrics and confirm. The mAadhaar app, an enrolment centre and an Aadhaar Seva Kendra do the same job. It is free. Once locked, fingerprint, iris and face authentication against your number returns error 330.

Does locking my Aadhaar biometrics stop my bank KYC or income tax OTP working?

No. A biometric lock blocks only fingerprint, iris and face authentication. Demographic and OTP-based authentication continue to work, so bank e-KYC, income tax OTPs, DigiLocker, PAN linkage and scheme authentication are unaffected. Only the full Aadhaar Lock service blocks every modality, including OTP, and that one needs a Virtual ID to reverse.

How do I check if my Aadhaar has been misused?

Use the Aadhaar authentication history service on the UIDAI resident portal or the mAadhaar app. Log in with your Aadhaar number or VID and an OTP. It shows the last six months, up to fifty records at a time, with the authentication method, date and time, the Authentication User Agency name and transaction ID, and the response and error codes.

Money was withdrawn from my account through AePS without my fingerprint. What do I do first?

Notify your bank immediately through any of its 24x7 reporting channels and obtain the complaint reference number, because your liability depends on the date you reported. Then report on 1930 and cybercrime.gov.in, lock your biometrics, and download your Aadhaar authentication history the same day before the entries age out of the six-month window.

How long does the bank have to refund an unauthorised transaction?

Under RBI's 2017 circular the bank must credit the disputed amount to your account within ten working days of your notifying it, value-dated to the transaction date, without waiting for any insurance settlement. Liability is zero if you reported a third-party breach within three working days, and the burden of proving you were liable rests on the bank.

What is a Virtual ID and should I use it instead of my Aadhaar number?

A VID is a temporary, revocable sixteen-digit number mapped to your Aadhaar that lets an agency authenticate you without ever seeing your Aadhaar number. Generate it on myAadhaar, in mAadhaar, during an e-Aadhaar download, or by texting GVID and the last four digits of your Aadhaar to 1947. Only one VID is valid at a time.

The bank has refused my claim. Can I go to the RBI Ombudsman?

Yes, once you have complained to the bank and either thirty days have passed with no reply — or the longer timeline set by RBI, NPCI or the card network where one applies — or you are dissatisfied with the reply. File within ninety days of that point, free, at cms.rbi.org.in, by email to [email protected], or on paper to the Chandigarh processing centre.

Can I lock the biometrics of an elderly parent who does not use a smartphone?

Yes, but their Aadhaar must have a working registered mobile number, because the service is OTP-gated. The mAadhaar app holds multiple profiles, so one family phone can manage several people. If the registered mobile is wrong or lost, the number has to be updated in person at an enrolment centre or Aadhaar Seva Kendra first — there is no online workaround.

Read next

Sources & provenance

Facts verified

  1. 1.UIDAI — Aadhaar services OfficialUnique Identification Authority of IndiaUsed for: The list of resident services — Lock/Unlock Biometrics, VID generator described as a temporary revocable 16-digit random number, authentication history, bank seeding status, paperless offline e-KYC — and the 1947 helpline and [email protected] address
  2. 2.About your Aadhaar OfficialUIDAIUsed for: UIDAI's statement that just by knowing your Aadhaar number no one can harm you because authentication requires a prescribed mode, and that Aadhaar is proof of identity but confers no right of citizenship or domicile
  3. 3.Biometric Lock/Unlock — FAQs OfficialUIDAIUsed for: That locked biometrics mean fingerprints, iris and face cannot be used for authentication, that attempts return error code 330, and that a registered mobile number is essential to use the service
  4. 4.How to unlock locked biometrics OfficialUIDAIUsed for: The four channels — UIDAI website, enrolment centre, Aadhaar Seva Kendra and the mAadhaar app — and the choice between a temporary unlock and disabling the locking system
  5. 5.Aadhaar Lock/Unlock — FAQs OfficialUIDAIUsed for: That a locked Aadhaar blocks all authentication using the UID, UID token and VID across biometric, demographic and OTP modalities, that a 16-digit VID is needed to lock and the latest VID to unlock, and the UID, name, PIN code and OTP or TOTP entry flow
  6. 6.Virtual ID (VID) — FAQs OfficialUIDAIUsed for: The 16-digit VID format and the SMS shortcuts — GVID and the last four or eight digits of the Aadhaar number to 1947 to generate, RVID to retrieve — from the registered mobile
  7. 7.How does an Aadhaar number holder obtain VID? OfficialUIDAIUsed for: That a VID can be generated only by the Aadhaar number holder, through myAadhaar, mAadhaar, e-Aadhaar download or SMS, and that only one VID is valid for an Aadhaar number at any given time
  8. 8.Authentication — FAQs OfficialUIDAIUsed for: That the authentication history service gives logs for the last six months with a maximum of 50 records viewable at a time, the fields shown — method, date and time, response and error codes, AUA name and transaction ID, success or failure — and the instruction to contact the relevant AUA about an authentication you did not perform
  9. 9.Procedure for checking Aadhaar authentication history OfficialUIDAIUsed for: The access points — the UIDAI resident portal authentication history page and the mAadhaar app — and that the Aadhaar number or VID, a security code and a registered mobile for OTP are required
  10. 10.UIDAI — contact and support OfficialUIDAIUsed for: The 1947 toll-free number, the [email protected] address, the myAadhaar complaint filing and status routes, the New Delhi head office address and the list of regional offices
  11. 11.UIDAI legal framework LawUIDAIUsed for: The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 and the Aadhaar and Other Laws (Amendment) Act 2019 as the governing statutes
  12. 12.Aadhaar regulations LawUIDAIUsed for: The Aadhaar (Authentication and Offline Verification) Amendment Regulations of December 2025 and the Aadhaar (Sharing of Information) First Amendment Regulations of November 2025 as the live instruments governing how an agency may authenticate and share information
  13. 13.Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions RegulatorReserve Bank of IndiaUsed for: Circular RBI/2017-18/15 of 6 July 2017: zero liability for bank negligence and for a third-party breach reported within three working days, the capped liability tier for reports made four to seven working days later, the shadow reversal within ten working days value-dated to the transaction, the burden of proof on the bank, the 24x7 multi-channel reporting requirement and the immediate acknowledgement with a complaint reference number
  14. 14.Aadhaar Enabled Payment System — Due Diligence of AePS Touchpoint Operators RegulatorReserve Bank of IndiaUsed for: Circular RBI/2025-26/63 of 27 June 2025, effective 1 January 2026: customer due diligence of every AePS touchpoint operator on the individual KYC standard, periodic KYC updates, fresh KYC after three months of inactivity, transaction monitoring on location, volume and velocity, and system controls restricting APIs to AePS operations
  15. 15.Reserve Bank — Integrated Ombudsman Scheme FAQs RegulatorReserve Bank of IndiaUsed for: The requirement to complain to the regulated entity first, the 30-day wait or the longer timeline set by RBI, NPCI or the card network, the 90-day filing window, the cms.rbi.org.in and [email protected] filing routes, the Chandigarh Centralised Receipt and Processing Centre address and the 14448 contact centre
  16. 16.RBI Master Directions RegulatorReserve Bank of IndiaUsed for: That the Reserve Bank issued consolidated KYC Directions in November 2025 for commercial banks, small finance banks, payments banks, regional rural banks, co-operative banks and NBFCs — the framework the AePS touchpoint operator due-diligence obligation is expressed by reference to
  17. 17.National Cyber Crime Reporting Portal OfficialMinistry of Home AffairsUsed for: Confirms the live address of the Government of India's cyber crime reporting portal, named here as the channel for reporting an unauthorised AePS withdrawal alongside the 1930 helpline

Not a source — AI-assisted analysis on this page

  • AI-assisted analysis — biometric lock as the default settingThe recommendation that biometric locking should be the default state for most people, the cost-benefit reasoning about how rarely a typical household presents a fingerprint, and the carve-out for beneficiaries who authenticate at Aadhaar-enabled touchpoints several times a month are our conclusions. UIDAI publishes the lock service and the error code but takes no position on who should use it or how often.
  • AI-assisted analysis — copy discipline and reading the AUA fieldThe rule of treating every surrendered Aadhaar copy as permanently compromised, the practice of regenerating a VID after a one-off interaction to invalidate stored copies, and the interpretation that an unfamiliar Authentication User Agency in the history log usually reflects an aggregator or correspondent rather than fraud are our reasoning. UIDAI documents the VID, masked Aadhaar, offline e-KYC and the log fields, but does not give this guidance or explain the aggregator layer.
  • AI-assisted analysis — sequencing the bank report ahead of the police complaintThe conclusion that notifying the bank and obtaining a complaint reference number should precede the police complaint, because the Reserve Bank's zero-liability window expires in three working days while the criminal process carries no equivalent deadline, is our reasoning across the RBI circular and the cyber crime reporting route. The RBI circular sets out the liability tiers and the burden of proof but does not sequence them against a police complaint.

The lock and unlock mechanics, error code 330, the Virtual ID rules, the GVID and RVID shortcuts and the six-month, fifty-record authentication history come from the UIDAI FAQ sets and the UIDAI site cited above. The liability tiers, the ten-working-day reversal, the burden of proof and the 24x7 reporting duty come from RBI circular RBI/2017-18/15; the touchpoint operator due-diligence requirements from RBI/2025-26/63; the ombudsman timelines and addresses from the RB-IOS FAQs. Three passages are marked as AI-assisted analysis: the case for locking by default, the copy-discipline and AUA-reading guidance, and the ordering of the bank report ahead of the police complaint. Liability caps, fees, portal addresses and the ombudsman's filing windows change — confirm with UIDAI on 1947 and with your bank before relying on any figure here.

Facts on this page are taken from the sources listed above — Government of India ministries and departments, statutory authorities, regulators such as the RBI, SEBI, IRDAI and TRAI, state governments and official statistical releases. Comparisons, judgments and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Fees, slabs, limits and processing times change, often at the start of a financial year on 1 April; figures are current as of the review date shown and should be confirmed with the responsible department before you rely on them. A great deal of Indian administration is state administration — where a rule differs by state, this site says so.