Government inaction against cyber criminals is driving a steep rise in cybercrime cases across India. As a result, this alarming trend leaves countless individuals, businesses, and institutions vulnerable to online threats such as identity theft, financial fraud, and data breaches.

Meanwhile, the absence of robust legislation and proactive law enforcement only worsens the situation, emboldening cyber criminals to exploit loopholes and target unsuspecting victims. In addition, lack of awareness and education around cyber safety among the public fuels the rising number of incidents. Therefore, India urgently needs comprehensive cybersecurity initiatives and effective government intervention to protect citizens from these escalating threats.

Title: Unauthorized Aadhaar Attempts: A Case Study on What to Do When Your Digital ID is at Risk

In today’s digital world, your Aadhaar number is more than just a card — it acts as a key to your identity and unlocks access to a wide range of services and benefits. It is intricately linked to everything from your bank accounts to your mobile number, so it plays an integral part in your everyday life.

However, this convenience also carries real risk, since the potential for misuse lurks around every corner. So what happens when someone tries to misuse it? Here, we examine a real-life grievance filed with the Unique Identification Authority of India (UIDAI), which highlights the vulnerabilities many people face.

Our goal is not only to explain this pressing threat but also to educate the public about the risks involved. Accordingly, we outline the exact steps you should take to protect yourself from identity theft and unauthorized access, so that your digital identity remains secure and your personal information stays safe from malicious intent. By staying informed and vigilant, you can navigate this complex landscape with confidence.


The Complaint: Multiple Unauthorized Authentication Attempts

On January 2, 2025, Mr. Yogi M. P. Singh filed a formal grievance after noticing alarming activity related to his Aadhaar number. Here’s a breakdown of the case (Grievance No: UIDAI/E/2025/0000070).

  • The Incident: Over two days, someone made seven unauthorized Aadhaar authentication attempts. Specifically, six attempts occurred on January 1, 2025, and one more followed on January 2, 2025.
  • The Evidence: Mr. Singh received a barrage of SMS and email notifications. For instance, these included a specific “Aadhaar Authentication Failed” alert, which flagged an attempt at 9:32 PM on New Year’s Day. In addition, he received multiple One-Time Passwords (OTPs) from both “UIDAI Internal” and “AXIS Bank” that he never requested.
  • Prior History: Troublingly, Mr. Singh noted that the police had already registered a First Information Report (FIR) back in November 2023, regarding the misuse of his PAN and Aadhaar. Therefore, he indicated this is an ongoing issue.

UIDAI promptly registered the grievance, and the CRM Division is now processing it. Deputy Director Sunil Kumar is handling the case.


Understanding the Threat: What Does This Mean?

The series of OTPs and the failed authentication alert reveal a critical situation:

  1. Your Aadhaar Number is Exposed: The fraudulent person clearly has Mr. Singh’s 12-digit Aadhaar number.
  2. They Are Trying to Access Services: They are actively using the number across various platforms. For example, these platforms include UIDAI’s online services and AXIS Bank, where they are trying to authenticate his identity.
  3. The Security System Is Working (For Now): The attempts failed, because the perpetrator cannot access the OTPs that go to Mr. Singh’s registered mobile number and email.

While the immediate transactions failed, this remains a major red flag, because the perpetrator is persistent and may try to exploit other potential vulnerabilities.

The Bigger Picture: A Pattern, Not an Isolated Incident

Mr. Singh’s experience is not unique. Indeed, cybersecurity researchers and RTI activists have documented similar patterns of unauthorized Aadhaar authentication attempts across Uttar Pradesh and other states. Consequently, many victims only discover the fraud after receiving unexpected OTPs or failure alerts, much like Mr. Singh did. In other words, the fraud often becomes visible only through the very safeguards designed to stop it, the OTPs and alerts that flag an attempt.

Moreover, the recurrence of unauthorized attempts against a single individual, despite an active FIR and a formal UIDAI grievance, raises serious questions about enforcement. Specifically, filing a complaint does not automatically stop further attempts; it merely creates a paper trail for later action. As a result, victims cannot rely on institutional complaints alone. Instead, they must combine formal reporting with personal safeguards, such as locking their Aadhaar and monitoring their authentication history, to close the gap between reporting fraud and actually preventing it.

Furthermore, this gap points to a structural weakness in how Aadhaar-linked services verify identity. Because so many institutions, from banks to government departments, rely on the same 12-digit number, a single exposure can ripple across multiple platforms simultaneously. Therefore, protecting your Aadhaar number is not just about avoiding one fraudulent transaction; it is about limiting exposure across an entire ecosystem of interconnected services.


Your Action Plan: 4 Steps to Secure Your Aadhaar Quickly

If you find yourself in a similar situation, do not panic. Take these concrete steps right away to lock down your identity.

1. Lock Your Aadhaar & Biometrics

This is your most powerful first line of defense. Locking your Aadhaar prevents anyone from using it for authentication.

  • How to do it: Use the mAadhaar app or visit the MyAadhaar portal (myaadhaar.uidai.gov.in).
  • What it does: Once locked, no one can use your Aadhaar number for authentication. Not even you can do this until you unlock it. You can unlock it temporarily whenever you need to use it. Locking your biometrics (fingerprint and iris scan) is also a crucial step.

2. Review Your Authentication History

You have the right to know exactly when and where anyone used your Aadhaar number.

  • How to do it: Visit the MyAadhaar portal and go to the “Aadhaar Authentication History” section.
  • What it shows: You can see up to 50 past authentication records. These include the date, time, and the name of the organization that made the ask. This can give you vital clues about who is trying to misuse your data.

3. Formally Report the Incident to UIDAI

Create an official record of the fraudulent activity.

  • Call the Helpline: Dial the toll-free number 1947.
  • Send an Email: Pass all suspicious emails and a description of the incident to help@uidai.gov.in.

4. File a Police Complaint

Unauthorized attempts to use your Aadhaar are a cybercrime.

  • File an FIR: Visit your nearest police station or the cybercrime cell to file a First Information Report (FIR). This is a critical legal step for any future investigation and provides an official record of the crime.

Conclusion: Be Proactive, Not Reactive

Mr. Singh’s case is a stark reminder that we must be vigilant about our digital identity, especially in an era where data breaches are alarmingly common and cyber threats loom large.
As we increasingly rely on digital platforms for communication, banking, and various services, the importance of protecting our personal information has never been more critical.
Regularly checking your Aadhaar authentication history and keeping your mobile number updated are simple but effective habits that everyone should adopt to minimize risks.
Additionally, practicing good password hygiene, enabling two-factor authentication, and being cautious about the information shared online can further safeguard our identities.
By taking these proactive measures, we can create a more secure digital environment for ourselves and reduce the likelihood of falling victim to identity theft or fraud.


The UIDAI website is only for show — this dilapidated platform resolves nothing.


Mismanagement in working of the unique identification authority of India

Home » Fraudulent Aadhaar Authentication Attempts on the Rise

One response to “Fraudulent Aadhaar Authentication Attempts on the Rise”

  1. It is reflecting complete mismanagement in the working of the department of unique identification authority of India. Think about the gravity of situation the email has been provided to make contact with them regarding the problems but it is most unfortunate that this email is not accepting the emails sent by the aggrieved people. Whether it is good governance if there is good governance what is the cause of such third grade services being provided to the citizens in the state.

Facing a similar challenge? Share the details in the box below, and our team of experts will do their best to help.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  1. Right to Information act was introduced by the government of India to promote transparency and accountability in the working of…

Discover more from Yogi-Human Rights Defender

Subscribe now to keep reading and get access to the full archive.

Continue reading