A cash withdrawal appears in a bank account, but the account holder never visited an ATM. The transaction record points instead to a biometric payment route.
That detail can be confusing, especially when the person still has their card and phone. Understanding the route is the first step toward responding.

Overview
A legitimate system can be abused
AePS, the Aadhaar Enabled Payment System, allows certain banking transactions through Aadhaar-based authentication at authorized points in India.
It can help customers access money without a card. The AePS biometric fraud concern is unauthorized use of that system, not the system’s existence.
A person may discover an unexpected cash withdrawal or balance inquiry. The bank record may identify an AePS channel rather than a familiar ATM.
OnlineThreatAlerts describes reported AePS misuse and advises customers to check account activity. Its article is a lead, not proof of every proposed method.
What we can establish and what remains case-specific
Indian authorities provide ways to lock Aadhaar biometrics, and banking channels allow disputes. Those controls are relevant when an unauthorized transaction appears.
A transaction label alone does not prove how authentication was bypassed. Possible explanations require a bank and network investigation, including transaction logs.
Do not assume someone copied your fingerprint from a public photograph. Do not assume the bank will automatically refund every transaction within a fixed period.
The images here are fictional reconstructions of a banking view and biometric settings. They are not screenshots from UIDAI or a real victim’s account.
Details to preserve immediately
- The debit amount, date, time, transaction reference, and channel shown by the bank.
- Any SMS or app notification tied to the withdrawal.
- The complaint number and exact time you notified your bank.
- Whether your biometrics were locked before or after the transaction.
- Any visit to a banking correspondent or service point that you actually remember.
- Copies of official responses, without sharing full Aadhaar details publicly.
These records help separate a genuine dispute from a rumor about how the debit happened.
How AePS Transactions Are Supposed to Work
The account and authentication are linked
AePS is part of India’s digital financial infrastructure. A customer uses an Aadhaar-linked bank account and authentication at a participating service point.
Available services can include cash withdrawal and balance inquiry. The exact flow depends on the bank, agent, device, and current network rules.
A merchant-style receipt or transaction ID can help identify the agent and route. Ask your bank for that information when disputing a debit.
The presence of an AePS entry does not mean an ATM card was used. That difference matters when explaining the complaint.
Biometric locking is a protective control
UIDAI explains how Aadhaar holders can lock and unlock biometric authentication through its official service.
Locking can reduce the chance of further biometric authentication using those modalities. It is a protection to consider, not proof the first transaction was fraudulent.
It may also interrupt legitimate services that rely on your biometric authentication. Understand how to unlock it when you genuinely need those services.
Use the official UIDAI website or app directly. A link in an unsolicited text can lead to a fake Aadhaar page.
How the AePS Biometric Fraud Works
Step 1: An unauthorized party obtains usable information or access
A fraudulent transaction requires more than a stranger knowing that AePS exists. Investigators must establish what identity data, authentication route, and service point were involved.
Cases can differ. Some may involve compromised personal information, misuse at an agent location, collusion, or weaknesses in a particular process.
Do not assign one explanation to every unexplained debit. A bank’s logs and the transaction trail are more reliable than social-media speculation.
The practical concern is unauthorized use of your account. You do not need to prove the complete criminal method before reporting it.
Step 2: A transaction is submitted through an AePS channel
The request may be presented at a participating banking correspondent or service point. The system records a transaction against an Aadhaar-linked account.
The bank statement may show a channel label rather than a merchant name you recognize. That can make the debit seem mysterious at first.
Ask your bank for the transaction reference, acquiring institution, agent identifier where available, and the basis for authentication.
Those details may not be visible in a standard consumer app. A formal dispute creates a route for the bank to investigate.
Step 3: The account is debited
If the request is accepted, the account balance can fall even while the customer’s physical card remains untouched.
A debit notification may arrive promptly, arrive late, or be missed. Regular review of bank activity is therefore useful.
Do not rely on a message alone. Confirm the transaction in your bank’s established app, website, statement, or branch.
Multiple small debits can matter as much as one large withdrawal. Save each reference rather than grouping them into one vague complaint.

Step 4: Confusion delays reporting
People often first check whether an ATM card was stolen. An AePS entry may require a different question about the account and authentication channel.
Someone may tell you the debit is impossible because you still possess your phone. That conclusion overlooks how a biometric transaction differs from card payments.
Report the debit as unauthorized as soon as you discover it. Ask the bank to record the complaint, investigate the channel, and explain next steps.
Avoid anyone who asks you to pay a fee to unlock a refund. Use official bank, UIDAI, and government channels.
Step 5: The investigation determines what happened
The bank and relevant payment participants may need to examine authentication records, agent details, settlement data, and any applicable dispute rules.
That process can take time. Keep complaint numbers, dates, and written responses so you can escalate if the outcome is unclear.
No article can promise a refund in every case. Liability and remedies depend on the facts, timely reporting, and the rules applicable to your account.
Ask for a written explanation if a claim is rejected. You can then use the bank’s escalation route or an appropriate regulator channel.
What To Check Before Calling It AePS Fraud
Confirm the transaction classification
A bank statement may abbreviate payment channels. Contact the bank if you cannot tell whether a debit is AePS, a card withdrawal, or another transfer.
Check whether another authorized account user completed the withdrawal. Avoid accusing a specific agent or family member without evidence.
Ask the bank to distinguish an attempted transaction from a completed debit. A failed authentication notice does not always mean money left.
If a debit was reversed, save both entries. A temporary balance difference can still deserve investigation if it recurs.
Protect identity information while investigating
Do not post a full Aadhaar number, biometric image, bank statement, or phone number in a public forum to seek help.
When a bank requests documents, use its official app, branch, or verified secure channel. Ask why each detail is needed.
Unexpected callers may exploit the incident by claiming to be investigators. Never share an OTP or install a remote-control app at their request.
Use official UIDAI guidance for biometric-lock questions, and ask the bank how that control affects the services you normally use.
How to Build a Useful Bank Complaint
Describe the debit, not a guessed technical attack
Start with what you can verify: an account debit, the channel shown, when you noticed it, and why you did not authorize it.
Avoid leading with a claim that someone cloned a fingerprint unless you have evidence. An unsupported theory can distract from the transaction record.
State whether you have visited a banking correspondent recently and whether anyone else has authorized access to the account.
Ask the bank to identify the transaction’s acquiring side and the authentication result. The bank can explain what it is permitted to disclose.
Make the timeline easy to follow
Record the first alert, the time the debit appeared, the time you called or visited the bank, and every later bank response.
If there are several debits, give each its own row or note. Include the amount and reference rather than a total alone.
Keep copies of written complaints and screen captures. If you report in person, request an acknowledgment showing the date.
A clear timeline can help determine whether the bank met its investigation process and whether subsequent activity happened after notice.
Ask for concrete next steps
Ask whether the bank can restrict further AePS transactions, what happens to other account services, and how to restore access later.
Ask when you should expect an update and how to escalate if no answer arrives. Keep the answer with your complaint record.
If a bank representative says the debit cannot be disputed, ask for that position in writing with the applicable rule.
Do not send additional personal documents to an unofficial messaging account merely because someone offers to speed up the case.
Why One Protection Step Is Not Enough
A biometric lock addresses a particular route
UIDAI’s lock can affect Aadhaar biometric authentication. It does not replace bank fraud reporting and does not secure unrelated card, UPI, or online banking activity.
Check those channels separately if you also see suspicious transactions there. A single incident may involve more than one type of account misuse.
Do not assume a lock blocks every possible payment product or identity check. Read UIDAI’s current instructions for the exact service involved.
If you need to unlock biometrics for legitimate use, plan that process through official channels. Never ask an unsolicited caller to perform it for you.
Bank notifications help only when reviewed
Keep your registered mobile number and email current. An alert sent to an old address is less useful during a fast-moving dispute.
Review statements even if notifications seem quiet. A transaction may be missed because of network delay, message filtering, or a changed contact detail.
If you help an older relative, agree on a safe way to review alerts without taking over their account credentials.
Explain that a caller offering a refund may be exploiting a real debit. The relative should contact the bank using a known branch or published number.
Scam claims may spread faster than verified findings
Viral posts often describe a single dramatic method as if it explains every AePS dispute. Those posts rarely include bank authentication records.
Readers deserve a narrower conclusion: unauthorized AePS debits require prompt reporting, and each mechanism must be established on its own evidence.
The same caution applies to blanket refund promises. Rules can vary by account, transaction, timing, and the bank’s findings.
Use the complaint outcome to learn what actually happened. If the response leaves material questions unanswered, request clarification and escalate through official procedures.
Compare any advice you receive with your bank’s published grievance process. A neighbor’s earlier case may have involved different facts and a different rule.
Finally, avoid posting a screenshot that includes the full transaction reference and personal identifiers. Send it privately to the bank or investigators instead.
A well-documented report improves the chance of a useful investigation, even when the customer cannot explain the underlying technical failure.
What to Do if You Have Fallen Victim to This Scam
- Notify your bank immediately. Report the exact unauthorized debit and ask for a complaint number. Request the AePS transaction reference and available agent or acquiring-bank details.
- Preserve the evidence. Save the statement entry, alerts, timestamps, account balance before and after the debit, and every response. Keep full account and Aadhaar numbers out of public posts.
- Consider locking Aadhaar biometrics. Use UIDAI’s official service and follow its instructions. Understand that the lock can also affect legitimate biometric transactions until you unlock it.
- Secure related accounts. Change banking credentials if exposed, review registered phone and email details, and check for additional unauthorized transactions. Ask the bank whether temporary account controls are available.
- File a cybercrime report. In India, use the national cybercrime portal or the current official helpline. Include the bank complaint and transaction references.
- Escalate unresolved disputes in writing. Follow the bank’s grievance process, then the appropriate regulator route if the response is inadequate. Ask for the findings and applicable rule, not a verbal assurance.
Beware of messages promising instant reversal for a processing fee. A legitimate investigation should not require a transfer to a stranger.
Frequently Asked Questions
Is AePS itself a scam?
No. AePS is a legitimate payment system. This article concerns unauthorized withdrawals or impersonation connected to its use.
Can an AePS withdrawal happen without my ATM card?
Yes. AePS uses a different transaction path. Ask your bank for the precise channel and authentication record when you see an unfamiliar debit.
Will locking my biometrics reverse a past withdrawal?
No. The lock is a preventive control. Report and dispute an existing debit through your bank and the relevant official channels.
Does an AePS label prove my fingerprint was copied?
No. The label does not establish the mechanism. Investigators need authentication and service-point records to determine what happened.
Am I guaranteed a refund if I report within a set number of hours?
No universal promise fits every case. Report promptly and ask your bank which liability and dispute rules apply to your account.
Where should I check my Aadhaar biometric-lock status?
Use UIDAI’s official website or app directly. Avoid links in unexpected texts, emails, or calls claiming to provide an urgent unlock.
The Bottom Line
AePS biometric fraud is an unauthorized account transaction, not proof that every biometric payment is unsafe. The bank’s transaction trail matters more than guesses.
Confirm the debit, report it quickly, preserve records, and consider official biometric locking. Demand a written explanation of the outcome.