An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC checks, hijack victims' Aadhaar-linked mobile numbers, and take out fraudulent instant loans at multiple banks and fintech lenders before Ahmedabad Cyber Crime Police arrested seven suspects.
Reviewed by the Social Engineering Examples team.
Between at least early 2026 and May 2026, an interstate gang exploited India's Aadhaar biometric e-KYC system to fraudulently obtain instant personal loans from multiple banks and fintech lending platforms. The scheme came to light on 10 April 2026 when a Thaltej (Ahmedabad) businessman reported to Ahmedabad Cyber Crime Police that his Aadhaar-linked mobile number had been changed without his consent, cutting off his OTPs and letting unknown parties access his DigiLocker and banking services; he later discovered a Rs 25,000 fraudulent loan had been taken in his name via Jio Payments Bank after spotting suspicious enquiries on his credit report. Investigation revealed the gang combined identity-data harvesting (from data leaks, GST/PAN lookup services such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit reports, and photos scraped from social and payment apps) with AI deepfake technology: victims' static photographs were converted into short synthetic "eye-blink" videos using Google Gemini (and, per later reporting, Meta AI) and displayed on a screen to fool Aadhaar's facial-liveness verification carried out through Aadhaar Update Client Lite (UCL) kits at Common Service Centres, allowing the gang to change victims' registered mobile numbers, intercept OTPs, and apply for instant loans in the victims' names at IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank and lending apps RKBANSAL, True Credits and EarlySalary. Ahmedabad City Cyber Crime Police arrested four accused (Kanu Parmar, Ashish Valand, Mohammad Kaif Patel, Deep Gupta) on 29 April 2026, then three more alleged masterminds from Uttar Pradesh and Assam (Krishna Rampratap Motilal Prajapati, Rabbul Hussain, Kazimuddin Siraj Ali) on 7-8 May 2026, bringing the total to seven arrests with one suspect reportedly still at large.
Investigators described a multi-role gang: one member sourced victims' Aadhaar numbers, mobile numbers and photographs (via data leaks, GST/PAN lookup platforms such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit-report pulls, and photos scraped from social/payment apps including WhatsApp, Instagram, Facebook, PhonePe, Google Pay and Truecaller); a second procured genuine Aadhaar Update Client Lite (UCL) kits used at Common Service Centres; a third fed a victim's static photo into consumer AI tools (Google Gemini, and in the expanded case Meta AI) to generate a short synthetic "eye-blink" video simulating a live face; that video was displayed on a screen to the UCL kit's camera to pass Aadhaar's facial liveness check, after which the gang used the (fraudulently re-verified) session to change the victim's Aadhaar-linked mobile number. With the number redirected, OTPs that should have gone to the real Aadhaar holder went to the fraudsters instead, giving them access to DigiLocker, UIDAI services, and e-KYC flows at banks/lenders (reported: IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank, and lending platforms RKBANSAL, True Credits and EarlySalary), which they used to open accounts and apply for small instant personal loans (typically Rs 25,000-50,000) in the victims' names.
The scheme required no direct contact with or deception of the victim: it targeted an automated biometric/OTP verification pipeline rather than a person. The first case surfaced when a 36-year-old Thaltej (Ahmedabad) businessman stopped receiving OTPs from his bank for about two days and, on investigating, found his Aadhaar-linked mobile number had been changed without his consent, locking him out of DigiLocker and his banking apps; he only realized loans had been taken in his name after unusual loan enquiries appeared on his credit report. Ahmedabad Mirror had separately reported on deepfake-video liveness-bypass techniques the day before the arrests were announced, and police said the bust followed technical surveillance and human-intelligence work after the businessman's complaint.
Ahmedabad City Cyber Crime Police Station registered the case on 10 April 2026 under Bharatiya Nyaya Sanhita (BNS) Sections 61(2)(a), 336(2), 336(3) and Information Technology Act Sections 43(a), 43(b), 43(i), 66 and 66(C). Four accused (Kanu/Kanubhai Parmar, Ashish Valand, Mohammad Kaif Patel and Deep Gupta) were arrested and sent to judicial custody around 29 April 2026. Investigators, led by DCP Cyber Crime Cell Dr. Lavina Sinha and ACP Hardik Makadiya, said the probe then expanded, and on 7-8 May 2026 three more alleged masterminds (Krishna Rampratap Motilal Prajapati, Rabbul Hussain and Kazimuddin/Kajimuddin Siraj Ali) were arrested in a wider interstate racket, bringing the total to seven arrests, with one suspect (Oli Ullah) reported still absconding. As of the available reporting the matter remained under active investigation (police were coordinating with counterparts in other states to trace further suspects and victims); no trial verdict or conviction had been publicly reported. All claims here are police allegations pending court adjudication.
This is one of the first well-documented Indian law-enforcement cases showing consumer-grade generative AI tools (Gemini, Meta AI) being used to defeat a national government biometric identity system's liveness check at scale, converting a supposedly strong "physical presence" safeguard into a spoofable step via a screen-replay deepfake. It illustrates how AI-enabled identity fraud chains together multiple weak links, including leaked/scraped PII and photos, third-party credit-data lookup tools, legitimate-but-poorly-controlled Aadhaar update kits, and fintech e-KYC/instant-loan flows optimized for speed over friction, to produce fraudulent credit at scale against banks and digital lenders, with real individuals left holding hijacked identities and unauthorized loans on their credit files. It is a concrete data point for any organization (bank, fintech lender, or government ID system) relying on facial liveness or "video selfie" checks as a standalone anti-fraud control.
Reported/implied mitigations: Aadhaar biometric lock via the mAadhaar app (police publicly urged citizens to enable it); banks/UIDAI treating repeated e-KYC mobile-number-change requests and photo-only liveness passes as fraud signals; credit-report monitoring (the victim in the seed case only discovered the fraud via unexpected loan enquiries on his credit report); stronger liveness checks (e.g., randomized challenge-response, multi-frame depth/texture analysis, active blink+pose+lighting-consistency checks) rather than simple static-photo-to-video "blink" liveness tests; restricting/auditing CSC operator access to Aadhaar Update Client Lite (UCL) kits; cross-referencing GST/PAN/CIBIL data-broker platforms (MastersIndia, Peridot, CRIF High Mark) for anomalous bulk lookups; lenders adding secondary out-of-band verification before instant-loan disbursal rather than relying on e-KYC/OTP alone.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…