Case Library / Phishing / Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.

Share:

Social Engineering Examples·7 sources

What Happened

Between at least early 2026 and May 2026, an interstate gang exploited India's Aadhaar biometric e-KYC system to fraudulently obtain instant personal loans from multiple banks and fintech lending platforms. The scheme came to light on 10 April 2026 when a Thaltej (Ahmedabad) businessman reported to Ahmedabad Cyber Crime Police that his Aadhaar-linked mobile number had been changed without his consent, cutting off his OTPs and letting unknown parties access his DigiLocker and banking services; he later discovered a Rs 25,000 fraudulent loan had been taken in his name via Jio Payments Bank after spotting suspicious enquiries on his credit report.

Investigation revealed the gang combined identity-data harvesting (from data leaks, GST/PAN lookup services such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit reports, and photos scraped from social and payment apps) with AI deepfake technology: victims' static photographs were converted into short synthetic "eye-blink" videos using Google Gemini (and, per later reporting, Meta AI) and displayed on a screen to fool Aadhaar's facial-liveness verification carried out through Aadhaar Update Client Lite (UCL) kits at Common Service Centres, allowing the gang to change victims' registered mobile numbers, intercept OTPs, and apply for instant loans in the victims' names at IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank and lending apps RKBANSAL, True Credits and EarlySalary.

Ahmedabad City Cyber Crime Police arrested four accused (Kanu Parmar, Ashish Valand, Mohammad Kaif Patel, Deep Gupta) on 29 April 2026, then three more alleged masterminds from Uttar Pradesh and Assam (Krishna Rampratap Motilal Prajapati, Rabbul Hussain, Kazimuddin Siraj Ali) on 7-8 May 2026, bringing the total to seven arrests with one suspect reportedly still at large.

How the Attack Worked

Investigators described a multi-role gang: one member sourced victims' Aadhaar numbers, mobile numbers and photographs (via data leaks, GST/PAN lookup platforms such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit-report pulls, and photos scraped from social/payment apps including WhatsApp, Instagram, Facebook, PhonePe, Google Pay and Truecaller); a second procured genuine Aadhaar Update Client Lite (UCL) kits used at Common Service Centres; a third fed a victim's static photo into consumer AI tools (Google Gemini, and in the expanded case Meta AI) to generate a short synthetic "eye-blink" video simulating a live face; that video was displayed on a screen to the UCL kit's camera to pass Aadhaar's facial liveness check, after which the gang used the (fraudulently re-verified) session to change the victim's Aadhaar-linked mobile number.

With the number redirected, OTPs that should have gone to the real Aadhaar holder went to the fraudsters instead, giving them access to DigiLocker, UIDAI services, and e-KYC flows at banks/lenders (reported: IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank, and lending platforms RKBANSAL, True Credits and EarlySalary), which they used to open accounts and apply for small instant personal loans (typically Rs 25,000-50,000) in the victims' names.

The Lure & the Tell

The scheme required no direct contact with or deception of the victim: it targeted an automated biometric/OTP verification pipeline rather than a person. The first case surfaced when a 36-year-old Thaltej (Ahmedabad) businessman stopped receiving OTPs from his bank for about two days and, on investigating, found his Aadhaar-linked mobile number had been changed without his consent, locking him out of DigiLocker and his banking apps; he only realized loans had been taken in his name after unusual loan enquiries appeared on his credit report.

Ahmedabad Mirror had separately reported on deepfake-video liveness-bypass techniques the day before the arrests were announced, and police said the bust followed technical surveillance and human-intelligence work after the businessman's complaint.

Outcome

Ahmedabad City Cyber Crime Police Station registered the case on 10 April 2026 under Bharatiya Nyaya Sanhita (BNS) Sections 61(2)(a), 336(2), 336(3) and Information Technology Act Sections 43(a), 43(b), 43(i), 66 and 66(C). Four accused (Kanu/Kanubhai Parmar, Ashish Valand, Mohammad Kaif Patel and Deep Gupta) were arrested and sent to judicial custody around 29 April 2026. Investigators, led by DCP Cyber Crime Cell Dr. Lavina Sinha and ACP Hardik Makadiya, said the probe then expanded, and on 7-8 May 2026 three more alleged masterminds (Krishna Rampratap Motilal Prajapati, Rabbul Hussain and Kazimuddin/Kajimuddin Siraj Ali) were arrested in a wider interstate racket, bringing the total to seven arrests, with one suspect (Oli Ullah) reported still absconding.

As of the available reporting the matter remained under active investigation (police were coordinating with counterparts in other states to trace further suspects and victims); no trial verdict or conviction had been publicly reported. All claims here are police allegations pending court adjudication.

Why It Matters

This is one of the first well-documented Indian law-enforcement cases showing consumer-grade generative AI tools (Gemini, Meta AI) being used to defeat a national government biometric identity system's liveness check at scale, converting a supposedly strong "physical presence" safeguard into a spoofable step via a screen-replay deepfake. It illustrates how AI-enabled identity fraud chains together multiple weak links, including leaked/scraped PII and photos, third-party credit-data lookup tools, legitimate-but-poorly-controlled Aadhaar update kits, and fintech e-KYC/instant-loan flows optimized for speed over friction, to produce fraudulent credit at scale against banks and digital lenders, with real individuals left holding hijacked identities and unauthorized loans on their credit files.

It is a concrete data point for any organization (bank, fintech lender, or government ID system) relying on facial liveness or "video selfie" checks as a standalone anti-fraud control.

Defenses

Reported/implied mitigations: Aadhaar biometric lock via the mAadhaar app (police publicly urged citizens to enable it); banks/UIDAI treating repeated e-KYC mobile-number-change requests and photo-only liveness passes as fraud signals; credit-report monitoring (the victim in the seed case only discovered the fraud via unexpected loan enquiries on his credit report); stronger liveness checks (e.g., randomized challenge-response, multi-frame depth/texture analysis, active blink+pose+lighting-consistency checks) rather than simple static-photo-to-video "blink" liveness tests; restricting/auditing CSC operator access to Aadhaar Update Client Lite (UCL) kits; cross-referencing GST/PAN/CIBIL data-broker platforms (MastersIndia, Peridot, CRIF High Mark) for anomalous bulk lookups; lenders adding secondary out-of-band verification before instant-loan disbursal rather than relying on e-KYC/OTP alone.

Sources
Cite this case

Social Engineering Examples. “Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)”. Accessed 19 September 2026. https://socialengineeringexamples.com/ahmedabad-aadhaar-deepfake-ekyc-loan-fraud-2026

Attack Chain & Defense
1Data harvesting
What happened

A data-broker role sourced victims' Aadhaar numbers, PAN/GST details, and photographs, reportedly via data leaks, commercial GST/PAN lookup platforms (MastersIndia, Peridot), and CIBIL/CRIF High Mark credit-report pulls, plus photos scraped from social and payment apps (WhatsApp, Instagram, Facebook, PhonePe, Google Pay, Truecaller).

The control that would have stopped it

Restricting and auditing bulk/anomalous queries on commercial GST, PAN, and credit-bureau lookup platforms (MastersIndia, Peridot, CIBIL/CRIF High Mark) for patterns tied to a single requester is the most practical control here; leaked PII and scraped social/payment-app photos are very hard to eliminate at the source.

2Aadhaar-linked number identification
What happened

The gang is reported to have used bot-driven lookup tools on messaging platforms to confirm which mobile number was actually registered against a target's Aadhaar, narrowing which number needed to be hijacked.

The control that would have stopped it

Telecom and messaging-platform operators monitoring for automated bot activity that maps identities to registered mobile numbers, and rate-limiting such lookups, though this is a supporting control rather than a full stop given how distributed such tooling is.

3Kit access
What happened

A separate kit-runner role procured genuine Aadhaar Update Client Lite (UCL) enrolment kits normally issued to Common Service Centre operators, giving the gang legitimate-looking hardware/software access to Aadhaar's update and liveness-check pipeline.

The control that would have stopped it

Tightening access controls, credentialing, and audit trails over who can operate Aadhaar UCL enrolment kits at CSC centres, since kit diversion is the point where a "legitimate" tool enters the fraud chain and is realistically the more controllable choke point than the underlying data leaks.

4Deepfake generation
What happened

A technical operator fed a victim's static photograph into consumer generative-AI tools (Google Gemini, and in the expanded case Meta AI) to produce a short synthetic "eye-blink" video simulating a live face.

The control that would have stopped it

Consumer generative-AI platforms' own misuse-detection and provenance tooling (for example, watermarking or flagging repeated face-animation generation from a single uploaded photo) could catch this pattern, though it is hard to close completely given the tools' legitimate uses; the more reliable control sits downstream at the verification step itself (Stage 5).

5Liveness bypass and mobile-number takeover
What happened

The synthetic video was displayed on a screen to the UCL kit's camera to pass Aadhaar's facial-liveness verification, and the fraudulently re-verified session was used to change the victim's Aadhaar-linked mobile number.

The control that would have stopped it

Replacing simple static-photo-to-blink liveness checks with randomized challenge-response prompts and multi-frame depth, texture, and lighting-consistency analysis would make a screen-replay deepfake far harder to pass, and any Aadhaar mobile-number-change request should itself be treated as a high-risk event pending secondary verification.

6OTP interception and account access
What happened

With the number redirected, OTPs intended for the real Aadhaar holder went to the fraudsters, giving them access to DigiLocker, UIDAI services, and e-KYC flows at banks and lending apps.

The control that would have stopped it

Step-up authentication and fraud alerts on DigiLocker, UIDAI, and bank logins immediately following an Aadhaar mobile-number change, plus notifying the old number/email of the change before it takes effect, would give the real holder a chance to catch the takeover before OTPs are misused.

7Fraudulent loan origination
What happened

The gang used the hijacked identity to open bank accounts and apply for small instant personal loans (typically Rs 25,000-50,000) at multiple banks and fintech lenders in the victim's name.

The control that would have stopped it

Lenders adding secondary out-of-band verification, such as a callback to a previously-known number or a live human video-KYC review, before instant-loan disbursal rather than relying on e-KYC/OTP alone, and both lenders and consumers monitoring credit reports for unexpected enquiries, as happened in the seed case.

8Cash-out and laundering
What happened

Proceeds from the fraudulent loans were routed through multiple accounts, including one held by an accused acting as a money mule, to obscure the trail before the racket was disrupted.

The control that would have stopped it

Standard anti-money-laundering transaction monitoring on receiving accounts for the sudden appearance and rapid pass-through of freshly disbursed loan funds is the realistic backstop once the earlier controls have already failed, since tracing funds after multiple hand-offs is much harder than catching the fraud upstream.

Quick Facts
Victim
Indian digital lending platforms and banks relying on Aadhaar e-KYC/biometric liveness verification for instant loans and account opening
(named: IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank, RKBANSAL, True Credits, EarlySalary), plus the individual Aadhaar holders whose identities and mobile numbers were hijacked to obtain the loans
Location
Ahmedabad, Gujarat, India
(accused also drawn from Vadodara, Bharuch, Anand and Jambusar in Gujarat; Kushinagar, Uttar Pradesh; and Morigaon, Assam)
Date
Case registered 10 April 2026
(Ahmedabad Cyber Crime Police Station); first 4 arrests announced 29 April 2026; 3 further arrests announced 7-8 May 2026 (total 7 arrested as of reporting, with one suspect, Oli Ullah, reported still absconding)
Impact
At least one fraudulent instant loan of Rs 25,000 (about $300) was confirmed obtained in the victim's name.
Confirmed loss disclosed in reporting: at least one fraudulent instant loan of Rs 25,000 (~$300) obtained in a Thaltej (Ahmedabad) victim's name via Jio Payments Bank, discovered only when the victim noticed suspicious loan enquiries on his credit report. Investigators separately gave an unverified estimate that the wider racket may have generated roughly Rs 10-15 lakh per year (~$12,000-$18,000) across multiple victims and lenders; this figure is described in press reporting as a police estimate, not a court-established or audited total. Full victim count and aggregate fraudulent-loan value were still under investigation (police were "probing to unveil the scale of the scam") as of the last reporting found.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance, Government & Public Sector
Threat Actor
Organized Crime
Explore more

Related Cases

Browse by what this case has in common with others in the library.

Council on Foreign Relations Watering-Hole Attack (IE Zero-Day, CVE-2012-4792)

In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…

Incident 2012Read →

UAC-0050 ClickFix Fake-reCAPTCHA Campaign Deploys 'Lucky Volunteer' Infostealer Against Ukrainian Organizations

A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…

Incident 2024Read →

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…

Incident 2021Read →

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.

Incident 2026Read →

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.

Incident 2006Read →

North Korea's 'Contagious Interview' ClickFix Fake Job-Assessment Campaign Targets Crypto Industry (2025)

Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.

Incident 2025Read →