Case Library / Phishing / Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)

An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC checks, hijack victims' Aadhaar-linked mobile numbers, and take out fraudulent instant loans at multiple banks and fintech lenders before Ahmedabad Cyber Crime Police arrested seven suspects.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between at least early 2026 and May 2026, an interstate gang exploited India's Aadhaar biometric e-KYC system to fraudulently obtain instant personal loans from multiple banks and fintech lending platforms. The scheme came to light on 10 April 2026 when a Thaltej (Ahmedabad) businessman reported to Ahmedabad Cyber Crime Police that his Aadhaar-linked mobile number had been changed without his consent, cutting off his OTPs and letting unknown parties access his DigiLocker and banking services; he later discovered a Rs 25,000 fraudulent loan had been taken in his name via Jio Payments Bank after spotting suspicious enquiries on his credit report. Investigation revealed the gang combined identity-data harvesting (from data leaks, GST/PAN lookup services such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit reports, and photos scraped from social and payment apps) with AI deepfake technology: victims' static photographs were converted into short synthetic "eye-blink" videos using Google Gemini (and, per later reporting, Meta AI) and displayed on a screen to fool Aadhaar's facial-liveness verification carried out through Aadhaar Update Client Lite (UCL) kits at Common Service Centres, allowing the gang to change victims' registered mobile numbers, intercept OTPs, and apply for instant loans in the victims' names at IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank and lending apps RKBANSAL, True Credits and EarlySalary. Ahmedabad City Cyber Crime Police arrested four accused (Kanu Parmar, Ashish Valand, Mohammad Kaif Patel, Deep Gupta) on 29 April 2026, then three more alleged masterminds from Uttar Pradesh and Assam (Krishna Rampratap Motilal Prajapati, Rabbul Hussain, Kazimuddin Siraj Ali) on 7-8 May 2026, bringing the total to seven arrests with one suspect reportedly still at large.

How the Attack Worked

Investigators described a multi-role gang: one member sourced victims' Aadhaar numbers, mobile numbers and photographs (via data leaks, GST/PAN lookup platforms such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit-report pulls, and photos scraped from social/payment apps including WhatsApp, Instagram, Facebook, PhonePe, Google Pay and Truecaller); a second procured genuine Aadhaar Update Client Lite (UCL) kits used at Common Service Centres; a third fed a victim's static photo into consumer AI tools (Google Gemini, and in the expanded case Meta AI) to generate a short synthetic "eye-blink" video simulating a live face; that video was displayed on a screen to the UCL kit's camera to pass Aadhaar's facial liveness check, after which the gang used the (fraudulently re-verified) session to change the victim's Aadhaar-linked mobile number. With the number redirected, OTPs that should have gone to the real Aadhaar holder went to the fraudsters instead, giving them access to DigiLocker, UIDAI services, and e-KYC flows at banks/lenders (reported: IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank, and lending platforms RKBANSAL, True Credits and EarlySalary), which they used to open accounts and apply for small instant personal loans (typically Rs 25,000-50,000) in the victims' names.

The Lure & the Tell

The scheme required no direct contact with or deception of the victim: it targeted an automated biometric/OTP verification pipeline rather than a person. The first case surfaced when a 36-year-old Thaltej (Ahmedabad) businessman stopped receiving OTPs from his bank for about two days and, on investigating, found his Aadhaar-linked mobile number had been changed without his consent, locking him out of DigiLocker and his banking apps; he only realized loans had been taken in his name after unusual loan enquiries appeared on his credit report. Ahmedabad Mirror had separately reported on deepfake-video liveness-bypass techniques the day before the arrests were announced, and police said the bust followed technical surveillance and human-intelligence work after the businessman's complaint.

Outcome

Ahmedabad City Cyber Crime Police Station registered the case on 10 April 2026 under Bharatiya Nyaya Sanhita (BNS) Sections 61(2)(a), 336(2), 336(3) and Information Technology Act Sections 43(a), 43(b), 43(i), 66 and 66(C). Four accused (Kanu/Kanubhai Parmar, Ashish Valand, Mohammad Kaif Patel and Deep Gupta) were arrested and sent to judicial custody around 29 April 2026. Investigators, led by DCP Cyber Crime Cell Dr. Lavina Sinha and ACP Hardik Makadiya, said the probe then expanded, and on 7-8 May 2026 three more alleged masterminds (Krishna Rampratap Motilal Prajapati, Rabbul Hussain and Kazimuddin/Kajimuddin Siraj Ali) were arrested in a wider interstate racket, bringing the total to seven arrests, with one suspect (Oli Ullah) reported still absconding. As of the available reporting the matter remained under active investigation (police were coordinating with counterparts in other states to trace further suspects and victims); no trial verdict or conviction had been publicly reported. All claims here are police allegations pending court adjudication.

Why It Matters

This is one of the first well-documented Indian law-enforcement cases showing consumer-grade generative AI tools (Gemini, Meta AI) being used to defeat a national government biometric identity system's liveness check at scale, converting a supposedly strong "physical presence" safeguard into a spoofable step via a screen-replay deepfake. It illustrates how AI-enabled identity fraud chains together multiple weak links, including leaked/scraped PII and photos, third-party credit-data lookup tools, legitimate-but-poorly-controlled Aadhaar update kits, and fintech e-KYC/instant-loan flows optimized for speed over friction, to produce fraudulent credit at scale against banks and digital lenders, with real individuals left holding hijacked identities and unauthorized loans on their credit files. It is a concrete data point for any organization (bank, fintech lender, or government ID system) relying on facial liveness or "video selfie" checks as a standalone anti-fraud control.

Defenses

Reported/implied mitigations: Aadhaar biometric lock via the mAadhaar app (police publicly urged citizens to enable it); banks/UIDAI treating repeated e-KYC mobile-number-change requests and photo-only liveness passes as fraud signals; credit-report monitoring (the victim in the seed case only discovered the fraud via unexpected loan enquiries on his credit report); stronger liveness checks (e.g., randomized challenge-response, multi-frame depth/texture analysis, active blink+pose+lighting-consistency checks) rather than simple static-photo-to-video "blink" liveness tests; restricting/auditing CSC operator access to Aadhaar Update Client Lite (UCL) kits; cross-referencing GST/PAN/CIBIL data-broker platforms (MastersIndia, Peridot, CRIF High Mark) for anomalous bulk lookups; lenders adding secondary out-of-band verification before instant-loan disbursal rather than relying on e-KYC/OTP alone.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Data harvesting: A data-broker role sourced victims' Aadhaar numbers, PAN/GST details, and photographs, reportedly via data leaks, commercial GST/PAN lookup platforms (MastersIndia, Peridot), and CIBIL/CRIF High Mark credit-report pulls, plus photos scraped from social and payment apps (WhatsApp, Instagram, Facebook, PhonePe, Google Pay, Truecaller).
Countering Stage 1: Restricting and auditing bulk/anomalous queries on commercial GST, PAN, and credit-bureau lookup platforms (MastersIndia, Peridot, CIBIL/CRIF High Mark) for patterns tied to a single requester is the most practical control here; leaked PII and scraped social/payment-app photos are very hard to eliminate at the source.
2
Aadhaar-linked number identification: The gang is reported to have used bot-driven lookup tools on messaging platforms to confirm which mobile number was actually registered against a target's Aadhaar, narrowing which number needed to be hijacked.
Countering Stage 2: Telecom and messaging-platform operators monitoring for automated bot activity that maps identities to registered mobile numbers, and rate-limiting such lookups, though this is a supporting control rather than a full stop given how distributed such tooling is.
3
Kit access: A separate kit-runner role procured genuine Aadhaar Update Client Lite (UCL) enrolment kits normally issued to Common Service Centre operators, giving the gang legitimate-looking hardware/software access to Aadhaar's update and liveness-check pipeline.
Countering Stage 3: Tightening access controls, credentialing, and audit trails over who can operate Aadhaar UCL enrolment kits at CSC centres, since kit diversion is the point where a "legitimate" tool enters the fraud chain and is realistically the more controllable choke point than the underlying data leaks.
4
Deepfake generation: A technical operator fed a victim's static photograph into consumer generative-AI tools (Google Gemini, and in the expanded case Meta AI) to produce a short synthetic "eye-blink" video simulating a live face.
Countering Stage 4: Consumer generative-AI platforms' own misuse-detection and provenance tooling (for example, watermarking or flagging repeated face-animation generation from a single uploaded photo) could catch this pattern, though it is hard to close completely given the tools' legitimate uses; the more reliable control sits downstream at the verification step itself (Stage 5).
5
Liveness bypass and mobile-number takeover: The synthetic video was displayed on a screen to the UCL kit's camera to pass Aadhaar's facial-liveness verification, and the fraudulently re-verified session was used to change the victim's Aadhaar-linked mobile number.
Countering Stage 5: Replacing simple static-photo-to-blink liveness checks with randomized challenge-response prompts and multi-frame depth, texture, and lighting-consistency analysis would make a screen-replay deepfake far harder to pass, and any Aadhaar mobile-number-change request should itself be treated as a high-risk event pending secondary verification.
6
OTP interception and account access: With the number redirected, OTPs intended for the real Aadhaar holder went to the fraudsters, giving them access to DigiLocker, UIDAI services, and e-KYC flows at banks and lending apps.
Countering Stage 6: Step-up authentication and fraud alerts on DigiLocker, UIDAI, and bank logins immediately following an Aadhaar mobile-number change, plus notifying the old number/email of the change before it takes effect, would give the real holder a chance to catch the takeover before OTPs are misused.
7
Fraudulent loan origination: The gang used the hijacked identity to open bank accounts and apply for small instant personal loans (typically Rs 25,000-50,000) at multiple banks and fintech lenders in the victim's name.
Countering Stage 7: Lenders adding secondary out-of-band verification, such as a callback to a previously-known number or a live human video-KYC review, before instant-loan disbursal rather than relying on e-KYC/OTP alone, and both lenders and consumers monitoring credit reports for unexpected enquiries, as happened in the seed case.
8
Cash-out and laundering: Proceeds from the fraudulent loans were routed through multiple accounts, including one held by an accused acting as a money mule, to obscure the trail before the racket was disrupted.
Countering Stage 8: Standard anti-money-laundering transaction monitoring on receiving accounts for the sudden appearance and rapid pass-through of freshly disbursed loan funds is the realistic backstop once the earlier controls have already failed, since tracing funds after multiple hand-offs is much harder than catching the fraud upstream.
Quick Facts
Victim
Indian digital lending platforms and banks relying on Aadhaar e-KYC/biometric liveness verification for instant loans and account opening (named: IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank, RKBANSAL, True Credits, EarlySalary), plus the individual Aadhaar holders whose identities and mobile numbers were hijacked to obtain the loans
Location
Ahmedabad, Gujarat, India (accused also drawn from Vadodara, Bharuch, Anand and Jambusar in Gujarat; Kushinagar, Uttar Pradesh; and Morigaon, Assam)
Date
Case registered 10 April 2026 (Ahmedabad Cyber Crime Police Station); first 4 arrests announced 29 April 2026; 3 further arrests announced 7-8 May 2026 (total 7 arrested as of reporting, with one suspect, Oli Ullah, reported still absconding)
Impact
Confirmed loss disclosed in reporting: at least one fraudulent instant loan of Rs 25,000 (~$300) obtained in a Thaltej (Ahmedabad) victim's name via Jio Payments Bank, discovered only when the victim noticed suspicious loan enquiries on his credit report. Investigators separately gave an unverified estimate that the wider racket may have generated roughly Rs 10-15 lakh per year (~$12,000-$18,000) across multiple victims and lenders; this figure is described in press reporting as a police estimate, not a court-established or audited total. Full victim count and aggregate fraudulent-loan value were still under investigation (police were "probing to unveil the scale of the scam") as of the last reporting found.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance, Government & Public Sector
Threat Actor
Organized Crime
Related

Related Cases

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…

Incident 2026Read →

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…

Incident 2026Read →