An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
Social Engineering Examples·7 sources
Between at least early 2026 and May 2026, an interstate gang exploited India's Aadhaar biometric e-KYC system to fraudulently obtain instant personal loans from multiple banks and fintech lending platforms. The scheme came to light on 10 April 2026 when a Thaltej (Ahmedabad) businessman reported to Ahmedabad Cyber Crime Police that his Aadhaar-linked mobile number had been changed without his consent, cutting off his OTPs and letting unknown parties access his DigiLocker and banking services; he later discovered a Rs 25,000 fraudulent loan had been taken in his name via Jio Payments Bank after spotting suspicious enquiries on his credit report.
Investigation revealed the gang combined identity-data harvesting (from data leaks, GST/PAN lookup services such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit reports, and photos scraped from social and payment apps) with AI deepfake technology: victims' static photographs were converted into short synthetic "eye-blink" videos using Google Gemini (and, per later reporting, Meta AI) and displayed on a screen to fool Aadhaar's facial-liveness verification carried out through Aadhaar Update Client Lite (UCL) kits at Common Service Centres, allowing the gang to change victims' registered mobile numbers, intercept OTPs, and apply for instant loans in the victims' names at IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank and lending apps RKBANSAL, True Credits and EarlySalary.
Ahmedabad City Cyber Crime Police arrested four accused (Kanu Parmar, Ashish Valand, Mohammad Kaif Patel, Deep Gupta) on 29 April 2026, then three more alleged masterminds from Uttar Pradesh and Assam (Krishna Rampratap Motilal Prajapati, Rabbul Hussain, Kazimuddin Siraj Ali) on 7-8 May 2026, bringing the total to seven arrests with one suspect reportedly still at large.
Investigators described a multi-role gang: one member sourced victims' Aadhaar numbers, mobile numbers and photographs (via data leaks, GST/PAN lookup platforms such as MastersIndia and Peridot, CIBIL/CRIF High Mark credit-report pulls, and photos scraped from social/payment apps including WhatsApp, Instagram, Facebook, PhonePe, Google Pay and Truecaller); a second procured genuine Aadhaar Update Client Lite (UCL) kits used at Common Service Centres; a third fed a victim's static photo into consumer AI tools (Google Gemini, and in the expanded case Meta AI) to generate a short synthetic "eye-blink" video simulating a live face; that video was displayed on a screen to the UCL kit's camera to pass Aadhaar's facial liveness check, after which the gang used the (fraudulently re-verified) session to change the victim's Aadhaar-linked mobile number.
With the number redirected, OTPs that should have gone to the real Aadhaar holder went to the fraudsters instead, giving them access to DigiLocker, UIDAI services, and e-KYC flows at banks/lenders (reported: IDFC First Bank, Kotak Mahindra Bank, City Union Bank, Jio Payments Bank, and lending platforms RKBANSAL, True Credits and EarlySalary), which they used to open accounts and apply for small instant personal loans (typically Rs 25,000-50,000) in the victims' names.
The scheme required no direct contact with or deception of the victim: it targeted an automated biometric/OTP verification pipeline rather than a person. The first case surfaced when a 36-year-old Thaltej (Ahmedabad) businessman stopped receiving OTPs from his bank for about two days and, on investigating, found his Aadhaar-linked mobile number had been changed without his consent, locking him out of DigiLocker and his banking apps; he only realized loans had been taken in his name after unusual loan enquiries appeared on his credit report.
Ahmedabad Mirror had separately reported on deepfake-video liveness-bypass techniques the day before the arrests were announced, and police said the bust followed technical surveillance and human-intelligence work after the businessman's complaint.
Ahmedabad City Cyber Crime Police Station registered the case on 10 April 2026 under Bharatiya Nyaya Sanhita (BNS) Sections 61(2)(a), 336(2), 336(3) and Information Technology Act Sections 43(a), 43(b), 43(i), 66 and 66(C). Four accused (Kanu/Kanubhai Parmar, Ashish Valand, Mohammad Kaif Patel and Deep Gupta) were arrested and sent to judicial custody around 29 April 2026. Investigators, led by DCP Cyber Crime Cell Dr. Lavina Sinha and ACP Hardik Makadiya, said the probe then expanded, and on 7-8 May 2026 three more alleged masterminds (Krishna Rampratap Motilal Prajapati, Rabbul Hussain and Kazimuddin/Kajimuddin Siraj Ali) were arrested in a wider interstate racket, bringing the total to seven arrests, with one suspect (Oli Ullah) reported still absconding.
As of the available reporting the matter remained under active investigation (police were coordinating with counterparts in other states to trace further suspects and victims); no trial verdict or conviction had been publicly reported. All claims here are police allegations pending court adjudication.
This is one of the first well-documented Indian law-enforcement cases showing consumer-grade generative AI tools (Gemini, Meta AI) being used to defeat a national government biometric identity system's liveness check at scale, converting a supposedly strong "physical presence" safeguard into a spoofable step via a screen-replay deepfake. It illustrates how AI-enabled identity fraud chains together multiple weak links, including leaked/scraped PII and photos, third-party credit-data lookup tools, legitimate-but-poorly-controlled Aadhaar update kits, and fintech e-KYC/instant-loan flows optimized for speed over friction, to produce fraudulent credit at scale against banks and digital lenders, with real individuals left holding hijacked identities and unauthorized loans on their credit files.
It is a concrete data point for any organization (bank, fintech lender, or government ID system) relying on facial liveness or "video selfie" checks as a standalone anti-fraud control.
Reported/implied mitigations: Aadhaar biometric lock via the mAadhaar app (police publicly urged citizens to enable it); banks/UIDAI treating repeated e-KYC mobile-number-change requests and photo-only liveness passes as fraud signals; credit-report monitoring (the victim in the seed case only discovered the fraud via unexpected loan enquiries on his credit report); stronger liveness checks (e.g., randomized challenge-response, multi-frame depth/texture analysis, active blink+pose+lighting-consistency checks) rather than simple static-photo-to-video "blink" liveness tests; restricting/auditing CSC operator access to Aadhaar Update Client Lite (UCL) kits; cross-referencing GST/PAN/CIBIL data-broker platforms (MastersIndia, Peridot, CRIF High Mark) for anomalous bulk lookups; lenders adding secondary out-of-band verification before instant-loan disbursal rather than relying on e-KYC/OTP alone.
Social Engineering Examples. “Ahmedabad Aadhaar Deepfake e-KYC Loan Fraud (2026)”. Accessed 19 September 2026. https://socialengineeringexamples.com/ahmedabad-aadhaar-deepfake-ekyc-loan-fraud-2026
A data-broker role sourced victims' Aadhaar numbers, PAN/GST details, and photographs, reportedly via data leaks, commercial GST/PAN lookup platforms (MastersIndia, Peridot), and CIBIL/CRIF High Mark credit-report pulls, plus photos scraped from social and payment apps (WhatsApp, Instagram, Facebook, PhonePe, Google Pay, Truecaller).
Restricting and auditing bulk/anomalous queries on commercial GST, PAN, and credit-bureau lookup platforms (MastersIndia, Peridot, CIBIL/CRIF High Mark) for patterns tied to a single requester is the most practical control here; leaked PII and scraped social/payment-app photos are very hard to eliminate at the source.
The gang is reported to have used bot-driven lookup tools on messaging platforms to confirm which mobile number was actually registered against a target's Aadhaar, narrowing which number needed to be hijacked.
Telecom and messaging-platform operators monitoring for automated bot activity that maps identities to registered mobile numbers, and rate-limiting such lookups, though this is a supporting control rather than a full stop given how distributed such tooling is.
A separate kit-runner role procured genuine Aadhaar Update Client Lite (UCL) enrolment kits normally issued to Common Service Centre operators, giving the gang legitimate-looking hardware/software access to Aadhaar's update and liveness-check pipeline.
Tightening access controls, credentialing, and audit trails over who can operate Aadhaar UCL enrolment kits at CSC centres, since kit diversion is the point where a "legitimate" tool enters the fraud chain and is realistically the more controllable choke point than the underlying data leaks.
A technical operator fed a victim's static photograph into consumer generative-AI tools (Google Gemini, and in the expanded case Meta AI) to produce a short synthetic "eye-blink" video simulating a live face.
Consumer generative-AI platforms' own misuse-detection and provenance tooling (for example, watermarking or flagging repeated face-animation generation from a single uploaded photo) could catch this pattern, though it is hard to close completely given the tools' legitimate uses; the more reliable control sits downstream at the verification step itself (Stage 5).
The synthetic video was displayed on a screen to the UCL kit's camera to pass Aadhaar's facial-liveness verification, and the fraudulently re-verified session was used to change the victim's Aadhaar-linked mobile number.
Replacing simple static-photo-to-blink liveness checks with randomized challenge-response prompts and multi-frame depth, texture, and lighting-consistency analysis would make a screen-replay deepfake far harder to pass, and any Aadhaar mobile-number-change request should itself be treated as a high-risk event pending secondary verification.
With the number redirected, OTPs intended for the real Aadhaar holder went to the fraudsters, giving them access to DigiLocker, UIDAI services, and e-KYC flows at banks and lending apps.
Step-up authentication and fraud alerts on DigiLocker, UIDAI, and bank logins immediately following an Aadhaar mobile-number change, plus notifying the old number/email of the change before it takes effect, would give the real holder a chance to catch the takeover before OTPs are misused.
The gang used the hijacked identity to open bank accounts and apply for small instant personal loans (typically Rs 25,000-50,000) at multiple banks and fintech lenders in the victim's name.
Lenders adding secondary out-of-band verification, such as a callback to a previously-known number or a live human video-KYC review, before instant-loan disbursal rather than relying on e-KYC/OTP alone, and both lenders and consumers monitoring credit reports for unexpected enquiries, as happened in the seed case.
Proceeds from the fraudulent loans were routed through multiple accounts, including one held by an accused acting as a money mule, to obscure the trail before the racket was disrupted.
Standard anti-money-laundering transaction monitoring on receiving accounts for the sudden appearance and rapid pass-through of freshly disbursed loan funds is the realistic backstop once the earlier controls have already failed, since tracing funds after multiple hand-offs is much harder than catching the fraud upstream.
Browse by what this case has in common with others in the library.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP…