oppn parties The Face in the Machine - How AI Is Breaking AEPS Security

News Snippets

  • Calcutta HC asks why are MPs facing egg-pelting, in the mohua Moitra case, allows the MP to enter her constituency with police protection
  • Police find fingerprints and other evidence of both the two accused and the rape survivor inside the bus in the Delhi gang rape case
  • Abhishek Upadhyay, the journalist who exposed the embezzlement of Ram Mandir funds, has sought Supreme Court help as Ghaziabad Police have sought his digital footprint from X. He claimed that such information will compromise the sources who provided him the information
  • Supreme Court quashes 127 FIRs in 5 states against students who took part in CJP stir. In repsonse, CJP cancels the September 5 march from India Gate to Delhi Police headquarters
  • TCS buys Best Buy's GCC operations in India, pips Accenture to the post in a deal worth around Rs 2000cr
  • To avoid stiff tariff, Aun Pharma offers to supply cheaper drugs at Most Favoured Nation pricing to US Medicaid programme
  • 5-member NCLT bench stays Subhash Chandra's Rs 6.5cr repayment order
  • Reliance entered the icecream space by launching Bombay Creamery
  • Copyright office rejects AI system as artwork author, says Parliament needs to make the legal position clear
  • GST collection jumps 15% in August to Rs 199853cr on the back of 29% jump in tax from imports
  • Asian Games: Japan Cricket Association says participating cricketing teams can arrange their own hotels as the Games are not directly under JCA
  • T20s versus Afghanistan: Bumrah and Samson return, Hardik still unfit. Sooryavanshi keeps his place
  • Duleep Trophy: South Zome have upper hand in the other semifinal
  • Duleep Trophy: East Zone beat Central Zone by four wickets to enter the final
  • PM Modi asks youth to make social media content on drug abuse
Duleep Trophy: South Zone beat North Zone by 7 wickets to set up the final clash with East Zone ////// Air Marshall (Retd) Jeetendra Sharma appointed the first CEO of the Ram Temple at Ayodhya
oppn parties
The Face in the Machine - How AI Is Breaking AEPS Security

By Sunil Garodia
First publised on 2026-05-01 15:28:43

About the Author

Sunil Garodia Editor-in-Chief of indiacommentary.com. Current Affairs analyst and political commentator. Author of Cyber Scams in India, Digital Arrest, The Money Trap and The Human Hack

India's digital payments system rests on a single pillar  - Aadhaar. That pillar is now being stress-tested by artificial intelligence.

In 2025, the Unique Identification Authority of India introduced face authentication into its ecosystem - a system that matches a live camera image with Aadhaar records to verify identity instantly. It was pitched as frictionless and secure.

It is now being weaponised.


The Weak Link: AEPS

The Aadhaar Enabled Payment System allows withdrawals using just three inputs - bank name, Aadhaar number, and biometric authentication.

No OTP. No PIN.

Designed for inclusion, it has quietly become one of the most exploitable financial rails in the country.


From Fingerprints to Faces

Fraudsters were already cloning fingerprints using leaked Aadhaar data to drain accounts. By 2023, AEPS fraud made up 11% of cyber-enabled financial crime in India.

Now, the method has evolved.

Cybercrime agencies warn that attackers are using AI-generated facial identities to bypass authentication. A photograph - pulled from social media, land records, or documents - is enough. AI tools animate it, simulate liveness, and present it at an AEPS terminal. The system verifies. The withdrawal goes through.

No alert. No OTP. No resistance.


The Core Risk

Biometrics are not passwords. They cannot be reset.

Once your facial data is compromised, the breach is permanent. Every image you have shared - publicly or through government records - becomes raw material for identity theft.

The barrier to entry has collapsed. What once required technical sophistication now needs little more than a photo and a free app.


A Systemic Failure

The real vulnerability is not just technology - it is architecture.

Biometric data is scattered across poorly secured state portals, especially land and revenue databases. A fraudster does not need to breach Aadhaar's core systems. One weak government website is enough.

As cybercrime experts have repeatedly warned, the threat lies in data leakage combined with procedural gaps - not just hacking.


What You Must Do

Lock your Aadhaar biometrics immediately through UIDAI or the mAadhaar.

Enable bank alerts. Avoid sharing Aadhaar details. Treat any biometric request with suspicion.

If fraud occurs, act fast: report to your bank and file a complaint at cybercrime.gov.in or call 1930.


The Bigger Question

India's digital identity system has expanded financial access at an unprecedented scale. But scale without security is a liability.

Face authentication is not the problem. Deploying it without robust safeguards is.

Without multi-factor authentication, secure data infrastructure, and real-time fraud detection, AEPS risks becoming a pipeline for silent financial theft.

The criminals have already upgraded. The system has not.