Rajasthan Police warns of AI, deepfake cyber fraud targeting Aadhaar
Synopsis
Key Takeaways
The Rajasthan Police Cyber Crime Branch has issued a public advisory alerting citizens to a sharp rise in Artificial Intelligence (AI) and deepfake-based cyber fraud, with criminals increasingly exploiting AI tools to bypass Aadhaar biometric security and commit financial crimes. The advisory, released on 20 May from Jaipur, outlines specific attack methods and urges immediate preventive action.
How the Fraud Works
According to the advisory, cybercriminals begin by harvesting a victim's Aadhaar number, photograph, and mobile details through phishing, social engineering, and data leaks. They then attempt to change the Aadhaar-linked mobile number by misusing Common Service Centres (CSC) or Update Client Lite (UCL) kits.
Once the registered mobile number is altered, OTPs are redirected to the criminals, granting them unauthorised access to digital accounts and services. This method effectively bypasses standard two-factor authentication that millions of Indians rely on for banking and government services.
The Deepfake Dimension
Additional Director General of Police (Cyber Crime) V.K. Singh highlighted a more sophisticated layer to these attacks: AI-powered deepfake technology capable of generating highly realistic fake videos that replicate a person's facial expressions and eye movements. Such fabricated visuals can deceive facial authentication systems used by platforms including DigiLocker, e-KYC portals, and online banking systems, enabling fraudulent transactions.
Singh noted that tools such as Google Gemini, OpenAI ChatGPT, and xAI Grok are among the AI platforms reportedly being misused to facilitate these attacks. This comes amid a broader national surge in AI-assisted cybercrime, with law enforcement agencies across multiple states flagging similar threats in recent months.
What Citizens Must Do Now
Rajasthan Police has urged all citizens to immediately lock their Aadhaar biometrics through the mAadhaar app or the official UIDAI website. Once locked, fingerprint and iris data cannot be used for authentication unless personally unlocked by the Aadhaar holder.
Citizens have also been advised to regularly review their Aadhaar authentication history on the UIDAI portal, which shows where and how Aadhaar credentials have been used over the past six months. Keeping an active email ID linked to Aadhaar for instant change notifications was also recommended.
Reporting and Helpline
ADG Singh urged citizens not to ignore SMS alerts regarding any updates to their Aadhaar-linked mobile number. In cases of fraud or attempted fraud, complaints can be filed at the nearest police station, a Cyber Police Station, or the National Cyber Crime Reporting Portal. The dedicated Cyber Helpline number 1930 is also available for immediate assistance.
As AI tools grow more accessible and deepfake quality improves rapidly, this advisory signals that identity-based cyber threats are entering a new and more dangerous phase — one that demands proactive steps from every digital citizen.