🛡 Today's alert: fake "electricity bill overdue" SMS scam is trending — never click payment links in SMS.
Online Privacy

Aadhaar Safety in 2026 — The New Aadhaar App, Masked Aadhaar and Locking Your Biometrics

Your Aadhaar number is on more photocopies than you can count — at hotels, hospitals, phone shops, gas agencies. Each of those copies is a small risk: your Aadhaar is tied to your bank accounts, SIM cards, and government benefits, and a leaked copy can be used for impersonation. In 2026, UIDAI (the authority that runs Aadhaar) has rolled out tools that finally let you share less and lock down more — headlined by a new Aadhaar app.

Here's how to use Aadhaar safely today.

The new Aadhaar app — what changed

UIDAI has launched a new Aadhaar app (replacing the older mAadhaar, which is being retired). Its whole design is about sharing less:

  • QR-based sharing — verify your identity at a hotel, hospital or office by showing a QR code instead of handing over a photocopy. No paper trail of your Aadhaar left behind.
  • Face authentication — verify yourself using your face, reducing reliance on fingerprints.
  • Selective information sharing — share only the fields a particular counter actually needs, not your full details.
  • Built-in biometric lock — lock or unlock your fingerprint, face and iris data with a single tap.

Download it only from the official Google Play Store or Apple App Store, and set up your profile with the OTP sent to your Aadhaar-linked mobile number.

Stop giving photocopies

The single biggest Aadhaar risk is loose photocopies. Wherever a QR scan or the app is accepted, use it instead of paper. When a copy is genuinely required, use Masked Aadhaar (below) and write the purpose and date across it.

Masked Aadhaar — share proof without the number

Masked Aadhaar is an official version of your e-Aadhaar in which the first eight digits are hidden, showing only the last four. It still carries your photo, name, address and a verifiable QR code — so it works as valid identity proof while keeping your actual number off the page.

Download it from the myAadhaar portal (myaadhaar.uidai.gov.in) by choosing the "masked Aadhaar" option. Use it for hotels, private verifications, and anywhere the full number isn't strictly required.

Lock your biometrics — the most underused protection

Biometric authentication (fingerprint/iris) can be used to authorise things like Aadhaar-enabled Payment System (AePS) transactions. If your fingerprint data were ever cloned from a leaked document, locking your biometrics blocks that misuse entirely.

  • In the new Aadhaar app (or myAadhaar portal), turn on biometric lock.
  • While locked, no one can use your biometrics to authenticate — not even you, until you temporarily unlock it for a genuine need (say, an Aadhaar update).
  • Unlock only for the moment you need it, then it re-locks.

This one setting shuts down a whole category of AePS and impersonation fraud. Turn it on today.

Check who has used your Aadhaar

UIDAI lets you view your Aadhaar authentication history — a log of when and where your Aadhaar was used to authenticate. Review it periodically on the myAadhaar portal; if you see authentications you don't recognise, that's your early warning to lock biometrics and investigate.

Everyday Aadhaar safety rules

DoDon't
Use QR / app / masked Aadhaar to shareHand over open photocopies
Lock biometrics when not neededShare your Aadhaar OTP with anyone, ever
Download only from official UIDAI channelsTrust "Aadhaar update" links in SMS/WhatsApp
Keep your linked mobile number currentEnter Aadhaar details on unknown websites
Check authentication history occasionallyAssume a leaked copy is harmless
No one calls you to "verify Aadhaar"

UIDAI does not call, SMS or WhatsApp asking you to "verify", "re-KYC" or "update" your Aadhaar urgently, and it never asks for your OTP. Those are scams — including fake "your Aadhaar is suspended" messages. Update Aadhaar only through official UIDAI channels.

Virtual ID — the feature almost nobody uses

If you would rather not hand over your Aadhaar number at all, you often do not have to. A Virtual ID (VID) is a temporary 16-digit number, generated by you, that can be used in place of your Aadhaar number for authentication and KYC. The agency verifies you successfully but never learns your actual Aadhaar number.

  • Generate it free from the myAadhaar portal or the Aadhaar app, or through UIDAI's SMS service.
  • It is revocable and replaceable — generate a fresh one whenever you like, and the old one stops working.
  • It cannot be reverse-engineered into your Aadhaar number, which is the entire point.

Use a VID wherever a private entity asks for Aadhaar for verification — telecom, private KYC, one-off registrations. Combined with masked Aadhaar for paper and QR for in-person checks, there are very few situations left in which anyone genuinely needs your bare Aadhaar number.

AePS fraud and the bank account you forgot about

Two Aadhaar-specific money risks are worth understanding separately, because neither behaves like an ordinary scam.

AePS withdrawals. The Aadhaar-enabled Payment System lets money be withdrawn at a banking correspondent using only your Aadhaar number and a fingerprint — no card, no PIN, no OTP. That is a genuine convenience in areas with no branch, and a genuine exposure if your fingerprint has been captured from a document or a cloned scanner. Victims often notice only when a balance drops. Locking your biometrics eliminates this risk entirely, which is why it is the single highest-value setting in this guide.

The NPCI mapper and your DBT money. Government benefits, subsidies and scholarships are credited to whichever bank account is currently Aadhaar-seeded in the NPCI mapper — and that is normally the account you seeded most recently, not the one you think of as your main account. People routinely find a subsidy sitting in a dormant account opened years ago for a single purpose. If a benefit has not arrived, check which account your Aadhaar is mapped to before assuming the payment failed; you can re-seed through the bank you want the money in.

If your Aadhaar is misused

  1. Lock your biometrics immediately via the app or myAadhaar portal.
  2. Check your authentication history and your bank statements (especially for AePS debits).
  3. Report to UIDAI on 1947 (the Aadhaar helpline) or at uidai.gov.in.
  4. For financial loss, call the cyber helpline 1930 and file at cybercrime.gov.in.

Frequently asked questions

Is it safe to give my Aadhaar number to a hotel or shop?

Usually unnecessary, which is the better answer. Private entities can verify you without holding your number — through the app's QR, a masked Aadhaar copy, or a Virtual ID. Where a hotel or shop insists on a photocopy, hand over masked Aadhaar and write the purpose and date across the copy. An open photocopy sitting in a drawer is the most common way Aadhaar details leak.

Can someone empty my bank account with just my Aadhaar number?

Not with the number alone. The realistic risk is AePS, where a withdrawal can be authorised with your Aadhaar number plus a fingerprint — no OTP involved. That is precisely the scenario biometric lock shuts down. With biometrics locked, a leaked Aadhaar number on its own does not let anyone move your money.

What is the difference between masked Aadhaar and a Virtual ID?

Masked Aadhaar is a document — your e-Aadhaar with the first eight digits hidden, useful when someone needs a physical or PDF copy. A Virtual ID is a number — a temporary, revocable 16-digit substitute you can quote instead of your Aadhaar for authentication and KYC. Use masked Aadhaar for paper, VID when a number is being asked for.

If I lock my biometrics, will I have problems at the ration shop or bank?

Only if you forget to unlock. Locking blocks biometric authentication until you temporarily unlock it, which takes a moment in the app or on the myAadhaar portal, after which it re-locks. For anyone who authenticates regularly, the habit is simply: unlock, do the transaction, done. The protection is worth that minor friction.

I got an SMS saying my Aadhaar will be suspended. Is it real?

No. UIDAI does not send urgent suspension, re-KYC or verification demands by SMS or WhatsApp, and never asks for your OTP. Aadhaar is not "suspended" for inaction in this way. Do not click the link; update Aadhaar only through official UIDAI channels, and report the number on Chakshu at sancharsaathi.gov.in.

How do I check whether a SIM or bank account was opened in my name?

For mobile connections, use the Sanchar Saathi portal at sancharsaathi.gov.in to see the connections issued against your identity and flag any you do not recognise. For Aadhaar use generally, review your authentication history on the myAadhaar portal — unfamiliar entries are your earliest warning that something is being done in your name.

Is my Aadhaar-linked mobile number important?

It is the linchpin. Every OTP, update and alert goes to it — so an outdated number means you cannot authenticate, cannot update Aadhaar, and will not see alerts, while whoever now holds that number might. If you have changed numbers, update it at an Aadhaar centre as a priority; it is not something you can change online.

Should my child have an Aadhaar, and is it safe?

Children can be enrolled, and biometrics are updated at prescribed ages as they grow. Apply the same discipline you would to your own: keep the linked mobile number one a parent controls, avoid circulating photocopies to schools and coaching centres, and use masked Aadhaar where a copy is genuinely required. Children's data also carries additional protection under the DPDP framework — see our guide to your privacy rights.

The bottom line

Aadhaar isn't going anywhere, but in 2026 you finally have the tools to control it: share a QR or masked version instead of a photocopy, use the new Aadhaar app for selective sharing, and — above all — lock your biometrics. Five minutes of setup closes off the most common ways an Aadhaar leak turns into real money lost.

How this guide is made

Written and fact-checked by the Awareness360 editorial team from primary sources — RBI, SEBI, IRDAI, the Income Tax Department and Government of India portals — with links to the originals in the text above. Last reviewed on 16 Jul 2026. This is general educational information for Indian readers, not professional financial, legal or tax advice.

Spotted something out of date? Tell us and we'll correct it — see our editorial policy.

← Previous
WhatsApp Safety — Lock Down Your Account and Spot the Scams