Ritesh Bhatia, a cybercrime investigator and cybersecurity consultant, highlights the vulnerability of biometrics linked to Aadhaar cards, emphasizing the ease with which fingerprints can be hacked and stolen. Criminals are exploiting high-resolution cameras to capture fingerprints from various sources, leading to unauthorized access to individuals’ bank accounts through the Aadhaar Enabled Payment System (AEPS) micro ATMs. Bhatia provides insights into the risks associated with biometric hacking and offers practical advice for safeguarding biometric data.
1. Lock biometrics linked to Aadhaar cards to prevent unauthorized use of fingerprints.
2. Use virtual IDs and regularly monitor authentication history on the UIDAI website to minimize the risk associated with Aadhaar numbers.
3. In the event of falling victim to a biometric scam, report the incident to the bank, freeze the account, and lodge a complaint through the national cybercrime reporting portal.
The issue of biometric hacking and theft linked to Aadhaar cards is a serious concern, as highlighted by Ritesh Bhatia, a cybercrime investigator and cybersecurity consultant. Criminals are using high-resolution cameras to capture fingerprints from various sources, such as property registrations and SIM card registrations, and selling them to other cybercriminals. With access to the Aadhaar number and bank details, these criminals can withdraw money using Aadhaar Enabled Payment System (AEPS) micro ATMs.
The process of biometric hacking involves the theft of fingerprints through various means, such as property registrations, SIM card registrations, or other instances where individuals leave behind their fingerprints. These stolen fingerprints are then used to create rubber moulds or silicon thumbs, which are then used to authenticate transactions through AEPS micro ATMs. This has led to a sudden spike in misuse of the system, resulting in significant financial losses for individuals.
Ritesh Bhatia emphasizes the importance of locking biometrics as a crucial step for every citizen. By locking biometrics, individuals can prevent unauthorized use of their fingerprints for fraudulent activities. Additionally, he suggests getting rid of old Aadhaar cards that do not have a virtual ID and frequently checking the UIDAI website for any unauthorized attempts to use biometric data.
To safeguard against biometric theft and misuse, individuals are advised to take the following steps:
1. Lock Biometrics: Use the mAadhaar app or the UIDAI website to lock biometric data, preventing unauthorized use.
2. Use Virtual ID: Download an Aadhaar with a virtual ID and start using that number to minimize the risk associated with the Aadhaar number.
3. Check Authentication History: Regularly monitor the authentication history on the UIDAI website to identify any unauthorized attempts to access biometric data.
In the event of falling victim to a biometric scam, individuals are advised to take the following actions:
1. Report to the Bank: Report the incident to the bank within three working days, as per RBI guidelines, to initiate the process of refunding the stolen money.
2. Freeze the Account: Consider freezing the bank account temporarily to prevent further unauthorized transactions.
3. Lodge a Complaint: Contact the national cybercrime reporting portal at www.cybercrime.gov.in and call 1930 to lodge a complaint about the incident.
The protection of biometric data linked to Aadhaar cards is crucial to prevent unauthorized access and financial losses. By following the recommended steps, individuals can take proactive measures to safeguard their biometric information and mitigate the risks associated with biometric hacking and theft.
Q1: How can individuals safeguard their biometric data linked to Aadhaar cards?
A1: Individuals can safeguard their biometric data by locking their biometrics, using virtual IDs, and regularly monitoring authentication history on the UIDAI website.
Q2: What should individuals do if they become victims of a biometric scam?
A2: In the event of falling victim to a biometric scam, individuals should report the incident to the bank, consider freezing the account, and lodge a complaint through the national cybercrime reporting portal.