AePS: The easiest way to withdraw money without OTP.
The government had launched AePS (Aadhaar Enabled Payment System) for the convenience of the common people, especially in rural areas where there is less facility of ATM or internet. In this system, no OTP or bank account information is required for transactions.
All you need is your Aadhaar number and biometric (fingerprint or iris) scan. That is, if a cheater reaches these two things of yours, then he can withdraw your money without any hindrance. Recently, a similar case came to light in Bihar where Aadhaar details and fingerprints were stolen from government land records and swindled through AePS.
Surprisingly, no two-factor authentication (like OTP) is mandatory in this system yet, which makes it even more vulnerable.
APK Scam: When one click makes your phone a weapon of thugs
Another way to steal APK files is by using a malicious APK file. An APK (Android Package Kit) is a file that installs an application for an Android phone. The fraudsters send fake messages or links to people - such as "update your KYC," "pay gas bill," or "view traffic challan."
As soon as you click on this link, an APK file will be downloaded. Once installed, the app asks for access to your phone's SMS, call log, camera, and screen. Often people give all the permissions without reading - and then the thug gets full control of your phone. He can see your banking app, read OTP, and transact in your name.
Several cases of this scam have come to light, in which fraudsters have swindled more than Rs 43 crore. In one case, the fraudsters even tricked the antivirus by making the APK file "FUD" (Fully Undetected).
5 Easy Steps to Protect Yourself 1. Lock Your Aadhaar Biometric
The most effective way to avoid fraud through AePS is to lock your biometric by visiting the UIDAI website or m-Aadhaar app. Once locked, no one will be able to do any transaction using your biometric (fingerprint / iris).
Whenever you have to do the transaction yourself, you can unlock it temporarily. You can also get this facility through SMS.
Also, never share your Aadhaar number with any unknown person or online website. Use masked Aadhaar (in which the number is hidden) or Virtual ID (VID) if required.
Don't open any unknown link or APK file.
Never click on a link in an unknown SMS or WhatsApp message. If possible, delete such messages immediately. Never download an app from anywhere other than the Google Play Store or App Store.
Always turn off the "Install from Unknown Sources" option in your Android phone's settings. If someone has sent an APK file on the pretext of some work, then think twice before installing it.
Use 2FA for online banking.
Wherever possible, enable two-factor authentication (2FA) in your online accounts. This adds an extra layer of security, even if your password falls into someone else's hands. Read carefully all the transactions coming from the bank. In case of any unknown transaction, inform your bank immediately.
Don't share your personal information with anyone.
Remember - No bank will ever call you and ask for your card number, CVV, OTP or banking password.
If someone does this, then understand that he is a cheat. If a bank employee calls, put the phone down and call the bank's official helpline and ask if there is a genuine demand.
Avoid sharing your personal information on social media
Don't make your phone number, date of birth, or home address public on social media. Cyber fraudsters create your profile by collecting these small pieces of information and then carry out phishing attacks.
Keep your profile private and don't accept friend requests from strangers.
What to do if you are cheated?
If you get a cyber fraud, don't panic and take the following steps immediately:
Call your bank immediately and get your card / account blocked.
Register a complaint on the National Cyber Crime Reporting Portal (cybercrime. gov. in).
Call the Cyber Helpline number 1930.
Uninstall the malicious app from your phone and run an antivirus scan.
Conclusion
Cyber fraudsters are now all set to break your perception that your money is safe by not sharing the OTP. These methods of withdrawing money without OTP - AePS biometric fraud and malicious APK scam - are growing rapidly.
To avoid these, the most important thing is to lock your Aadhaar card biometrically, avoid opening any unknown link or file, and always be alert about online banking. The bank never asks for an OTP or password. Remember this always.
