Your 12-digit Aadhaar number shows up in more places than almost any other piece of personal data you have — SIM registration, hotel check-ins, courier deliveries, gym memberships. Because it's requested so casually, it's easy to assume it's harmless to share, or to swing the opposite way and panic every time it's asked for. Both reactions skip the actual question: what can someone do with just the number?
What the number alone cannot do
- Your Aadhaar number by itself cannot be used to withdraw money from your bank account.
- It cannot be used to take out a loan in your name without additional authentication (biometric or OTP-based).
- It cannot be used to change your registered mobile number or address without further verification through UIDAI's process.
Aadhaar's authentication system is designed so the number is closer to a username than a password — it identifies you, but most sensitive actions require a second factor: your fingerprint/iris scan, or an OTP sent to your registered mobile number.
What actually is at risk
- Combined with other leaked data (name, date of birth, address, PAN), your Aadhaar number strengthens identity-theft attempts — applying for duplicate SIM cards, opening accounts using forged documents, or convincing a call-centre agent you're someone else.
- e-KYC misuse: in rare cases involving compromised biometric data or offline XML misuse, someone could complete e-KYC processes fraudulently — this is a biometric/document risk, not something caused by the number alone.
- Social engineering leverage: scammers use a correct Aadhaar number to sound credible on a phone call ("I have your Aadhaar details in front of me, sir") purely to build trust for a different scam — usually the actual theft happens through a fraudulent action you're pressured into taking, not through the number itself.
The mAadhaar Lock feature — the actual fix
UIDAI provides a genuinely effective tool for this: locking your Aadhaar biometrics. Once locked, no one can perform biometric authentication using your Aadhaar — including you — until you unlock it. This closes the one door that matters: fraudulent e-KYC or biometric-based transactions.
- Open the mAadhaar app (official UIDAI app) or visit the UIDAI website.
- Go to Aadhaar Lock/Unlock under the biometric settings.
- Lock your biometrics. You'll need your Aadhaar number and an OTP to do this — and to unlock it later if you need biometric authentication for something specific (like a SIM purchase).
- For everyday use, keep it locked and unlock only briefly when you specifically need biometric-based Aadhaar authentication.
Should you share your Aadhaar number when asked?
In most day-to-day situations — hotel check-in, SIM registration, courier ID checks — providing your Aadhaar is standard and required by regulation. The better question isn't "should I share the number" but "who's asking, and are they storing more than they need to." A few practical habits:
- Use the masked Aadhaar option when downloading your e-Aadhaar — it shows only the last 4 digits, sufficient for most identity checks where the full number isn't strictly necessary.
- For non-essential services asking for ID, prefer alternatives (driving licence, voter ID) when the request seems unnecessary for the transaction.
- Avoid posting photos of your physical Aadhaar card on social media, resale listings, or shared documents online — this is the most common way full Aadhaar numbers end up scraped in bulk.
If you're worried your Aadhaar has already been exposed
- Lock your biometrics immediately via mAadhaar, as described above.
- Check your Aadhaar authentication history (available on the UIDAI portal) for any authentication attempts you don't recognise.
- If you find unauthorised activity, file a complaint with UIDAI directly and with the National Cyber Crime Reporting Portal (cybercrime.gov.in) or call 1930.