Identity data harm
Stolen KYC Data Harm
Stolen KYC data can turn a citizen identity into reusable fraud infrastructure. The research framing treats the harm as identity exposure, financial risk and governance accountability.
Public-interest questions
- Which authority, platform or intermediary collected the identity data?
- What evidence shows exposure, misuse or attempted misuse?
- Was the affected person given a correction, deletion, recovery or complaint pathway?
- Can the same data be used repeatedly against the person after one case is closed?
Evidence limits
This archive should not publish raw identity documents or expose private victim data. Public pages should use redaction, source labels and a clear separation between filed allegations and verified findings.
What KYC data contains and why it is valuable to fraudsters
Know Your Customer (KYC) data in India typically comprises a combination of identity documents and biometric credentials: Aadhaar number and linked biometric, PAN card, passport, voter ID, bank account number, mobile number, address proof and photograph. This data set is collected by banks, telecom operators, financial intermediaries, government portal registrations and e-commerce platforms as a condition of service. Once a fraudster obtains a complete or partial KYC data set, they possess the keys to impersonate the affected citizen across multiple financial and government systems. A stolen KYC data set is therefore not a one-time loss; it is a durable fraud asset that can be reused months or years after the initial exposure.
Digital arrest fraud frequently involves a KYC-theft component. The fraudster, posing as a law-enforcement officer, demands that the victim share their Aadhaar, PAN or bank details as part of a fictitious verification process. Alternatively, the victim may already have had their KYC data stolen from a breached database, and the fraudster is using that pre-existing knowledge of personal details to make the impersonation more convincing. In either scenario, the KYC data becomes the foundation for continued exploitation after the initial call has ended.
Downstream harms from stolen KYC data
The harm from stolen KYC data extends well beyond the immediate fraud incident. Stolen Aadhaar-linked credentials can be used to open bank accounts, obtain SIM cards or register mobile payment wallets in the victim's name — all of which can then be used as fraud conduits in subsequent crimes, potentially exposing the victim to secondary law-enforcement inquiries. A stolen PAN number can be used to file false tax returns or create shell-company director records. A stolen bank account number, combined with other KYC details, can support social-engineering attacks against the victim's bank on the pretext of account recovery. The governance accountability dimension of this harm is significant: each of these downstream uses involves a system — banking, telecommunications, tax administration — that should have verification controls capable of detecting the fraudulent use. When those controls fail, the public-interest question is which authority is responsible for the failure and what remedy is available to the affected citizen.
The KYC data trail as evidence
For research and legal purposes, the KYC data trail itself can become evidence. When a victim can demonstrate that their KYC information was used in a transaction, registration or account opening that they did not authorise, that demonstration is a source-backed showing of identity theft. The DISHA archive treats such documentation as a verified record when it is supported by a bank statement, telecom operator confirmation, tax authority record or government portal log. The victim's account of what data was shared and when is treated as a documented allegation until it is corroborated. The gap between what happened to the stolen data and what public authorities did in response is recorded as an unresolved question pending disclosure or complaint resolution.