Key Facts
- Trend: Viral “80s retro AI photo” trend using ChatGPT, Gemini and third-party apps
- Core Risk: Uploading a high-resolution selfie hands over a permanent biological identifier
- India Case 1: Ahmedabad Cyber Crime Branch busted an interstate gang (May 2026) that used AI-generated “eye-blinking” deepfake videos to bypass Aadhaar biometric authentication
- India Case 2: Kerala Police issued a public warning (September 2025) about viral Gemini AI photo trends including “Retro Saree” and “Hug My Younger Self”
- Legal Framework: DPDP Act, 2023 classifies biometric data as high-risk; IT Act Section 66C covers identity theft; BNS Sections 335 and 340 cover forgery of electronic records
- Enforcement Gap: DPDP Rules were notified on 13 November 2025, with full compliance due by 13 May 2027 — leaving a grey zone
Direct Answer
The viral “80s retro AI photo” trend is not just a privacy risk. It is a biometric data harvesting opportunity. When a user uploads a high-resolution selfie to an unverified app, they are handing over a permanent biological identifier.
In India, that identifier is directly linked to Aadhaar, DigiLocker, banking, and telecom authentication. The Ahmedabad deepfake Aadhaar fraud case (May 2026) proves that the chain from photo to loan fraud takes weeks, not years.
The Kerala Police advisory (September 2025) warned citizens about exactly this risk. Under the Digital Personal Data Protection Act, 2023, biometric data is classified as a high-risk category requiring verifiable consent and heightened safeguards.
However, with DPDP Rules notified only in November 2025 and full compliance due by May 2027, enforcement remains in a grey zone. The IT Act, 2000 (Section 66C) covers identity theft, and the BNS, 2023 (Sections 335 and 340) covers forgery of electronic records. But the regulatory infrastructure has not caught up with the speed of AI-powered fraud.
In this article:
- The “80s Retro AI Photo” Trend: What Users Are Doing
- Case 1: The Ahmedabad Deepfake Aadhaar Fraud (May 2026)
- Case 2: The Kerala Police Advisory (September 2025)
- The Legal Framework: DPDP Act, IT Act, and BNS
- The Enforcement Gap: Why the Law Hasn’t Caught Up
- Practical Steps for Users and Organisations
- FAQ
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police forces since 1996.
The “80s Retro AI Photo” Trend: What Users Are Doing
The viral “80s retro AI photo” trend has swept across Instagram and other social media platforms. Users upload high-resolution selfies to AI-powered tools — including ChatGPT, Gemini, and third-party apps — and receive nostalgic 1980s-style portraits in return.
The trend is emotionally engaging. It offers a fleeting moment of fun. But experts are flagging serious risks.
What Happens When You Upload
When you upload your photo, the AI companies are collecting your precise biometric data. This information could be used later to train other AI models. Scammers can also use these high-resolution AI pictures to create fake accounts. They might even use deepfake videos and images made from your face to carry out financial scams.
The Core Problem
Losing your password is inconvenient. Losing your facial geometry is permanent. Unlike passwords or email addresses, facial geometry cannot be changed once it is compromised. Exposed data can facilitate sophisticated deepfake attacks, unauthorised identity verification, and persistent tracking across digital ecosystems.
Global Regulatory Warnings
The Turkish Personal Data Protection Authority (KVKK) issued a formal warning on 10 September 2026, cautioning that third-party AI applications may process sensitive biometric data without adequate user protection or transparency. Al Jazeera and other Arab media outlets warned that the photograph users upload may contain far more valuable information than they realise.
Case 1: The Ahmedabad Deepfake Aadhaar Fraud (May 2026)
In May 2026, the Ahmedabad Cyber Crime Branch busted an interstate gang that used photographs harvested from social media platforms including WhatsApp, Facebook, and Instagram to create AI-generated “eye-blinking” deepfake videos.
The Modus Operandi
The gang’s process was a highly organised exploitation of digital vulnerabilities.
Step 1: Target Selection
Using platforms like MastersIndia and Peridot, the suspects obtained GST and PAN details of their targets. They used PAN details to download CIBIL reports from CRIF High Mark, allowing them to see registered mobile numbers and creditworthiness.
Step 2: Photo Harvesting
They collected victim photos from social media platforms including WhatsApp and Instagram.
Step 3: Deepfake Generation
Using AI platforms including Gemini and Meta AI, they generated “eye-blink” deepfake videos from static images. These AI-generated videos were then shown to Aadhaar UCL kits to trick “Live Face” verification.
Step 4: Identity Takeover
This allowed the gang to change the Aadhaar-linked mobile number to one in their possession — without the victim ever receiving an OTP. With the mobile number changed, they gained full access to the victim’s DigiLocker and opened accounts in various banks to apply for personal loans.
Step 5: Loan Fraud
The accused opened bank accounts at institutions including IDFC, Kotak Mahindra, and Jio Payments Bank. They applied for personal loans through multiple lending services, effectively saddling unsuspecting victims with substantial financial debt.
The Scale
According to police, the racket generated nearly ₹10 lakh to ₹15 lakh every year through fraudulent loans. Seven accused were arrested across Assam and Uttar Pradesh. The case was registered under the Bharatiya Nyaya Sanhita, 2023, and the IT Act.
The Single Photograph
Police said the gang’s methods were so sophisticated that even cyber experts were shocked during the investigation. The accused allegedly began by hunting for financially stable targets online. Using platforms such as Master India, they accessed GST and PAN details to check a victim’s CIBIL score and financial eligibility. Once a target was selected, the gang allegedly turned to Telegram bots and other digital tools to collect Aadhaar-linked information and photographs from social media accounts.
That single photograph became the gateway to the fraud.
The fake videos were then allegedly used to bypass Aadhaar-linked biometric and online authentication systems. Within minutes, the victim’s registered mobile number would be changed. And once that happened, the gang effectively took over the victim’s digital identity.
How It Was Exposed
The operation finally unravelled after a businessman from Ahmedabad suddenly stopped receiving OTPs connected to his Aadhaar-enabled payment system. Initially, he believed it was a technical glitch. But the truth was far more alarming. Investigators later discovered that his Aadhaar-linked mobile number and biometric details had already been changed — allegedly without any OTP verification at all. Loans had also been taken in his name.
Case 2: The Kerala Police Advisory (September 2025)
On 19 September 2025, the Kerala Police issued a public warning urging citizens to exercise caution while using artificial intelligence tools to edit or enhance personal photographs.
What the Advisory Said
The advisory came in response to a growing wave of AI-generated content flooding social media, where users were increasingly submitting their own images to third-party platforms for stylisation. According to the police, such practices may expose individuals to privacy violations, impersonation or misuse of their likeness in cybercrimes.
The Trends Flagged
The advisory followed the viral popularity of several AI-driven visual trends powered by Gemini’s Flash 2.5 model:
- “Hug My Younger Self”: Uses AI to generate composite images of users embracing their childhood selves
- “Retro Saree”: Users appear in hyper-stylised edits featuring vintage sarees, soft lighting, and cinematic backgrounds
The Police’s Warning
Citizens who suspect misuse or become victims are advised to report incidents immediately via the national cybercrime helpline 1930 or through the portal cybercrime.gov.in. The department emphasised the need for responsible use of AI, especially when dealing with sensitive personal data.
The advisory aimed to raise awareness not just about immediate risks, but about the long-term implications of surrendering biometric data to unregulated platforms.
The Legal Framework: DPDP Act, IT Act, and BNS
Digital Personal Data Protection Act, 2023
Under the DPDP Act, biometric data is classified as a high-risk category requiring verifiable consent and heightened safeguards. For high-risk categories — including biometrics and financial data — special safeguards apply, including verifiable consent and DPO obligations. Organisations must map purpose, obtain valid consent, and ensure retention limitation.
Section 66C of the IT Act, 2000
Section 66C covers identity theft. Whoever, fraudulently or dishonestly makes use of the electronic signature, password, or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to ₹1 lakh.
Sections 335 and 340 of the BNS, 2023
Section 335 of the BNS defines making a false document or false electronic record. Section 336 covers forgery. Section 340 covers forgery of electronic records.
The DPDP Rules, 2025
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. The rules define materiality for breach reporting: breaches affecting over 1,000 individuals, resulting in financial loss exceeding ₹1,000-5,000 per individual, or exposing sensitive data categories (health, financial, biometric) must be reported.
Full compliance is due by 13 May 2027.
The Enforcement Gap: Why the Law Hasn’t Caught Up
The Regulatory Grey Zone
As of September 2026, the DPDP Rules have been notified but full enforcement is not yet in place. The phased rollout means that while the framework exists on paper, the regulatory infrastructure has not caught up with the speed of AI-powered fraud.
The Consent Problem
How do you enforce consent when the device records without the bystander’s knowledge? The DPDP Act’s consent requirement is meaningless if the data subject doesn’t know their biometric data is being harvested.
The Platform Problem
Many of the tools being used for this trend are developed by obscure entities with unknown server locations. There is little guarantee that the biometric data extracted during the image rendering process remains private. In many cases, these facial maps could be repurposed for training unauthorised AI models, sold to third-party data brokers, or stored indefinitely in insecure databases.
The Attribution Problem
Even when fraud is detected, attributing it to a specific AI platform or developer is difficult. The Ahmedabad gang used multiple AI platforms — Gemini, Meta AI, and others — making it hard to pin liability on any single provider.
Practical Steps for Users and Organisations
For Users
- Stick to trusted tools: Use only well-established, global AI services with transparent data management practices
- Deny unnecessary permissions: Verify which permissions an app requests before proceeding
- Avoid uploading childhood photos: These are high-value biometric data that cannot be changed
- Turn off metadata: Before uploading, turn off metadata in your pictures
- Lock your Aadhaar biometrics: Use the mAadhaar app or the official UIDAI website to lock biometric data, which prevents unauthorised fingerprint, iris, or facial authentication
- Use masked Aadhaar: Use masked Aadhaar copies that only display the final four digits
- Never share OTPs: Do not share OTPs with anyone claiming to be an official
For Organisations
- Update privacy policies: Ensure biometric data is classified as high-risk and requires verifiable consent
- Conduct DPIAs: Data Protection Impact Assessments for any processing of biometric data
- Implement retention limits: Do not store biometric data longer than necessary
- Train employees: On the risks of AI-powered biometric harvesting
If You Suspect Fraud
- Call the National Cyber Crime Helpline at 1930
- File a complaint at cybercrime.gov.in
- Notify your bank branch
- Document all communications and transaction records
FREQUENTLY ASKED QUESTIONS (FAQ)
What is the “80s retro AI photo” trend?
The trend involves users uploading high-resolution selfies to AI-powered tools to receive nostalgic 1980s-style portraits. It has gone viral on Instagram and other social media platforms.
Why is it a privacy risk?
When you upload your photo, AI companies collect your precise biometric data. This information can be used to train unauthorised AI models, sold to third-party data brokers, or stored indefinitely in insecure databases.
What happened in the Ahmedabad deepfake Aadhaar fraud case?
A gang used AI-generated “eye-blinking” deepfake videos created from social media photos to bypass Aadhaar biometric authentication, change registered mobile numbers, and take out instant personal loans in victims’ names. Seven accused were arrested.
How did the gang operate?
They harvested photos from WhatsApp and Instagram, used AI platforms including Gemini and Meta AI to generate “eye-blink” deepfake videos, showed these videos to Aadhaar UCL kits to trick “Live Face” verification, changed the Aadhaar-linked mobile number, and then accessed DigiLocker and opened bank accounts.
What did the Kerala Police advisory say?
The Kerala Police warned citizens about the privacy risks of viral Gemini AI photo trends including “Retro Saree” and “Hug My Younger Self,” urging caution when submitting personal photographs to third-party platforms.
What does the DPDP Act say about biometric data?
Under the DPDP Act, 2023, biometric data is classified as a high-risk category requiring verifiable consent and heightened safeguards.
What does Section 66C of the IT Act cover?
Section 66C covers identity theft — fraudulently or dishonestly making use of the electronic signature, password, or any other unique identification feature of another person. Punishment extends to three years imprisonment and fine up to ₹1 lakh.
What do Sections 335 and 340 of the BNS cover?
Section 335 defines making a false document or false electronic record. Section 340 covers forgery of electronic records.
When do the DPDP Rules come into full force?
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. Full compliance is due by 13 May 2027.
What can users do to protect themselves?
Use only trusted AI tools, deny unnecessary permissions, avoid uploading childhood photos, turn off metadata, lock Aadhaar biometrics using the mAadhaar app, use masked Aadhaar, and never share OTPs.
How do I lock my Aadhaar biometrics?
Use the official mAadhaar app or the UIDAI portal to lock your biometrics. This prevents unauthorised fingerprint, iris, or facial authentication.
What should I do if I suspect fraud?
Call the National Cyber Crime Helpline at 1930, file a complaint at cybercrime.gov.in, notify your bank branch, and document all communications.
Q: Why is losing facial geometry more dangerous than losing a password or email address?
Ans: Passwords and email addresses can be easily changed when compromised; facial geometry is a permanent biological identifier that, once harvested, can be persistently tracked and exploited across digital ecosystems.
Q: What specific legal provisions cover identity theft and electronic forgery in India?
Ans: Section 66C of the Information Technology Act, 2000, covers identity theft, while Sections 335 and 340 of the Bharatiya Nyaya Sanhita (BNS), 2023, cover the forgery of electronic records.
Q: What practical steps can individuals take to protect their Aadhaar data from biometric fraud?
Ans: Users should lock their Aadhaar biometrics using the official mAadhaar app or UIDAI portal, use masked Aadhaar copies showing only the final four digits, and avoid sharing high-resolution self-portraits with unverified apps.
Q: What warning did the Kerala Police issue regarding AI photo trends in September 2025?
Ans: The Kerala Police warned citizens that submitting personal photographs to viral AI tools like “Retro Saree” and “Hug My Younger Self” exposes individuals to privacy violations, impersonation, and cybercrime misuse.
Explore More:
Read my blog: Shoeb Hakim Blog
Book Now: Book a Consultation
Contact: Contact Adv. Shoeb Hakim
Careers: Careers at Shoeb Hakim
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
#AdvShoebHakim #BiometricRisk #DeepfakeFraud #AadhaarSecurity #DPDPAct #WhiteCollarCrime #DigitalForensics #LegalDefense #Compliance #CyberSecurity



Leave a Reply