April 7, 2026
How fraudsters fake proof of address (and how to catch them)
Proof of address is one of the easiest KYC checks to fake. Unlike a passport or national ID, a utility bill or bank statement doesn't have a chip, a hologram, or a tamper-evident security feature. It's a piece of paper with text on it. And anyone with Photoshop, a free PDF editor, or now even a chatbot can produce something that looks convincing at a glance.
For compliance teams, this creates a real problem. The document looks fine. The name matches. The address matches. The date is recent. A human reviewer skimming hundreds of files per day will accept it without a second thought. Meanwhile, the actual person behind the application doesn't live there at all.
This post breaks down the most common ways fraudsters fake proof of address documents, from low-effort Photoshop jobs to AI-generated bills, and the signals that reliably catch them.
The four levels of POA fraud
Not all fake documents are created equal. We see four broad categories, ranging from sloppy amateur jobs to sophisticated forgeries that pass casual inspection.
Level 1: Edit a real document
The most common fraud technique is also the simplest. The fraudster starts with a genuine document, often their own real utility bill or bank statement, and edits the name and address. Tools used: Photoshop, GIMP, Photopea (browser-based, free), or any PDF editor.
What they typically change:
- The recipient name and address block
- Sometimes the issue date if the original is too old
- Occasionally the account number, if it's visible
The rest of the document, the issuer logo, the body text, the formatting, the fine print, stays untouched. From a few feet away it looks identical to a real bill.
Level 2: Use a template
One step up: the fraudster doesn't bother with a real document at all. They download a "fake utility bill template" from a shady site, fill in the blanks with the target name and address, and export to PDF. There's an entire underground market for these templates, organised by country and issuer.
Templates are easy to spot when you know what to look for. They tend to use generic placeholder text in the parts the fraudster didn't customise, and the formatting often doesn't match the actual issuer's current branding.
Level 3: AI-generated documents
This is the newest and fastest-growing category. Instead of editing a real document or using a template, the fraudster asks an AI image generator or large language model to produce a fake bill from scratch. The model generates plausible-looking text, formatting, and even fake logos.
AI-generated documents have two telltale weaknesses: subtle text artifacts that humans don't notice but pixel analysis can catch, and metadata that screams "generated by Stable Diffusion / DALL-E / Midjourney" if you know where to look.
Level 4: Real document, wrong person
The most insidious version: the document is completely real, just stolen. The fraudster obtained a genuine utility bill (often through phishing, data breaches, or buying it on the dark web) and uses it for identity theft. Address, name, issue date, everything checks out. But the person submitting it isn't the person on the document.
This category is the hardest to catch with document analysis alone, because the document itself is genuine. Catching it requires cross-referencing with other identity signals or detecting reuse across multiple applications.
How to catch faked documents
The good news: every category above leaves traces. The trick is knowing what to look for, and combining multiple signals so that even sophisticated forgeries get flagged.
Metadata analysis
Every PDF and image file carries metadata, hidden information about how it was created. Most fraudsters never think to clean it up, and even when they do, traces remain.
For PDFs:
- Producer and Creator fields: a bank statement should be produced by a bank's document system, not by Photoshop or a PDF editing tool. If the Producer says "Adobe Photoshop CC 2024" on a Lloyds bank statement, that's a red flag.
- Creation vs modification dates: legitimate bank PDFs are generated once and never edited. If the modification date is days or weeks after the creation date, the file has been tampered with.
- Incremental updates: PDFs that have been edited contain multiple
%%EOFmarkers, one for each save. A clean original has exactly one. Two or more is a strong signal of post-creation edits. - Text layer mismatches: PDFs have both a visual layer (what you see) and a text layer (what computers read). When fraudsters paint over the name on the visual layer, the original name often remains in the text layer underneath.
For images:
- EXIF software tag: photos taken with a phone include the make and model of the camera. Photos exported from Photoshop, Photopea, GIMP, or AI generators include the software name. A "scanned" utility bill that has "Stable Diffusion" in its EXIF is obviously fake.
- Missing camera metadata: a real photo of a real document has sensor noise, EXIF data, and a consistent profile. A digital fabrication has none of that.
Visual analysis
When metadata isn't enough (or has been carefully wiped), pixel-level analysis can still catch tampering:
- Error level analysis (ELA): when a JPEG is edited and re-saved, the edited regions have a different compression history than the rest of the image. ELA highlights these inconsistencies. A pasted name block over a photographed bill will glow brightly compared to its surroundings.
- Block variance analysis: real photographed paper has natural texture and grain. Digitally pasted content (like a clean white rectangle covering the original name) has near-zero variance. Comparing variance across image regions reveals the pasted areas.
- Noise analysis: a real photograph has consistent sensor noise across the whole image. Inserted digital content doesn't, it's either suspiciously clean or has a completely different noise profile.
Document classification
A surprisingly effective check: does the document actually claim to be the type of document it's supposed to be? Fraudsters sometimes submit retail receipts, loyalty card statements, or marketing letters and hope nobody notices. Automatically classifying the document type and rejecting anything that isn't a utility bill, bank statement, or government letter catches a lot of low-effort fraud.
Date validation
Many faked documents have stale dates that the fraudster forgot to update. Enforcing strict document age limits (typically 3 months) automatically rejects anything outside the window, regardless of how realistic it otherwise looks.
Cross-referencing identity signals
For the hardest cases, especially Level 4 (real documents, wrong person), document analysis alone isn't enough. You need to combine the POA check with other signals: device fingerprinting, IP geolocation, behavioural analysis, and cross-application matching to detect when the same document or address appears across multiple applications.
The reality of fraud detection
No single signal catches everything. A determined, technically skilled fraudster can produce a document with clean metadata, no visible Photoshop traces, the right document type, a plausible recent date, and a real-looking issuer. Catching this requires defence in depth: multiple independent checks that each catch different fraud patterns, combined with risk scoring and human review for edge cases.
The goal isn't to make fraud impossible. The goal is to make fraud expensive enough that it's no longer worth the effort for the vast majority of attempts, while raising the suspicion level on the minority that does get through.
How trusqo handles fraud detection
trusqo runs every uploaded document through multiple layers of analysis:
- Metadata extraction: PDF Producer/Creator, creation and modification dates, revision count, fingerprints, embedded text presence, and image EXIF data including camera info and software signatures
- Suspicious software detection: highlights PDFs and images created or modified with editing tools (Photoshop, GIMP, Photopea, Canva, AI generators, PDF editors, and dozens more)
- PDF structure analysis: counts
%%EOFmarkers to detect incremental updates, compares creation and modification dates, and flags suspicious producers - Text layer mismatch detection: compares the visible content of a PDF against its embedded text layer to catch edits where the visual was changed but the underlying text wasn't
- Image forensic analysis: error level analysis, block variance analysis, and noise analysis to detect pasted regions and digital tampering in photographed documents
- Document type classification: automatically classifies documents and rejects anything that isn't an accepted type
- Configurable fraud actions: when tampering is detected, automatically flag the request for review or auto-decline it, based on your risk tolerance
All findings are surfaced in a dedicated fraud analysis section of every verification result, with clear explanations of what was detected and why. Teams can configure the system to either flag suspicious requests for human review or auto-decline them, depending on their risk appetite.
Full API documentation is available at trusqo.com/docs.