Skip to content

April 7, 2026

How fraudsters fake proof of address (and how to catch them)

Proof of address is one of the easiest KYC checks to fake. Unlike a passport or national ID, a utility bill or bank statement doesn't have a chip, a hologram, or a tamper-evident security feature. It's a piece of paper with text on it. And anyone with Photoshop, a free PDF editor, or now even a chatbot can produce something that looks convincing at a glance.

For compliance teams, this creates a real problem. The document looks fine. The name matches. The address matches. The date is recent. A human reviewer skimming hundreds of files per day will accept it without a second thought. Meanwhile, the actual person behind the application doesn't live there at all.

This post breaks down the most common ways fraudsters fake proof of address documents, from low-effort Photoshop jobs to AI-generated bills, and the signals that reliably catch them.

The four levels of POA fraud

Not all fake documents are created equal. We see four broad categories, ranging from sloppy amateur jobs to sophisticated forgeries that pass casual inspection.

Level 1: Edit a real document

The most common fraud technique is also the simplest. The fraudster starts with a genuine document, often their own real utility bill or bank statement, and edits the name and address. Tools used: Photoshop, GIMP, Photopea (browser-based, free), or any PDF editor.

What they typically change:

The rest of the document, the issuer logo, the body text, the formatting, the fine print, stays untouched. From a few feet away it looks identical to a real bill.

Level 2: Use a template

One step up: the fraudster doesn't bother with a real document at all. They download a "fake utility bill template" from a shady site, fill in the blanks with the target name and address, and export to PDF. There's an entire underground market for these templates, organised by country and issuer.

Templates are easy to spot when you know what to look for. They tend to use generic placeholder text in the parts the fraudster didn't customise, and the formatting often doesn't match the actual issuer's current branding.

Level 3: AI-generated documents

This is the newest and fastest-growing category. Instead of editing a real document or using a template, the fraudster asks an AI image generator or large language model to produce a fake bill from scratch. The model generates plausible-looking text, formatting, and even fake logos.

AI-generated documents have two telltale weaknesses: subtle text artifacts that humans don't notice but pixel analysis can catch, and metadata that screams "generated by Stable Diffusion / DALL-E / Midjourney" if you know where to look.

Level 4: Real document, wrong person

The most insidious version: the document is completely real, just stolen. The fraudster obtained a genuine utility bill (often through phishing, data breaches, or buying it on the dark web) and uses it for identity theft. Address, name, issue date, everything checks out. But the person submitting it isn't the person on the document.

This category is the hardest to catch with document analysis alone, because the document itself is genuine. Catching it requires cross-referencing with other identity signals or detecting reuse across multiple applications.

How to catch faked documents

The good news: every category above leaves traces. The trick is knowing what to look for, and combining multiple signals so that even sophisticated forgeries get flagged.

Metadata analysis

Every PDF and image file carries metadata, hidden information about how it was created. Most fraudsters never think to clean it up, and even when they do, traces remain.

For PDFs:

For images:

Visual analysis

When metadata isn't enough (or has been carefully wiped), pixel-level analysis can still catch tampering:

Document classification

A surprisingly effective check: does the document actually claim to be the type of document it's supposed to be? Fraudsters sometimes submit retail receipts, loyalty card statements, or marketing letters and hope nobody notices. Automatically classifying the document type and rejecting anything that isn't a utility bill, bank statement, or government letter catches a lot of low-effort fraud.

Date validation

Many faked documents have stale dates that the fraudster forgot to update. Enforcing strict document age limits (typically 3 months) automatically rejects anything outside the window, regardless of how realistic it otherwise looks.

Cross-referencing identity signals

For the hardest cases, especially Level 4 (real documents, wrong person), document analysis alone isn't enough. You need to combine the POA check with other signals: device fingerprinting, IP geolocation, behavioural analysis, and cross-application matching to detect when the same document or address appears across multiple applications.

The reality of fraud detection

No single signal catches everything. A determined, technically skilled fraudster can produce a document with clean metadata, no visible Photoshop traces, the right document type, a plausible recent date, and a real-looking issuer. Catching this requires defence in depth: multiple independent checks that each catch different fraud patterns, combined with risk scoring and human review for edge cases.

The goal isn't to make fraud impossible. The goal is to make fraud expensive enough that it's no longer worth the effort for the vast majority of attempts, while raising the suspicion level on the minority that does get through.

How trusqo handles fraud detection

trusqo runs every uploaded document through multiple layers of analysis:

All findings are surfaced in a dedicated fraud analysis section of every verification result, with clear explanations of what was detected and why. Teams can configure the system to either flag suspicious requests for human review or auto-decline them, depending on their risk appetite.

Full API documentation is available at trusqo.com/docs.