A selfie match is not a certificate of authenticity for the file beside it. Deepfake document fraud is the use of generative AI to create or alter IDs and supporting documents for deception. A convincing face or consistent name does not prove the document came from its claimed issuer. Detection needs document authentication alongside checks on the applicant.
This is more than a hypothetical gap. In its April 2025 risk guidance, the UK Gambling Commission warned of increasingly sophisticated attempts to bypass customer due diligence using false documentation, deepfake videos and AI-generated face swaps. The point is not to abandon liveness. It is to stop asking it to answer a document question.
What deepfake document fraud means
We use the term here for AI-generated or AI-altered documents, not just video impersonation. An ID image can be fabricated, a photograph replaced or a supporting statement invented. These are different attacks, even when they arrive in the same application.
The distinction matters because a document image and an original digital PDF offer different evidence. A photograph of a passport does not contain the passport issuer’s PDF object structure. Wrapping that photograph in a PDF does not create it.
Nor does a picture of a hologram establish that the physical security feature exists. Treat the visible design as something to inspect, not as proof of authenticity. NIST’s identity-proofing guidance separates evidence validation, including checks for counterfeiting and security features, from verification that the evidence belongs to the applicant.
There is also a statistical trap here. Sumsub’s November 2024 report announcement reported a fourfold increase in deepfakes detected worldwide from 2023 to 2024. That is a vendor-reported detection trend, not a measured growth rate for AI-generated bank statements or every business’s exposure. It does not tell you the share of documents in your own queue that are fake.
What the $15 fake ID story actually showed
In February 2024, 404 Media investigated OnlyFake, a service advertising realistic fake ID images for $15. The outlet generated documents in its tests and reported using one to complete an identity-verification process on the cryptocurrency exchange OKX.
That is a concrete example of a verification failure. It is not evidence that every exchange could be bypassed, that the service still works today or that a $15 image reproduces genuine physical security features.
OnlyFake claimed to use neural networks. Keep that attribution attached: the seller’s description is not independent verification of how its generation system worked. The important observed result was a fabricated ID image passing a particular verification flow.
The story should change the question you ask your provider. Instead of “Do you use AI?”, ask: “Which document-authentication controls would have challenged this submission, and what happens when the file offers too little evidence?”
Why liveness and document authentication are different checks
A liveness check evaluates whether the biometric capture represents a live person rather than a spoof. Face matching evaluates whether the captured face matches the reference image. Document authentication evaluates the evidence itself. Passing one does not establish the other two.
NIST’s guidance on forged media and digital injection describes attacks that combine generative AI with injection of modified images or videos into remote identity-proofing processes. It treats these as risks to document validation, biometric operations and visual comparison, not as a problem one selfie test resolves.
Consider an illustrative case: an applicant submits a fabricated ID bearing their own real face. The selfie may genuinely be live and may match that photograph. The unresolved question is whether the ID was issued at all. No face swap is necessary for that particular document attack.
This does not mean a complete KYC system ignores documents. Providers can combine biometric checks with document validation and other controls. The gap appears when a team treats a successful selfie result as sufficient evidence for the entire application, including income and address documents.
Our broader article on why ID verification needs supporting-document checks covers that workflow problem. Here, the narrower issue is what AI fabrication changes about the evidence you receive.
What file-level forensics can add
For a digital bank statement or payslip, ask for the original PDF rather than a screenshot placed inside a new PDF. For an identity document, use the appropriate image capture and document-authentication process. Do not expect the same forensic signals from both.
VerifyPDF’s documented checks include template matching where reference data is available, content consistency, file-origin signals and machine-learning analysis of the visible document and PDF structure. Its explanation of fraud flags and risk indicators also makes an important distinction: a warning is a reason to investigate, not a verdict.
For synthetic document detection, the practical questions are:
- Does the file’s origin and structure fit the document it claims to be?
- Does its layout match relevant issuer examples where those are available?
- Do dates, totals and other details make sense together?
- Is there enough evidence to support a decision, or should the reviewer request a better source?
A producer string is a clue, not a confession. Missing metadata is not proof of fraud. A neat image is not proof of authenticity either. We would rather show a reviewer the reasons for concern than pretend one field settles the case.
If your process stops at face matching, compare it with VerifyPDF’s document fraud detection workflow. The page explains the separate document-analysis layer, so you can assess where it belongs alongside your existing identity checks.
Where detection still falls short
File-level forensics is not a universal deepfake detector. A freshly generated document may lack the editing history of a manipulated original. An image-only submission offers different evidence from an issuer-generated PDF. Neither limitation is solved by changing the file extension.
A consistent package can still be fabricated. Compare names, addresses and financial details across submissions, but do not mistake agreement for independent confirmation. Where the decision warrants it, seek evidence from the issuer or an authoritative source rather than relying entirely on applicant-supplied files.
There are false positives too. Legitimate re-saving or editing can trigger warnings, as VerifyPDF’s fraud-flag documentation explains. Review the reasons, account for the submission format and give legitimate applicants a route to supply better evidence.
Deepfake identity verification therefore needs layered controls: evidence validation, biometric verification and protection against forged-media injection where relevant. A document-analysis result does not establish that a person exists, owns an account or is entitled to the income shown. Those remain separate questions.
Check the file before trusting the application
The useful lesson from AI-generated fake IDs is not that KYC is defeated. It is that a plausible document, a matching selfie and an authentic issuer record are different things. Your review process should make those distinctions explicit.
Open the VerifyPDF interactive demo to inspect sample document results, risk indicators and metadata before deciding what to add to your workflow. Start with the evidence your current checks do not examine, not another promise that every fake will be caught.