Skip to content
Case studiesPricingSecurityCompareBlog

Europe

Americas

Oceania

Data10 min read

Document Fraud-as-a-Service: AI Fake Document Generators

Document fraud-as-a-service lets anyone buy AI-generated payslips, bank statements and IDs online in minutes. How the marketplaces work and how to detect them.

CheckFile Team
CheckFile Teamยท
Illustration for Document Fraud-as-a-Service: AI Fake Document Generators โ€” Data

Summarize this article with

Document fraud-as-a-service is a business model in which fraudsters sell ready-made, AI-generated fake documents โ€” payslips, bank statements, ID cards, invoices, proof of address โ€” via websites and Telegram channels. Buyers need no design skill: they pick a template, enter a name and figures, and receive a convincing file within minutes for a few pounds. This industrialises forgery in a way isolated Photoshop edits never could, because the same infrastructure serves thousands of buyers at once.

This article is provided for informational purposes. Regulatory requirements evolve โ€” consult the FCA or a qualified adviser for your specific situation.

What is document fraud-as-a-service?

Document fraud-as-a-service is the commercial packaging of forgery tools and templates into a paid product, sold on demand regardless of technical skill. Instead of a single forger manually editing one file, an operator builds a catalogue โ€” payslip layouts for major UK employers, bank statement formats matching High Street banks, ID card designs for dozens of countries โ€” and lets customers self-serve through a website or bot.

The model mirrors legitimate software-as-a-service: pick a document type and issuer, submit the details to print on it, pay by card or crypto, and receive the file near-instantly. Prices are usually low enough to make the transaction disposable, which removes cost as a natural deterrent.

Sites such as Doc Juicer illustrate the scale of the approach, offering more than 200 ready-made pay stub templates, according to resistant.ai. A buyer does not need to know what a genuine payslip from a given company looks like โ€” someone else already built and tested the template. The same pattern repeats for bank statements, proof-of-address letters and identity documents, sold through websites, marketplaces and closed Telegram groups.

How AI generators and Telegram kits work technically

The pipeline behind these services combines several generative techniques, each suited to a different part of the document. Large language models produce coherent text and figures: job titles matching a stated employer, addresses resolving to real postcodes, transaction narrative reading like a genuine bank statement rather than placeholder text. Template PDFs โ€” often reverse-engineered from genuine documents โ€” provide the visual scaffold: logos, fonts, layout grids, security-style watermarks. Generative adversarial networks and diffusion models handle the hardest part for identity documents: synthesising a photorealistic face and micro-print on an ID card or passport page that belongs to no real institution.

The most consequential case study is OnlyFake, a fake-ID generator that used exactly this combination to produce convincing driving licences and identity cards. US federal authorities shut the site down in February 2026 and pursued a criminal case against its operator, Yurii Nazarenko โ€” background from resistant.ai and ftxidentity.com. The takedown did not end the market: a near-identical service reopened within weeks as MacDoc, reusing the same templates โ€” evidence that shutting one storefront barely dents the underlying supply.

Telegram is the preferred distribution channel: encrypted messaging, easy payment handling, searchable group discovery. Researchers identified 22 public Telegram channels and groups, in Chinese, Vietnamese and English, openly advertising tools to bypass know-your-customer checks at major institutions including Binance, BBVA and Revolut, according to tech-insider.org. These toolkits go beyond static documents: virtual webcam software injecting a synthetic video feed, stolen biometric templates, and deepfake video generators built to defeat liveness checks. Fraud-as-a-service has expanded from document forgery into live-verification evasion โ€” a materially harder problem to solve with document review alone.

Document types, techniques and detection signals

The table below summarises the main document categories sold through these services, the generation technique used, indicative pricing, and the detection signal verification systems look for.

Document type AI technique used Typical price / turnaround Detection signal
Payslips LLM-generated figures on template PDFs ยฃ5โ€“ยฃ15, minutes Inconsistent tax/NI arithmetic, font mismatches
Bank statements Template plus LLM-generated transaction narrative ยฃ10โ€“ยฃ25, minutes to hours Balances that don't reconcile, recent creation metadata
ID documents (cards, licences) GAN/diffusion-generated photos, security features ยฃ20โ€“ยฃ80, hours to 1โ€“2 days Synthetic micro-print, no matching issuing-authority record
Invoices LLM-generated line items on branded templates ยฃ5โ€“ยฃ20, minutes Supplier details mismatched with registry records
Proof of address Template with address/name substitution ยฃ10โ€“ยฃ20, minutes Layout drift from provider's house style, mismatched dates

None of these signals is decisive alone โ€” fraud-as-a-service templates are built to satisfy the checks a busy reviewer runs informally. Detection depends on several signals together, not one visual cue.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

Why manual and visual review no longer works

A document produced by a fraud-as-a-service template is designed to pass a glance: the logo is correctly placed, the font is close enough, the numbers add up on first inspection. That is the point of selling a template rather than a one-off forgery โ€” it has already been tuned to defeat the review process most organisations use.

According to the ACFE 2024 Report to the Nations, only 37% of document fraud is caught through direct human review. In the UK, AI-generated synthetic documents now represent 12% of all detected fraud, a category that registered close to zero three years ago, according to lettingagenttoday.co.uk. Within the same dataset, fake payslips account for 31% of detected tenant-fraud cases, falsified proof-of-address for 22%, and counterfeit ID documents for 19% โ€” the document types most requested by letting agents and lenders are also the most heavily targeted.

Cifas, the UK's not-for-profit fraud prevention body, recorded a record 444,000 fraud cases in 2025, with AI-enabled scams a major contributor, according to bynn.com. A reviewer trained to spot amateur Photoshop work โ€” misaligned text, mismatched fonts, cloning artefacts โ€” is not equipped to catch a document generated end-to-end by a model trained on thousands of genuine examples. See our explainer on how generative tools produce convincing fake paperwork for more on the underlying methods.

What compliance teams are asking

Compliance teams on industry forums often ask how to keep pace when the threat is a moving target โ€” new templates, generators and storefronts appear faster than any checklist can be updated. A recurring frustration is that a document can pass every visual check a junior reviewer knows to run, yet still be entirely synthetic.

Letting agents raise a related concern: with payslips and proof-of-address letters representing over half of detected tenant fraud, several ask whether it is still reasonable to rely on a document upload at all. Onboarding teams at fintechs and banks ask a version of the same question about live verification โ€” given that some fraud-as-a-service kits now include virtual webcam and deepfake tools aimed at KYC video checks, is a liveness check still reliable alone, or does it need pairing with document-level signals.

The shared thread is less about any single tool and more about process: teams want automated signals layered under human judgement, so a decision rests on structural and forensic checks rather than how a document looks. Our checklist of signs a document may be AI-generated gives reviewers concrete indicators for an intake process.

Multi-layer detection: beyond the visual check

Effective detection against templated fraud combines several independent layers, so a document has to pass all of them, not just one.

Metadata analysis examines the file itself โ€” creation and modification timestamps, software signatures embedded in the PDF, inconsistencies between a claimed issue date and the actual production history. A payslip supposedly issued eighteen months ago carrying metadata showing it was created yesterday is an immediate red flag, regardless of how convincing the layout is.

Cross-document validation checks a submitted document against other available data points: does the employer named on a payslip actually exist, does an address on a proof-of-address letter match records held elsewhere, do the figures on a bank statement reconcile internally. This catches the errors template generation tends to introduce when the underlying data was invented rather than pulled from a genuine source.

Machine-learning forensic signals look for the statistical fingerprints generative models leave behind โ€” artefacts in font rendering, unnatural pixel-level patterns around security features, structural inconsistencies invisible to the eye but detectable computationally. This is where platforms like CheckFile fit into an existing verification stack: CheckFile adds detection of synthetic content as a complement to the structural and consistency checks compliance teams already run, rather than replacing them. No single layer catches every forgery, and no vendor should claim otherwise โ€” the value comes from stacking independent checks so a document engineered to pass one test still has to clear the others.

CheckFile's approach to document security and verification infrastructure supports banking and KYC workflows and real estate and letting agent screening.

Firms in scope of the Money Laundering Regulations 2017 (as amended in 2019) are expected by the FCA to apply risk-based customer due diligence, meaning identity and supporting documents must be verified as genuine, not merely present. A firm that accepts an AI-generated payslip or bank statement without adequate checks can be in breach even where the fraud was not detected, because the regulatory expectation concerns the adequacy of the control, not the outcome of any single case.

On the criminal side, submitting a fabricated document to obtain a benefit โ€” a tenancy, a loan, an account, a job โ€” typically falls under the Fraud Act 2006 as fraud by false representation, where a person dishonestly makes a false representation intending to make a gain or cause a loss. This applies to both the person submitting the document and, in some circumstances, an operator running the platform that supplied it.

The reporting process is also changing: Action Fraud, the UK's long-standing national fraud reporting service, is being phased out from 2026 in favour of a new Report Fraud service, so compliance teams should update incident-response documentation to reflect the new channel.

None of this removes the need for proportionate, well-evidenced verification โ€” regulatory expectations and criminal liability both assume firms apply reasonable, documented checks rather than relying on a document simply "looking right." Extending existing controls with AI-generation signals as a complement to your existing controls is one practical way to close that gap โ€” see CheckFile's deepfake and AI document detection capability.

Frequently Asked Questions

What is document fraud-as-a-service?

A business model where fraudsters sell ready-made, AI-generated fake documents โ€” payslips, bank statements, ID cards, invoices โ€” through websites or Telegram channels, delivered within minutes for a small fee and requiring no design skill from the buyer.

How is this different from someone editing a document in Photoshop?

A Photoshop edit is a one-off effort limited by the skill of the person doing it. Fraud-as-a-service packages the forgery into a reusable template sold to many buyers, so the same quality bar scales to thousands of transactions.

Can these AI-generated documents be detected?

Many can be, but not through visual review alone. Metadata analysis, cross-document validation and machine-learning forensic checks each catch signals a human eye typically misses, particularly when templates are built to pass a casual check.

What should a UK business do if it suspects it received a fraudulent document?

Follow the internal escalation process, retain the file and metadata as evidence, and report through the UK's Report Fraud service, which is replacing Action Fraud from 2026. Regulated firms should also review whether the incident points to a gap in existing due diligence controls.

Does using a detection tool like CheckFile guarantee fraud will be caught?

No tool can guarantee every forgery will be caught, and any vendor claiming otherwise should be treated with caution. CheckFile adds AI-generation detection signals as a complement to a firm's existing controls, strengthening a layered process rather than replacing human judgement.

This article is for general informational purposes and does not constitute legal or regulatory advice. For a broader overview of the fraud data landscape, see our fraud data guide, and consult the FCA or a qualified adviser for guidance specific to your organisation.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.