Fake IDs: What the Market Looks Like Now, and What Actually Stops One
Fake IDs now range from borrowed real documents to AI-generated images designed for remote verification. The most effective controls compare the visible document data with machine-readable data and add checks that address genuine IDs used by the wrong person.

A fake ID is no longer only a crude counterfeit presented at a bar or border. For online businesses, the threat increasingly arrives as an image or video submitted during remote identity verification. That shifts the question from whether a document can be scanned to whether the document, its encoded data and the person presenting it all belong together.
The problem is material but should be kept in perspective. Veriff's Identity Fraud Report 2025 says document fraud accounted for 0.97 percent of verification attempts in North America in 2024. That is Veriff's measurement of its verification traffic, not an independent estimate of every fake ID in circulation. Still, the techniques behind those attempts are becoming cheaper to access and harder to separate from legitimate-looking submissions.
Three forms of document fraud
Fake-ID cases generally fall into three categories. They differ in what a verifier must detect and in whether the underlying credential is genuine.
- Borrowed genuine IDs: A real, unaltered document is presented by someone other than its rightful holder. This is widely described as the most common category because the credential can pass document-authenticity checks. The central question is whether the presenter matches the portrait and the claimed identity.
- Altered documents: A genuine document has had information, a portrait or another visible element changed. Some alterations are obvious; others are designed to preserve an apparently valid machine-readable record.
- Forged documents: The credential itself is fabricated or reproduced rather than issued by the named authority. Modern forgeries can imitate familiar layouts, fonts and data conventions well enough to defeat a simple front-of-document review.
Why a barcode scan is not a decision
A barcode reader can confirm that a code parses into plausible fields, but that is not the same as confirming that the document is authentic. PDF417, a two-dimensional barcode used on many North American driver licenses, and one-dimensional barcodes can contain data that appears internally consistent. A successful scan therefore establishes little more than that the reader found readable data.
Detection providers report that more than 60 percent of forged IDs they encounter look legitimate on the front and carry PDF417 or 1D barcode data that matches that visible front. One reason is that fraudsters can obtain a genuinely encoded credential and replace or reprint its visible front while retaining the barcode. Barcode-generation tools can also produce scannable codes that parse into valid-looking fields.
The important control is a cross-check: optical character recognition, or OCR, reads the name, date of birth, document number and other visible fields from the document image, then compares them with the barcode payload. A mismatch can expose a document whose front and encoded record were assembled from different sources. This is a more meaningful test than barcode readability alone, although it does not solve the borrowed-ID problem. A genuine document with matching fields can still be in the hands of the wrong person.
OnlyFake showed the remote-verification risk
The OnlyFake case put AI-generated identity images into sharper focus. Prosecutors said the service sold subscription access to generated document images that could pass some remote know-your-customer, or KYC, checks at banks and crypto exchanges. KYC is the process businesses use to establish a customer's identity before opening or maintaining an account.
Yurii Nazarenko, associated with the case, was extradited from Romania in September 2025, pleaded guilty and forfeited about $1.2 million, according to US prosecutors and court filings. The case did not establish that generated documents defeat every verification provider or every bank control. It did demonstrate that synthetic document images can be sold at scale and that weak remote workflows can be a viable target.
The market is moving, and so is enforcement
Generative AI is lowering the expertise needed to produce persuasive document images, iterate on rejected submissions and adapt layouts for digital channels. That does not make every suspicious image AI-generated, nor does it make traditional alteration and borrowing obsolete. Instead, it expands the supply of tools available to actors who already understand where verification processes are thin.
The response cannot be a single detector. Barcode-to-OCR comparison is a necessary safeguard against a common forged-document pattern. For higher-risk uses, organizations also need controls that test whether a real person is present and whether that person is the document holder, along with monitoring for repeat attempts and inconsistent account behavior. The OnlyFake prosecution also shows that enforcement is active rather than settled: the technical barrier is falling, while investigators and courts are still defining the practical limits of this newer fraud market.


