Skip to content
Case studiesPricingSecurityCompareBlog

Europe

Americas

Oceania

Data12 min read

Document Fraud-as-a-Service: AI Fake Documents in Australia

AI generators and Telegram kits now sell fake payslips, bank statements and IDs on demand. How fraud-as-a-service works and what it means for Australian firms.

CheckFile Team
CheckFile Teamยท
Illustration for Document Fraud-as-a-Service: AI Fake Documents in Australia โ€” Data

Summarize this article with

Document fraud-as-a-service is a business model in which fraudsters sell ready-made, AI-generated fake documents โ€” payslips, bank statements, ID documents, invoices, proof of address โ€” through websites and Telegram channels. Buyers need no design skill: they choose a template, enter a name and figures, and receive a convincing file within minutes for a few dollars. This industrialises forgery in a way individual edits in Photoshop never could, because the same storefront serves thousands of buyers at once.

This article is provided for informational purposes. Regulatory requirements evolve โ€” consult AUSTRAC guidance or a qualified compliance adviser for your specific situation.

What is document fraud-as-a-service?

Document fraud-as-a-service is the commercial packaging of forgery tools and templates into a paid product, sold on demand regardless of technical skill. Instead of one forger manually editing a single file, an operator builds a catalogue โ€” payslip layouts for major Australian employers, bank statement formats matching the big four banks, ID templates covering dozens of countries โ€” and lets customers self-serve through a website or bot.

The model mirrors legitimate software-as-a-service: pick a document type and issuer, submit the details to print on it, pay by card or crypto, and receive the file almost instantly. Prices are usually low enough to make the transaction disposable, which removes cost as a natural deterrent.

Sites such as Doc Juicer illustrate the scale of the approach, offering more than 200 ready-made pay stub templates, according to resistant.ai. A buyer does not need to know what a genuine payslip from a given employer looks like โ€” someone else already built and tested the template. The same pattern repeats for bank statements, proof-of-address letters and identity documents, sold through websites, marketplaces and closed Telegram groups reaching Australian buyers as easily as anyone else.

How AI generators and Telegram kits work technically

The pipeline behind these services combines several generative techniques, each suited to a different part of the document. Large language models produce coherent text and figures: job titles matching a stated employer, addresses resolving to real postcodes, transaction narrative reading like a genuine bank statement rather than placeholder text. Template PDFs โ€” often reverse-engineered from genuine documents โ€” provide the visual scaffold: logos, fonts, layout grids, security-style watermarks. Generative adversarial networks and diffusion models handle the hardest part for identity documents: synthesising a photorealistic face and micro-print on a driver licence or passport page that belongs to no real person.

The most consequential case study is OnlyFake, a fake-ID generator that used exactly this combination to produce convincing driver licences and identity cards. US federal authorities shut the site down in February 2026, but the takedown did not end the market: a near-identical service reopened within weeks as MacDoc, reusing the same templates โ€” evidence that closing one storefront barely dents the underlying supply, according to resistant.ai.

Telegram remains the preferred distribution channel: encrypted messaging, easy payment handling, searchable group discovery. Researchers identified 22 public Telegram channels and groups, in Chinese, Vietnamese and English, openly advertising tools to bypass know-your-customer checks at major institutions including Binance, BBVA and Revolut, according to tech-insider.org. These toolkits go beyond static documents: virtual webcam software injecting a synthetic video feed, stolen biometric templates, and deepfake video generators built to defeat liveness checks. Fraud-as-a-service has expanded from document forgery into live-verification evasion โ€” a materially harder problem to solve with document review alone, and one increasingly relevant to Australian exchanges, lenders and banks running remote onboarding.

Document types, techniques and detection signals

The table below summarises the main document categories sold through these services, the generation technique used, indicative pricing, and the detection signal verification systems look for.

Document type AI technique used Typical price / turnaround Detection signal
Payslips LLM-generated figures on template PDFs AU$8โ€“$25, minutes Inconsistent tax/super arithmetic, font mismatches
Bank statements Template plus LLM-generated transaction narrative AU$15โ€“$40, minutes to hours Balances that don't reconcile, recent creation metadata
ID documents (passports, licences) GAN/diffusion-generated photos, security features AU$30โ€“$120, hours to 1โ€“2 days Synthetic micro-print, no matching issuing-authority record
Invoices LLM-generated line items on branded templates AU$8โ€“$30, minutes Supplier details mismatched with ASIC registry records
Proof of address Template with address/name substitution AU$15โ€“$30, minutes Layout drift from provider's house style, mismatched dates

None of these signals is decisive alone โ€” fraud-as-a-service templates are built to satisfy the checks a busy reviewer runs informally. Detection depends on several signals together, not one visual cue.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

Why manual and visual review no longer works

A document produced by a fraud-as-a-service template is designed to pass a glance: the logo is correctly placed, the font is close enough, the numbers add up on first inspection. That is the point of selling a template rather than a one-off forgery โ€” it has already been tuned to defeat the review process most organisations use.

According to the ACFE 2024 Report to the Nations, only 37% of document fraud is caught through direct human review globally. Australia's own data points in the same direction. In May 2026, AUSTRAC โ€” Australia's financial intelligence and regulatory agency โ€” issued a money-laundering update warning that AI is increasingly part of criminals' laundering toolkit, with AUSTRAC CEO Brendan Thomas noting that AI lets criminals "fabricate identities and conceal proceeds more efficiently than traditional methods," according to theadviser.com.au. The same reporting logged a 180% year-over-year rise in multi-layered fraud combining deepfakes and AI-generated identities, and found that 59% of fraud decision-makers in Australia โ€” 58% in New Zealand โ€” believe their existing KYC and identity-verification checks are not equipped to detect AI-generated documents.

That gap is not theoretical. Synthetic identity documents โ€” including passports, driver licences, and Medicare cards โ€” produced at a quality that makes visual inspection nearly useless have already been used in Australian fraud schemes in 2026. A reviewer trained to spot amateur editing โ€” misaligned text, mismatched fonts, cloning artefacts โ€” is not equipped to catch a document generated end-to-end by a model trained on thousands of genuine examples. See our explainer on how generative tools produce convincing fake paperwork for more on the underlying methods.

What compliance teams are asking

Compliance teams raise a recurring frustration: the threat is a moving target, with new templates, generators and storefronts appearing faster than any checklist can be updated. A document can pass every visual check a junior reviewer knows to run and still be entirely synthetic.

Banks and lenders ask a related question given AUSTRAC's own warning that fabricated identities are now easier to produce at scale: is a document upload, on its own, still a reasonable basis for identity verification, or does it need pairing with independent structural checks? Onboarding teams at exchanges and fintechs ask a version of the same question about remote verification โ€” given that some fraud-as-a-service kits now include virtual webcam and deepfake tools aimed at defeating liveness checks, is a liveness check reliable alone, or does it need document-level signals sitting alongside it?

The shared thread is less about any single tool and more about process: teams want automated signals layered under human judgement, so a decision rests on structural and forensic checks rather than how a document looks. Our checklist of signs a document may be AI-generated gives reviewers concrete indicators for an intake process.

Multi-layer detection: beyond the visual check

Effective detection against templated fraud combines several independent layers, so a document has to pass all of them, not just one.

Metadata analysis examines the file itself โ€” creation and modification timestamps, software signatures embedded in the PDF, inconsistencies between a claimed issue date and the actual production history. A payslip supposedly issued eighteen months ago carrying metadata showing it was created yesterday is an immediate red flag, regardless of how convincing the layout is.

Cross-document validation checks a submitted document against other available data points: does the employer named on a payslip actually exist on the ASIC register, does an address on a proof-of-address letter match records held elsewhere, do the figures on a bank statement reconcile internally. This catches the errors template generation tends to introduce when the underlying data was invented rather than pulled from a genuine source.

Machine-learning forensic signals look for the statistical fingerprints generative models leave behind โ€” artefacts in font rendering, unnatural pixel-level patterns around security features, structural inconsistencies invisible to the eye but detectable computationally. This is where platforms like CheckFile fit into an existing verification stack: CheckFile adds an additional layer of AI-generation signals deployed according to client configuration, as a complement to the structural and consistency checks compliance teams already run, rather than replacing them. No single layer catches every forgery, and no vendor should claim otherwise โ€” the value comes from stacking independent checks so a document engineered to pass one test still has to clear the others.

CheckFile's approach to document security and verification infrastructure supports banking and KYC workflows and real estate agent screening.

Entities regulated under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) โ€” the AML/CTF Act โ€” are expected by AUSTRAC to apply risk-based customer due diligence, meaning identity and supporting documents must be verified as genuine, not merely present. A firm that accepts an AI-generated payslip or bank statement without adequate checks can be in breach of its obligations even where the fraud was not detected at the time, because the regulatory expectation concerns the adequacy of the control, not the outcome of any single case. AUSTRAC's May 2026 update makes clear that AI-enabled identity fabrication and fake document generation now sit squarely within the money-laundering methods reporting entities are expected to watch for, alongside scam-proceeds laundering, and firms should factor that guidance directly into transaction monitoring and suspicious matter reporting.

Reforms extending AML/CTF obligations to a wider range of "tranche 2" entities โ€” including lawyers, accountants, real estate professionals and trust and company service providers โ€” are progressively bringing more Australian businesses into AUSTRAC's regulated population, meaning document verification obligations that once applied mainly to banks and remittance providers are becoming relevant to a much broader set of firms.

On the criminal side, using a fabricated document to obtain a benefit โ€” a tenancy, a loan, an account, a job โ€” typically engages the forgery provisions in Part 7.7 of the Criminal Code Act 1995 (Cth), which cover making or using a false document with intent to induce another person to accept it as genuine. Proceeds derived from fraud enabled by fake documents can also fall within the scope of the Proceeds of Crime Act 2002 (Cth), giving the Australian Federal Police a route to pursue and restrain the financial gains, not just the document itself.

Handling of the personal information collected during verification โ€” including any rejected or suspected-fraudulent documents retained as evidence โ€” is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles, which set expectations around collection, storage, use and disclosure. None of this removes the need for proportionate, well-evidenced verification โ€” regulatory expectations and criminal liability both assume firms apply reasonable, documented checks rather than relying on a document simply "looking right." Extending existing controls with AI-generation signals as a complement to your existing controls is one practical way to close that gap โ€” see CheckFile's deepfake and AI document detection capability.

Frequently Asked Questions

What is document fraud-as-a-service?

A business model where fraudsters sell ready-made, AI-generated fake documents โ€” payslips, bank statements, ID documents, invoices โ€” through websites or Telegram channels, delivered within minutes for a small fee and requiring no design skill from the buyer.

How is this different from someone editing a document in Photoshop?

A Photoshop edit is a one-off effort limited by the skill of the person doing it. Fraud-as-a-service packages the forgery into a reusable template sold to many buyers, so the same quality bar scales to thousands of transactions.

Can these AI-generated documents be detected?

Many can be, but not through visual review alone. Metadata analysis, cross-document validation and machine-learning forensic checks each catch signals a human eye typically misses, particularly when templates are built to pass a casual check.

What should an Australian business do if it suspects it received a fraudulent document?

Follow the internal escalation process, retain the file and metadata as evidence, and report to the Australian Federal Police or via ReportCyber. Reporting entities under the AML/CTF Act should also lodge a suspicious matter report with AUSTRAC where relevant and review whether the incident points to a gap in existing due diligence controls.

Does using a detection tool like CheckFile guarantee fraud will be caught?

No tool can guarantee every forgery will be caught, and any vendor claiming otherwise should be treated with caution. CheckFile adds AI-generation detection signals as a complement to a firm's existing controls, strengthening a layered process rather than replacing human judgement.

This article is for general informational purposes and does not constitute legal or regulatory advice. For a broader overview of the fraud data landscape, see our fraud data guide, and consult AUSTRAC guidance or a qualified compliance adviser for guidance specific to your organisation.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.