Skip to content
Case studiesPricingSecurityCompareBlog

Europe

Americas

Oceania

Industry10 min read

Fake US Passport Detection: Forgery and AI Deepfakes

How to spot a fake US passport: forged security features, AI-generated photo pages, injection attacks, and how automated checks catch them at onboarding.

CheckFile Team
CheckFile Teamยท
Illustration for Fake US Passport Detection: Forgery and AI Deepfakes โ€” Industry

Summarize this article with

A US passport is the one document a bank, insurer, car rental counter, or landlord often accepts on its own as full proof of identity โ€” why it remains the most heavily targeted identity document in circulation. Passport fraud used to mean a physical counterfeit or a stolen book; it increasingly means a photo-page image generated with AI and uploaded into a remote onboarding flow, never printed, never touched by a reviewer.

This article is provided for informational purposes and does not constitute legal or regulatory advice.

What Counts as a Fake or Forged US Passport

A fake US passport falls into three categories: a full physical counterfeit produced outside any government print run, a genuine document altered after issue, and a wholly or partially AI-generated image used to impersonate one during a remote check. Physical counterfeits copy the booklet's cover, layout, and printed data but typically fail on features hard to source outside a government printer โ€” intaglio printing, the security thread, and the hologram design the State Department uses. Altered passports start from a genuine document and change one field: a face-swapped photo, an extended expiry date, or a tampered date of birth.

The newest category exists only as a file. An AI-generated or edited image of a passport data page is uploaded to a bank's onboarding app or a rental company's web form, never presented as a physical document. It only needs to look correct in a still frame and, increasingly, to defeat selfie matching through an injection attack that feeds a manipulated image directly into the pipeline instead of a live capture. Our related guide on how AI-generated identity documents are constructed and detected covers the generation techniques in more depth.

Why Passport Fraud Is Rising in the US

Passport fraud is rising because national identity documents remain the largest single category of forged submissions organizations receive, and generative AI has sharply cut the skill needed to produce a convincing one. National ID cards and passports accounted for nearly 46% of all fraudulent document submissions detected globally, and deepfakes now make up roughly one in five biometric fraud attempts, with deepfake selfies up 58% in 2025 alone, according to Entrust's 2026 Identity Fraud Report, which analyzed more than a billion identity verifications across 195 countries. The same report found injection attacks surged 40% year-over-year โ€” significant because most remote US onboarding flows still pair a document photo with a selfie match.

A March 2026 Sapio Research survey of 850 fraud-prevention and financial-crime decision-makers across the US, UK, Germany, Singapore, UAE, Brazil, and Mexico found deepfakes now worry businesses almost as much as classic document forgery, according to Regula's coverage of the study. That matters for US compliance teams because a passport is frequently the single document accepted for a fully remote account opening.

Signs of a Physically Forged US Passport

A forged US passport rarely fails on one obvious point; it usually falls short on several details defined by ICAO Doc 9303, the standard the State Department follows for the passport book's security layers.

Feature Genuine US passport Common forgery indicator
Intaglio printing Raised, tactile ink on cover and data page Flat, smooth printing, no tactile relief
Hologram / OVD Shifts color and image sharply when tilted Static, printed, or blurred under tilt
UV-reactive ink Specific patterns fluoresce only under UV No reaction, or a generic unrelated glow
MRZ OCR-B text with check digits that validate against printed data Check digit mismatch or misalignment
Photo page Photo laser-engraved into the polycarbonate page Photo layered on top, edge or lifted corner
NFC chip data Digitally signed; passive authentication confirms the signature Chip absent, unreadable, or signature invalid

No single signal is conclusive alone โ€” a worn hologram on a genuine, well-used passport is common. What distinguishes a forgery is a pattern of several checks failing together, particularly a chip whose data no longer matches its digital signature, since altering chip content after issue invalidates that signature under ICAO's passive authentication process.

Why Chip and Hologram Checks Do Not Stop AI-Generated Submissions

None of the physical checks above apply once a "passport" arrives as an uploaded photo rather than a booklet in hand. A remote KYC flow, car rental app, or insurance quote tool that accepts a photo of the data page has nothing to tilt under light or tap for an NFC read โ€” the physical security layer of ICAO Doc 9303 is bypassed by design, not defeated. The new edition of ICAO Doc 9303, effective January 1, 2026, requires a more detailed document-type code in the MRZ, aimed at making these documents harder to template convincingly, according to ICAO's specification.

Three manipulations recur most: a face swapped onto a genuine-looking template, a synthetic photo page generated wholesale by a diffusion model with plausible but non-existent MRZ data, and an injection attack pairing a manipulated document image with a manipulated or replayed selfie. That last technique is why document verification and liveness detection against spoofed selfies increasingly need to be treated as one control, not two.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

Forging or knowingly using a false US passport is a federal crime. Forgery or false use of a passport is prohibited under 18 U.S.C. ยง 1543, which carries a fine and up to 10 years' imprisonment for a first or second offense, rising to 15 years for a subsequent offense, 20 years for drug trafficking, and 25 years for international terrorism. A related statute, 18 U.S.C. ยง 1546, covers fraud and misuse of visas and immigration documents and is often charged alongside passport offenses.

The State Department is the sole issuing authority for US passports, detailed on its lost/stolen passport pages, but its records sit behind no public real-time lookup for private businesses โ€” why document-level checks matter for banks, insurers, and rental companies that cannot query the issuer at onboarding. For banks and fintechs, Bank Secrecy Act customer identification rules, enforced through FinCEN, separately require documenting how identity was verified.

Manual Review vs AI-Assisted Verification

Criterion Manual review at a desk or counter AI-assisted document verification
Physical security features Checked when presented in person Assessed via image analysis from a photo
Chip signature validation Rarely done without NFC hardware Automated where chip access is available
Digital face swap or synthetic template Difficult without generation-artifact training Forensic analysis flags invisible inconsistencies
Cross-field consistency Spot-checked, reviewer-dependent Systematic validation across every field
Processing time under volume Degrades during onboarding peaks Consistent regardless of volume
Audit trail for regulators Often informal or undocumented Logged by design for BSA/AML evidence

Manual fraud detection catches roughly 37% of cases on average, with an average detection delay of 87 days, according to the ACFE 2024 Report to the Nations โ€” a delay incompatible with a same-day account opening, rental handover, or policy that binds immediately.

Where This Plays Out: KYC, Insurance, and Vehicle Rental

Passport fraud converges on moments where a document is trusted without a second identity source to cross-check against. In bank and fintech onboarding, a US passport is often the sole document accepted for a fully remote account opening under a bank's Customer Identification Program, so a convincing forgery that clears the upload can open an account used for money laundering before any reviewer sees the file. In insurance underwriting, a passport submitted with an application is rarely re-verified after policy inception, so an altered date of birth can misstate risk and only surface at claim time. In vehicle rental and tenant screening, a passport is often the only identity check for a non-domestic applicant, and a forged document can let someone rent a car or lease an apartment under an identity that never traces back.

Practitioners on r/compliance and r/fintech often ask whether chip verification alone is sufficient. It is not: chip presence confirms the document is an e-passport, not that it belongs to the presenter, and a chip read is rarely available in a remote, photo-only flow. A second common question is how to weigh a passport that passes visual inspection but shows inconsistent file metadata โ€” practitioners generally treat that as a stronger signal than appearance alone, since a well-made AI-generated image is built to pass a glance.

How CheckFile Complements These Controls

Document verification does not replace judgment or, where available, checks against the issuing authority; it standardizes the scrutiny applied to every submission, including during onboarding peaks when reviewer attention drops. That methodology layers structural analysis, metadata checks, and cross-field validation, built to hold up across the 3,200-plus document types and 32 jurisdictions CheckFile's platform covers. Banks and fintechs handling BSA/AML-driven KYC at volume can apply this through the CheckFile banking and KYC solution; insurers through the CheckFile insurance solution; and rental operators checking international renters through the CheckFile automotive solution.

AI-generation signals are made available as an additional layer on top of those structural checks, configured to a client's risk profile rather than delivered as a standalone verdict. For passports suspected of being AI-generated or face-swapped, CheckFile's AI and deepfake detection page explains how the platform surfaces those signals as a complement to existing controls, routing flagged cases to partner Label4 for forensic review โ€” it strengthens a verification stack, not a guarantee of catching every forgery, which no automated tool can credibly promise. Plans for teams processing passports at volume are on the pricing page. For how passport checks fit alongside other regulated documents, see the industry verification guide.

Frequently Asked Questions

How can I tell if a US passport is fake by eye

Check the intaglio printing for a tactile, raised feel, tilt the document to confirm the hologram shifts sharply rather than sitting static, and inspect the MRZ for consistent spacing and valid check digits. None of this confirms a chip's digital signature, which requires NFC hardware rather than visual inspection alone.

Can AI-generated passport images pass automated verification

A well-made AI-generated or face-swapped image can pass a basic visual or OCR check because the layout and text look correct. Catching it typically requires forensic analysis for generation artifacts and metadata inconsistencies, plus cross-referencing against a live, non-injected selfie.

Is possessing a fake passport a federal crime in the United States

Yes. Forgery or false use of a passport is a federal offense under 18 U.S.C. ยง 1543, carrying a fine and up to 10 years' imprisonment for a first or second offense, rising to 15 years for a subsequent offense, 20 years for drug trafficking, and 25 years for international terrorism. Related visa and immigration document fraud falls under 18 U.S.C. ยง 1546 and is often charged alongside passport offenses.

Does a genuine NFC chip guarantee a passport is authentic

No. A chip confirms the document is an e-passport and that its stored data matches the issuer's digital signature, but not that the presenter is its rightful holder, and altering chip content after issue invalidates that signature. Many remote, photo-only verification flows never read the chip at all, relying instead on the printed data page.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.