# OnlyFake, MacDoc, VerifTools: What AI Fake Document Generators Leave Behind

> What OnlyFake, MacDoc and VerifTools-style generators produce, why their output passes a visual check, and the forensic traces that still expose it.

*Published 2026-10-05 · 9 min read · TamperCheck.ai*

Canonical: https://tampercheck.ai/blog/ai-fake-document-generators-onlyfake-macdoc-veriftools

---
In early 2024, a reporter at 404 Media paid $15 to a website called OnlyFake, received a photo-realistic image of a California driver's licence lying on a carpet, and used a similar fake to pass the identity check at a cryptocurrency exchange. In February 2026, the site's creator pleaded guilty in a US federal court.

The site went dark. The business model did not. Successor services, copycats and template shops still sell the same thing: an image of an identity or financial document that looks like a phone photo of a real one, produced in seconds and paid for in crypto.

This post is for fraud analysts, KYC teams and security leads who keep seeing these names in their queues or in the news. It covers what the services are according to public reporting, why their output passes human review, what it leaves behind, and what to change in your intake process. We do not link to any of the services or describe how to use them.

## Key takeaways

- **This is a product category now.**: Fake document services run like SaaS businesses, with per-document pricing, subscriptions and support, and they relaunch after takedowns.
- **They are built to beat the glance.**: Outputs are staged as phone photos with backgrounds, lighting and camera artefacts, which is exactly what upload-based KYC expects.
- **Generated is not the same as captured.**: Synthetic images lack the physical and optical traces of a real card in front of a real camera, and they repeat across submissions.
- **Fix the intake, not just the detector.**: Live capture, barcode and MRZ cross-checks and duplicate detection close the gap that uploaded images open.

## The services, according to public reporting

### OnlyFake

OnlyFake advertised that it used "neural networks" to generate photos of fake IDs for around $15 each. [404 Media's February 2024 investigation](https://www.404media.co/onlyfake-neural-network-fake-id-site-goes-dark-after-404-media-investigation/) reported that the reporter was able to use an OnlyFake image to pass the verification flow at OKX, a cryptocurrency exchange, and the site went offline shortly after publication.

According to the [US Attorney's Office for the Southern District of New York](https://www.justice.gov/usao-sdny/pr/creator-onlyfake-charged-and-pleads-guilty-selling-more-10000-digital-fake), its creator pleaded guilty in February 2026 to conspiracy to commit fraud in connection with identification documents. Prosecutors said the site produced at least 10,000 digital fake IDs between 2021 and 2024, including driver's licences for all 50 US states, Social Security cards, and fake passports for the US and 56 other countries, and brought in about $1.2 million in cryptocurrency.

### MacDoc

Fraud researchers have described MacDoc as a successor to OnlyFake under new branding. [Koncile's analysis](https://www.koncile.ai/en/ressources/fake-documents-macdoc-fraud-detection) reports that it sells US and international identity documents for about $15 each, paid in cryptocurrency, delivered as a file that simulates a photograph of the document, including filters that imitate camera imperfections and fabricated capture metadata. Unlike older dark-web vendors, it is reachable through ordinary search.

### VerifTools

VerifTools was a marketplace for fake identity documents marketed explicitly for getting past verification checks. In August 2025, the FBI and Dutch police [seized its servers and domains](https://www.bleepingcomputer.com/news/security/police-seize-veriftools-fake-id-marketplace-servers-domains/); Dutch authorities took servers from an Amsterdam data centre, and the FBI linked about $6.4 million in proceeds to the site. [The Hacker News reported](https://thehackernews.com/2025/08/feds-seize-64m-veriftools-fake-id.html) that the operators relaunched on a new domain soon after.

### Template shops such as FakeDocShop

A second model sells editable templates rather than finished images: bank statements, utility bills, pay stubs and IDs that a buyer fills in. FakeDocShop is one of the names fraud researchers cite in this category. Template output differs from generator output: it tends to be a clean PDF or flat image rather than a staged photo, and it fails in different places (see below).

![Timeline of fake ID services: OnlyFake operating 2021 to 2024, exposed by 404 Media in February 2024, VerifTools seized by the FBI and Dutch police in August 2025, and OnlyFake creator pleading guilty in February 2026 as successors emerge](https://tampercheck.ai/images/blog/fake-id-generator-timeline.png?v=2)

*Each enforcement action ended a brand. The output kept arriving under new names.*

> **WARNING:** The lesson from all four: takedowns remove a brand, not a capability. Plan for the output of these services to keep arriving under new names.

## Why generated documents pass a visual check

Most remote onboarding still asks the customer to upload a photo of their document. Generator services are designed backwards from that requirement.

- **They look like photos, not scans.** The document is composited onto a carpet, a desk or a hand, with perspective, shadows and slight blur, because that is what a genuine upload looks like.
- **The data is internally consistent.** Names, dates of birth, issue and expiry dates and document numbers are produced to fit a template's rules, so obvious mismatches are rare.
- **The layout is right.** Templates are built from genuine documents, so fonts, field positions and background patterns are close to the real thing.
- **Volume beats scrutiny.** A reviewer clearing a queue spends seconds per document. A fake that looks right at a glance is all a fraudster needs.

This is the same shift we describe in [deepfake documents in KYC](https://tampercheck.ai/blog/deepfake-document-fraud-kyc): the fraud moved from *looking* real to being built to pass the specific check in front of it.

## What generated documents leave behind

A photo of a real card is the result of physics: plastic, holograms and ink under real light, captured by a real lens and sensor. A generated image imitates that result without going through the process. The gaps show up in several layers.

![Illustrative staged ID photo annotated with five traces of generation: mismatched noise between card and background, contradictory lighting, a flat hologram, printed data that disagrees with the machine-readable line, and the same scene reused across customers](https://tampercheck.ai/images/blog/ai-generated-id-traces.png?v=2)

*A generated “phone photo” looks right at a glance. Each numbered trace is something a camera would not produce.*

### Capture traces that do not add up

A genuine phone photo carries sensor noise, lens characteristics and compression from one camera pipeline across the whole frame. Generated or composited images tend to show noise that is too uniform, or noise that differs between the document and its background because they were made separately. Simulated "camera imperfections" applied as a filter sit on top of the image rather than coming from inside it.

Fabricated metadata is a weaker disguise than it looks. A claimed phone model has known resolutions, lens data and processing signatures. When the metadata says one device and the pixels say another, or nothing at all, that disagreement is a finding.

### Lighting and geometry that is almost right

The document and the scene around it should share one light source, one perspective and one depth of field. In composited images the shadow under the card, the glare on its surface and the blur at its edges often disagree. Security features that depend on angle, such as holograms and optically variable ink, are printed flat or behave identically across "different" photos.

### Data that is consistent on the face but not underneath

Many identity documents carry the same data twice: in printed text and in a machine-readable zone (MRZ) on passports, or a PDF417 barcode on the back of US driver's licences. Generators often get the printed fields right and the machine-readable layer wrong, or produce check digits that pass while the encoded data disagrees with the front. A static image of the front alone avoids this check entirely, which is a reason to require both sides. Our guide to [fake passport detection](https://tampercheck.ai/blog/fake-passport-detection-forensic-signals) covers the MRZ and passport-specific signals in detail.

### Repetition across submissions

Generator services reuse their inputs. The same background image, the same card angle, the same portrait framing or the same template artefacts appear again and again across different customers. One upload looks unique. A hundred uploads from the same service share fingerprints. Duplicate and near-duplicate detection across your whole intake, not just within one application, is one of the most reliable signals against this category.

### Template output: structural tells

Template-shop documents, such as statements and utility bills, usually fail on structure rather than imaging: PDF creator software that no bank or utility uses, fonts embedded from a desktop system, running balances that do not reconcile, or a text layer that disagrees with what is shown. Our [bank statement verification checklist](https://tampercheck.ai/blog/bank-statement-verification-checklist) and [pay stub red flags](https://tampercheck.ai/blog/how-to-spot-fake-pay-stubs) cover these in detail.

## How document fraud detection layers respond

In this context, "document detection" means detecting fraudulent documents, not just finding and reading a document in an image the way OCR does. No single check catches everything, which is why layered [document fraud detection](https://tampercheck.ai/document-fraud-detection) matters:

| Layer | What it catches |
| --- | --- |
| Image forensics (noise, compression, error levels) | Composited documents, pasted portraits, edited fields |
| AI-generation detection | Synthetic rendering signatures that cameras do not produce |
| Capture provenance and metadata | Fabricated or stripped device data, editor traces |
| Data consistency (MRZ, barcode, cross-field logic) | Fronts that disagree with machine-readable data |
| Cross-submission matching | Reused backgrounds, templates and portraits |
| File structure (for PDFs) | Template-shop output, incremental edits, foreign creator tools |

TamperCheck runs these layers on every document and returns a verdict, the specific findings and a risk score. For a deeper look at the image signals, see [how to check if a document is AI-generated](https://tampercheck.ai/blog/check-if-a-document-is-ai-generated) and [the 7 things that give away an AI image](https://tampercheck.ai/blog/deepfake-image-detection-pillars-2026).

## What to change in your intake process

Detection is stronger when the intake gives it more to work with:

1. **Prefer live capture to uploads.** A guided in-app camera capture makes it much harder to submit a pre-made image than a file picker does.
2. **Require both sides of the document**, and decode the barcode or MRZ to compare with the front.
3. **Pair document checks with liveness and facial forensics**, and match the selfie to the document portrait, checking the portrait itself for signs it was generated or swapped. See [liveness detection vs document forensics](https://tampercheck.ai/blog/liveness-detection-vs-document-forensics) for why you need both.
4. **Read the chip where you can.** NFC reading of passport and ID chips verifies data signed by the issuing state, which a generated image cannot provide.
5. **Match across your whole intake**, not just within one application, to catch reused templates and backgrounds.
6. **Watch the funnel, not just the document.** Bursts of sign-ups with similar document types, devices or locations often mark a single service's output.

**Test your intake against generated documents**. Upload a document image and see how TamperCheck separates a genuine capture from a generated one, with the findings explained. Free credits to start. (https://tampercheck.ai)

If you are evaluating this at scale, [book a demo](https://tampercheck.ai/book-a-demo) and we will run your own samples through the full pipeline. To run these checks on every upload without a manual queue, see [automated document tampering detection](https://tampercheck.ai/automated-document-tampering-detection).

## FAQ

### What is OnlyFake?

OnlyFake was a website that sold AI-generated images of fake identity documents for around $15 each. It went offline in 2024 after a 404 Media investigation, and in February 2026 its creator pleaded guilty in the US to conspiracy to commit fraud in connection with identification documents. Prosecutors said it produced more than 10,000 fake IDs.

### Is MacDoc the same as OnlyFake?

Fraud researchers have reported that MacDoc is a successor to OnlyFake under new branding, selling similar photo-style fake documents at a similar price. Whatever the ownership, the output is the same kind of threat and is detected in the same way.

### What happened to VerifTools?

The FBI and Dutch police seized VerifTools' servers and domains in August 2025. The FBI linked about $6.4 million in proceeds to the marketplace. Security press reported that the operators relaunched on a new domain shortly afterwards.

### Can AI-generated fake IDs pass KYC?

They have passed upload-based checks that rely on a person or a basic model looking at a single image, as 404 Media demonstrated in 2024. They are much less likely to pass checks that combine live capture, liveness, barcode or MRZ cross-checks, chip reading, image forensics and duplicate detection across submissions.

### How do you detect an AI-generated fake document?

Look at how the image was produced, not just what it shows: noise and compression that differ between the document and its background, lighting and geometry that disagree, metadata that does not match the claimed device, machine-readable data that disagrees with the printed fields, and the same backgrounds or templates appearing across different submissions.

### How do you detect fake passports made by AI generators?

Check the machine-readable zone against the printed data page, look for a portrait that was pasted or generated rather than printed, and examine lighting, noise and security-feature behaviour across the image. Where possible, read the passport's chip, which carries data signed by the issuing state that a generated image cannot reproduce. A fake passport detector that combines these signals is far more reliable than a visual check.

### What is facial forensics in identity verification?

Facial forensics examines the portrait on an ID and the customer's selfie for signs of manipulation: a face that was generated, swapped or pasted onto the document, or a selfie that is a replay or deepfake. It complements liveness detection and face matching, which confirm that a live person is present and resembles the portrait.

### Are fake document templates different from AI-generated IDs?

Yes. Template shops sell editable files, such as bank statements, utility bills and pay stubs, that the buyer fills in. They usually arrive as clean PDFs or flat images, and they fail on file structure, fonts and arithmetic rather than on camera traces.
