Identity-document fraud does not always involve creating a completely counterfeit passport or ID card. Fraudsters may begin with a genuine document and alter selected elements—such as the portrait, name, date of birth, document number, or expiry date—to support impersonation, account takeover, or synthetic identity fraud.
Some manipulated documents remain clear enough for OCR to read. Digital platforms must therefore evaluate authenticity and consistency rather than treating successful data extraction as proof that a document is genuine. Face++ explains the distinction between identity-document OCR and document verification.
1. Personal-Data Alteration
Fraudsters may edit identity fields while retaining the general appearance of a legitimate document. Common targets include:
- Name
- Date of birth
- Address
- Document number
- Nationality
- Issue or expiry date
Digital editing can produce inconsistent fonts, spacing, alignment, character thickness, or background texture. On a physical document, scraping, overprinting, erasure, or laminate disturbance may appear around the altered field.
However, visual appearance alone is not sufficient. The extracted data should also be checked against the machine-readable zone, barcode, chip data, document format, and information supplied elsewhere in the application.
2. Portrait Substitution
A fraudster may replace the legitimate holder’s portrait with another face while leaving the remaining document data unchanged.
Portrait substitution can involve:
- Physically lifting and replacing a printed photograph
- Editing the portrait region in a digital image
- Blending a new face into the original portrait
- Replacing both the main portrait and secondary facial image
- Reprinting or relaminating the document after alteration
Possible warning signs include unnatural portrait borders, inconsistent image resolution, unusual skin-edge transitions, disrupted background patterns, and mismatched lighting or compression.
Face comparison provides an important second layer. Face++ can compare the document portrait with a current facial capture and return a confidence score, helping determine whether the person presenting the document resembles its stated holder. Face++ Face Comparing
3. Template and Security-Feature Manipulation
Instead of modifying one field, a fraudster may reproduce part or all of an official document template. This can include copied emblems, simulated holograms, false seals, altered background patterns, or imitated microtext.
Common signs include:
- Incorrect colors or document dimensions
- Missing or misplaced security elements
- Distorted emblems and background patterns
- Inconsistent line thickness
- Incorrect typography
- Security features that remain identical under different lighting conditions
- A layout that does not match the claimed document version
ICAO materials describe machine-verifiable travel-document security features in categories such as document structure, material substances, and encoded data. These features help issuing and inspection authorities authenticate documents, although not every physical feature can be reliably evaluated from a standard remote image. ICAO machine-assisted security features
4. Machine-Readable Data Manipulation
Passports and some identity cards contain machine-readable zones, barcodes, QR codes, or electronic chips. Fraudsters may alter the visible fields without updating the encoded data—or manipulate both layers but introduce inconsistencies.
A verification system should compare:
- Printed name against encoded name
- Date of birth and expiry date across data sources
- Document number and check digits
- Nationality and issuing-country codes
- Portrait against chip or trusted reference imagery
- Encoded data structure against the expected format
A document becomes suspicious when individual elements appear valid but contradict one another. These internal consistency checks are often more dependable than evaluating one visual feature in isolation.

5. Copy-Paste and Image Compositing
Digital document images may be assembled from multiple sources. A fraudster can copy a portrait from one file, personal data from another, and a clean document background from a template.
Potential signs include:
- Sharpness differences between regions
- Uneven pixelation or compression
- Rectangular boundaries around edited fields
- Repeated background textures
- Inconsistent shadows or reflections
- Misaligned text baselines
- Different noise patterns across the image
High-quality compositing can be difficult to identify through manual inspection, particularly when the image is compressed before submission. Automated analysis should evaluate both localized anomalies and overall document consistency.
6. Screen Recapture, Printing, and Rephotography
Fraudsters often recapture a manipulated document from a screen or printout. This can hide editing traces, flatten digital layers, and make the submission appear to come from a physical document.
Common recapture indicators include:
- Moiré patterns or visible display pixels
- Screen glare and unnatural reflections
- Printer dots, paper texture, or cut edges
- Display borders or interface elements
- Uniform illumination inconsistent with a physical card
- Repeated compression or scaling artifacts
- Abnormal perspective and depth
A readable recaptured document can still be fraudulent. Face++ has similarly noted that manipulated documents may remain clean and machine-readable, reinforcing that readability and authenticity are separate questions. Why Readable Identity Documents Can Still Be Fake
7. Why OCR Alone Cannot Detect Document Tampering
OCR answers: What information is visible on the document?
Document-authenticity analysis answers: Does this evidence appear genuine, internally consistent, and appropriate for the claimed document type?
OCR may accurately extract an altered name or fabricated document number. A stronger workflow combines:
- Document-type and template recognition
- Image-quality and recapture checks
- Visual tampering analysis
- OCR and field normalization
- Cross-field and encoded-data validation
- Face comparison with the document portrait
- Liveness and capture-integrity analysis
- Device, session, and application-risk signals
Face++ OCR, face comparison, and liveness detection can support the data-extraction and biometric identity-binding layers. Document-authenticity results should then be combined with these signals rather than evaluated as an isolated pass or fail.

8. Responding to Suspected Tampering
A suspicious indicator should not always trigger immediate rejection. Blur, glare, compression, document wear, and unusual capture conditions can resemble manipulation.
A risk-based workflow may:
- Request a guided recapture
- Ask for the original physical document
- Compare additional document surfaces
- Read a chip or barcode where supported
- Perform face verification and liveness detection
- Request secondary identity evidence
- Route unresolved cases to manual review
- Reject or restrict confirmed fraudulent submissions
The platform should preserve the original capture, extracted fields, detected anomalies, model versions, and final decision to support investigation and auditability.
9. Frequently Asked Questions
Q1. Can a document pass OCR and still be fraudulent?
Yes. OCR may correctly read information that was digitally altered or printed onto a counterfeit document.
Q2. What is the clearest sign of ID tampering?
There is no universal single sign. The strongest evidence usually comes from several inconsistencies across visual appearance, encoded data, document structure, portrait matching, and capture context.
Q3. Can face verification detect an altered identity document?
Face verification does not authenticate the entire document. It can help determine whether the current user matches the document portrait, making it valuable for detecting portrait substitution and impersonation.
Q4. Why is liveness detection necessary?
Even when the face matches the portrait, the applicant may be presenting a photograph, replay, mask, deepfake, or injected media. Liveness detection evaluates genuine presence as a separate control.
10. Build a Layered Document-Fraud Defense
Modern identity-document fraud can combine physical alteration, digital compositing, data manipulation, and recapture techniques. No individual font anomaly, OCR result, or biometric score is sufficient to determine authenticity.
By combining document analysis with Face++ OCR, face comparison, liveness detection, and contextual risk signals, digital platforms can detect suspicious submissions more accurately while providing legitimate users with appropriate recapture or review paths.



