Digital identity verification allows customers to open accounts, apply for credit, and access financial services without visiting a physical branch. A typical eKYC process asks the user to capture an identity document so the system can extract its data and evaluate whether it is valid.
However, receiving a clear image of an ID does not necessarily mean the original document was presented. Fraudsters may submit screenshots, printed copies, or images recaptured from another screen. These methods can conceal document manipulation, support stolen-identity fraud, and bypass systems that rely primarily on OCR.
To manage this risk, digital platforms need to determine both what information appears on the document and whether the submitted image came from a genuine physical credential.
Why Recaptured Documents Create Risk
A recapture attack occurs when an existing document image is displayed or reproduced and then captured again. The submitted image may pass through several stages before reaching the verification system.
For example, a fraudster may obtain a photograph of a stolen ID, edit its portrait or personal information, display the manipulated file on a monitor, and photograph the screen. Alternatively, the image may be printed and presented as if it were the original document.
Recapture adds a new visual layer that can hide traces of editing. Resizing, printing, screen display, camera noise, glare, and compression may weaken the forensic signals left by image manipulation.
The document information may remain readable, allowing OCR to extract a plausible name, date of birth, and document number. Without authenticity and recapture analysis, a system may process the image as a normal identity document.
Three Common Forms of Document Reproduction
1. Screenshots
A screenshot is a digital copy captured directly from a device display or application. It may contain a genuine document image, a manipulated document, or a digital representation created from multiple sources.
Screenshots often lack characteristics associated with a live camera capture. They may have uniform pixel structures, unusual dimensions, missing camera metadata, interface remnants, or compression patterns inconsistent with the expected capture process.
A screenshot may also be cropped or processed before submission, making it difficult to identify the original source.
2. Printouts
In a printout attack, the fraudster prints an identity document image and presents the paper copy to the camera.
Printouts may show paper texture, ink patterns, color shifts, blurred security features, and reduced image depth. Document edges may appear physically present, which can make a printout look more convincing than a direct digital upload.
High-quality printers can reproduce portraits and text clearly, but they cannot fully reproduce holograms, optically variable elements, microprinting, and other physical security features.
3. Screen Recapture
A screen recapture occurs when a document image is displayed on a monitor, tablet, or other screen and photographed with a camera.
This method creates a new camera image, so basic controls that only check whether a file came from a camera may not be sufficient. The resulting image may contain moiré patterns, pixel-grid interference, screen glare, refresh artifacts, color distortion, or unusual lighting.
Fraudsters may adjust brightness, viewing angle, and screen resolution to reduce these signals, making detection more challenging.

OCR Alone Cannot Confirm Document Authenticity
OCR is designed to locate and extract information from a document image. It can convert names, addresses, dates, and identification numbers into structured data for downstream processing.
A screenshot, printout, or screen recapture may still contain perfectly readable information. OCR can therefore produce accurate results from a fraudulent submission.
Document authenticity analysis addresses a different question: does the submitted image show a genuine, physically presented identity document?
A complete document verification process should evaluate:
- Document format and layout
- Fonts and field positions
- Portrait and text consistency
- Physical and digital security features
- Image manipulation indicators
- Screenshot, printout, and recapture signals
- Cross-field and cross-side consistency
- Capture-session integrity
OCR and authenticity detection should operate together. Readable data is useful, but it should not be treated as proof that the document is genuine.
Visual Signals of Screenshot and Recapture Attacks
No single visual artifact reliably identifies every recaptured document. Detection should combine multiple signals across the full image.
Display and Pixel Patterns
Images photographed from screens may contain moiré, visible pixel structures, scan lines, or frequency patterns created by the interaction between the display and camera sensor.
Lighting and Reflection Inconsistencies
A physical document reflects ambient light differently from a display. Localized glare, screen brightness, dark borders, or inconsistent reflections may indicate that the source is electronic.
Texture and Printing Artifacts
Printed copies can contain halftone patterns, ink diffusion, paper texture, and reduced sharpness in portraits or fine security elements.
Edge and Background Anomalies
Unexpected borders, cropped corners, display frames, paper margins, or inconsistent depth around the document can reveal how the image was reproduced.
Metadata and Encoding Signals
File dimensions, compression history, missing capture data, editing traces, and unexpected encoding patterns can provide additional evidence. Metadata should support the decision rather than serve as the only detection method because it can be removed or modified.
Security Feature Degradation
Holograms, microtext, guilloche patterns, and optically variable elements may become blurred, flattened, or visually inconsistent after printing or screen recapture.
A Layered Detection Approach
Effective document fraud detection begins during capture rather than after the image has already been submitted.
A controlled capture SDK can guide document positioning, evaluate glare and blur, detect abnormal image sources, and collect session-level evidence. The backend can then combine image-quality analysis, document classification, OCR, authenticity checks, recapture detection, and data consistency validation.

The document result should also be evaluated alongside other identity signals. Face verification can compare the person completing the process with the portrait on the document, while liveness detection helps establish that a real person is present.
Device and session intelligence provide further context. Repeated submissions, emulators, modified applications, abnormal IP locations, or multiple identities linked to the same device can increase the overall risk score.
A risk engine can translate these signals into proportionate actions:
- Accept a low-risk document
- Request another capture
- Ask for a different identity document
- Trigger face and liveness verification
- Route the case to manual review
- Reject or block a high-risk session
Reducing False Rejections
Legitimate users may submit images with glare, compression, unusual lighting, or low camera quality. These conditions can resemble some recapture signals.
Platforms should avoid treating one weak indicator as definitive fraud. Detection models should evaluate the strength and combination of signals, while capture guidance should help genuine users correct quality problems before submission.
Risk thresholds should also reflect the use case. Opening a high-value financial account may require stronger assurance than accessing a lower-risk digital service.
Conclusion
Screenshots, printouts, and screen recaptures allow fraudsters to submit document information without presenting the original credential. Because these reproduced images may remain clear and machine-readable, OCR alone cannot provide sufficient protection.
Digital platforms need layered document verification that examines capture integrity, recapture artifacts, document security features, data consistency, facial identity, liveness, device risk, and session behavior. By combining these signals through risk-based decisioning, eKYC systems can detect suspicious submissions while maintaining an efficient experience for legitimate customers.



