Hesper LaunchYour first 200 claims free for new MGAs and TPAsMGAs & TPAs: first 200 claims freeApplyAuto | Homeowners | Workers' Comp | Pet
Blog›Use cases
Use casesMarch 18, 2026·7 min read·Pankaj Dhariwal, CEO·Updated October 7, 2026

Fake pay stubs: how to detect forged payslips with AI in 2026

Forged payslips are surging in loan and income fraud. How fake pay stubs are created, why traditional verification fails, and how AI catches them.

PD
Pankaj Dhariwal · CEO and Co-founder
March 18, 2026·7 min read·Updated October 7, 2026
USE CASESHesper AIPAYSLIP · PERIOD 09/15YTD total inconsistent with gross payFLAGGED BY HESPER
The numbers behind this
$10.4BAuto lending fraud exposure, 2025Income and employment misrepresentation is 45% of it - Point Predictive, 2026 Auto Lending Fraud Trends Report
67%Of synthetic ID fraud involves doc manipulationPay stubs and bank statements are most common
3 minTo forge a payslip with AI toolsUsing freely available inpainting and template generators
9.08%Of submitted documents carry high-risk fraud markersUp 28.5% from 2024 - Resistant AI, Global Document Fraud Report 2026

The scale of payslip fraud

Answer

How common is pay stub and income document fraud right now?

High single digits and climbing. Resistant AI found 9.08% of documents submitted for verification in 2025 carried high-risk fraud markers, up 28.5% year over year. Inscribe flagged about 6% of its network traffic, roughly 1 in 16, and its fraud-leader survey ranked pay stubs the second most manipulated document type.

Income verification is the foundation of lending decisions. When a borrower applies for a mortgage, personal loan, or auto lease, the lender needs to confirm that the stated income is real. The primary evidence for this is the pay stub - and as FTC identity theft reports document, pay stubs are now one of the easiest financial documents to forge.

The problem has grown rapidly since 2024. AI image editing tools and dedicated payslip template generators have reduced the time required to produce a convincing fake from hours to minutes. The cost has dropped to zero. Federal Reserve research on synthetic identity fraud confirms that this category of fraud has outpaced the verification infrastructure at most lending institutions, HR departments, and property management firms.

The scale is measurable in one line of business alone: Point Predictive put 2025 auto lending fraud exposure at $10.4 billion, with income and employment misrepresentation accounting for 45% of it and growing 21% year over year. Pay stubs are the document that carries that misrepresentation. For a broader view of how document fraud impacts every sector, see our analysis in Document fraud in 2026: the data behind a $4.7T problem.

Pay stub fraud has become the path of least resistance for loan fraud. The documents are simple, the templates are widely available, and most lenders still verify income by reading the text - not by examining the document itself.

Hesper AI Threat Research, Q1 2026

Common forgery techniques

Answer

What are the most common ways fraudsters forge pay stubs?

Three techniques dominate. Template generators produce a clean PDF from typed-in fields. AI inpainting edits gross pay or employer name on a genuine stub. PDF text-layer editing rewrites the text directly. Only the first is reliably visible to a human reviewer; the other two leave artifacts detectable only at the pixel level.

Fake pay stubs fall into three broad categories, each with different detection characteristics. Understanding these categories is essential for building effective detection - because the artifacts left behind by each technique are different, and a detection system needs to catch all three.

The first category is template-based generation. Dozens of websites and apps offer pay stub templates where the user fills in employer name, income, deductions, and dates. The output is a clean PDF that looks professional but contains telltale signs: identical font rendering across all fields (real payroll systems use variable rendering), mathematically perfect deduction calculations (real payroll often has rounding), and metadata that traces to consumer PDF libraries rather than payroll software.

The second category is AI inpainting. The fraudster starts with a legitimate pay stub - their own or someone else's - and uses AI editing tools to change specific fields: gross income, net pay, employer name, or dates. Inpainting tools are designed to blend edits seamlessly into the surrounding context, but they leave compression artifacts at edit boundaries that are detectable at the pixel level.

The third category is full PDF editing. Using tools like Adobe Acrobat or open-source PDF editors, the fraudster modifies text layers directly. This produces clean text but often introduces font substitution artifacts, misaligned baselines, or inconsistent character spacing that differs from the original payroll system output.

TechniqueDifficultyDetectable by manual reviewDetectable by AI pixel analysis
Template generatorsLow - fill in fields onlineSometimes - if reviewer checks format✓ Yes - template fingerprints, metadata anomalies
AI inpaintingLow - edit specific regions✗ Rarely - edits blend visually✓ Yes - compression artifacts at edit boundaries
PDF text-layer editingMedium - requires PDF tools✗ Rarely - text looks correct✓ Yes - font rendering anomalies, baseline shifts
Full AI document generationLow - emerging technique✗ No - visually indistinguishable✓ Yes - generation signatures, statistical patterns

Why traditional verification fails

Answer

Why do employer calls and OCR checks fail to catch forged payslips?

Because they verify content, not authenticity. Employer calls confirm dates, often not salary, and take days. OCR checks whether deductions add up, which any competent forgery satisfies. Manual review fails on volume: Inscribe puts careful document review at 10 to 15 minutes each, and 44% of North American institutions still review by hand.

Most lenders verify income documents through one or more of these methods: employer verification calls, cross-referencing with tax returns, OCR-based data extraction with rule validation, and manual visual review. Each has significant gaps when it comes to sophisticated fakes. The same gaps apply to the bank statements that usually arrive in the same loan file; our guide on how to detect a fake bank statement walks through the equivalent checks.

Employer verification calls are slow (often 3–5 business days), incomplete (many employers only confirm dates of employment, not salary), and easily circumvented by fraudsters who use accomplices or fake phone numbers. Cross-referencing with tax returns helps but only catches discrepancies between documents - if both the pay stub and tax return are forged, the cross-reference passes.

OCR-based extraction reads the text on the pay stub and checks for internal consistency - do the deductions add up, is the tax rate plausible, does the net pay match gross minus deductions. This catches sloppy fakes but misses any manipulation where the numbers are internally consistent. We covered this fundamental limitation in depth in Why OCR alone is not enough for document fraud detection.

Manual visual review is the last line of defence, but human reviewers process dozens or hundreds of documents per day. At that volume, reviewers check for obvious formatting issues - they do not zoom to 400% and inspect compression artifacts around the income field. The manipulation that AI tools produce is invisible at normal viewing resolution.

The verification gap

A forged pay stub with internally consistent numbers, a real employer name, and a professional layout will pass OCR validation, rule-based checks, and casual visual review. The only reliable detection path is pixel-level analysis of the document image - examining compression artifacts, font rendering patterns, and generation signatures that are invisible to the human eye at normal zoom. If you are evaluating tools for this capability, our document fraud detection software guide compares the three architectures on exactly this point.

How pixel-level AI detection catches fakes

Answer

How does AI detect a fake pay stub that looks perfect?

It reads the image, not the text. Compression analysis finds discontinuities where an inpainting tool rewrote a field. Font rendering analysis catches substituted glyphs and baseline shifts. Generation signature detection spots the statistical fingerprints template tools leave in noise and anti-aliasing. Metadata analysis flags PDFs that no payroll system would produce.

Pixel-level analysis operates on the raw document image before any text extraction occurs. It examines the visual properties of the document - not what the document says, but how it was produced and whether it has been altered. This is the fundamental difference from OCR-based approaches, which can only validate text-level consistency.

For pay stubs specifically, the AI examines 200+ fraud signals across several categories. Compression analysis detects discontinuities at editing boundaries - when a region has been modified with an inpainting tool, the JPEG or PNG compression patterns in that region differ from the surrounding area. Font rendering analysis identifies character-level anomalies: substituted fonts, misaligned baselines, inconsistent kerning, and rendering artifacts that differ from known payroll system outputs.

Generation signature detection identifies documents produced by template generators or AI generation tools. These tools leave statistical fingerprints in the pixel data - patterns in noise distribution, colour quantisation, and anti-aliasing that distinguish generated documents from scans or screenshots of legitimate payroll output.

Metadata and structural analysis examines the PDF structure, creation tools, timestamps, and layer composition. Legitimate payroll systems produce documents with characteristic metadata signatures. Template generators and PDF editors produce different signatures - and the mismatch is a strong fraud indicator.

json
{
  "fraud_score": 91,
  "verdict": "LIKELY_FRAUD",
  "findings": [
    {
      "type": "compression_discontinuity",
      "description": "JPEG compression artifact at income field boundary - inconsistent with surrounding regions",
      "region": { "x": 310, "y": 204, "w": 185, "h": 28 },
      "severity": "high"
    },
    {
      "type": "font_rendering_anomaly",
      "description": "Character baseline shift in gross pay value - inconsistent with payroll system font rendering",
      "region": { "x": 312, "y": 206, "w": 90, "h": 22 },
      "severity": "medium"
    }
  ],
  "signals_checked": 218
}

Integration for lenders and HR platforms

Answer

How do lenders add pay stub fraud detection without rebuilding their pipeline?

One API call, placed before OCR. The document image goes out, a fraud score from 0 to 100 and findings with pixel coordinates come back on the same request. Score above your threshold routes to review with the flagged regions attached; everything else continues to underwriting untouched. Nothing in the existing credit or income logic changes.

The integration pattern for pay stub verification follows the same architecture as any document fraud detection workflow: intercept the document before it reaches your existing processing pipeline, analyze the raw image, receive a fraud score and structured findings in seconds, and route based on the result.

  1. When a pay stub is uploaded as part of a loan application or employment verification, send the document image to the fraud detection API before passing it to your OCR or income extraction pipeline
  2. Receive a fraud score (0–100), a verdict, and an array of findings with pixel coordinates identifying suspicious regions
  3. For documents above your threshold (typically 70–80 for lending workflows), route to a focused manual review queue with findings attached
  4. Reviewers inspect the specific flagged regions rather than reviewing the entire document - reducing review time from minutes to seconds
  5. Clean documents continue to your existing income verification and underwriting workflow unchanged

This pre-OCR detection layer is additive - it does not replace your existing income verification, credit checks, or underwriting logic. It adds a document authenticity check that catches fakes before they enter your pipeline. The same architectural pattern applies to expense platforms detecting fake receipts and accounts payable workflows verifying invoices.

Key takeaways

  • Pay stub fraud is one of the fastest-growing document fraud categories: income and employment misrepresentation drove 45% of the $10.4 billion in 2025 auto lending fraud exposure reported by Point Predictive, up 21% year over year.
  • Three primary forgery techniques - template generators, AI inpainting, and PDF editing - each leave distinct pixel-level artifacts that are invisible to manual review.
  • Traditional verification methods (employer calls, OCR validation, manual review) fail against sophisticated fakes because they check text-level consistency, not document authenticity.
  • Pixel-level AI analysis examines 200+ fraud signals including compression artifacts, font rendering anomalies, and generation signatures to detect manipulation.
  • Integration is a single API call before your existing pipeline - documents are scored in seconds and routed by threshold without disrupting your current workflow.

Frequently asked questions

At the text level, check for mathematically inconsistent deductions, implausible tax rates, and formatting that does not match known payroll system outputs. However, sophisticated fakes pass all text-level checks. The most reliable method is pixel-level analysis: examining the document image for compression artifacts at edit boundaries, font rendering anomalies from character substitution, and generation signatures from template tools. These artifacts are invisible to the human eye at normal resolution but are reliably detectable by AI pixel analysis.

The three primary tools are: (1) online pay stub template generators that produce professional-looking PDFs from user-entered data; (2) AI image editing tools that use inpainting to modify specific fields on a legitimate pay stub while preserving the surrounding context; and (3) PDF editors that modify text layers directly. Since 2024, AI inpainting has become the dominant technique because it produces results that are visually indistinguishable from legitimate documents at normal viewing resolution.

Most employers verify income through direct employer contact or third-party verification services, which confirms employment dates and sometimes salary ranges. However, these methods are slow (3–5 business days), often incomplete, and can be circumvented. Pixel-level document analysis provides a faster and more reliable verification layer: the pay stub image is analyzed in seconds, and manipulation artifacts are identified with specific pixel coordinates - regardless of whether the text content appears consistent.

Network data from document forensics vendors puts the rate in the high single digits: Resistant AI's Global Document Fraud Report 2026 found 9.08% of submitted documents carried high-risk fraud markers in 2025, up 28.5% from 2024, and Inscribe flagged roughly 6% of documents on its network, about 1 in 16. In Inscribe's 2026 survey of fraud leaders, 85.6% named bank statements the document most vulnerable to manipulation, with pay stubs ranked second. The frequency has increased significantly since 2024 as AI tools have reduced the effort required to produce convincing fakes. Pay stub fraud is a primary vector in both conventional loan fraud and synthetic identity fraud schemes, where fabricated income documents are paired with synthetic identities to obtain credit.

The most thorough approach combines three layers: (1) pixel-level document analysis to verify the document has not been manipulated or generated from a template - this catches sophisticated fakes that look visually perfect; (2) cross-referencing stated income with employment verification services; and (3) comparing the pay stub format against known payroll system outputs. For property management firms processing high volumes, an automated API-based approach that scores each document in seconds is more practical and more reliable than manual review.

On the Hesper platform

Hesper AI runs every stage of a claim, from first notice of loss to subrogation recovery, with investigation-grade evidence behind every decision.

The platformFNOL intakeClaims triageFraud investigationSubrogation & recovery

Keep reading

← More articles on the Hesper AI blog

See Hesper AI on your documents

Request a demo and we'll run an analysis on your real document samples.