How a forged PDF bank statement betrays itself at the byte level
PDF files are append-only containers that silently retain their full edit history, making alterations detectable even when visually undetectable to the naked eye. A former KYC/AML document verification specialist explains how a fraudster editing a bank statement with a free browser-based PDF tool leaves behind forensic traces in the file's structure. The key indicator is the presence of multiple revision sections — detectable via duplicate '%%EOF' markers and 'startxref' offsets — which form a linked list of every save state the document has passed through. When a later revision replaces an object, such as a content stream, that already existed in the original document, it constitutes strong evidence of post-generation tampering. Unlike simply having multiple revisions, which can have legitimate explanations, a replaced content-stream object is structurally incompatible with an unmodified, bank-generated statement.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in