How to Detect a Forged Bank Statement at the Byte Level

Learn how to spot a forged bank statement by analyzing PDF byte-level traces: revision chains, metadata mismatches, and font tells. Essential for document

martes, 28 de julio de 2026 • 5 min read • Q2BSTUDIO Team

Señales forenses en PDF que revelan manipulación

Forged bank statements are among the most common frauds in income verification, loan processing and audits. Detecting these manipulations by sight alone is increasingly difficult, but byte-level analysis reveals evidence that no graphic editor can hide. This article explains how to identify forensic signals in PDF files, and how a company like Q2BSTUDIO can help you build robust technological solutions to combat this type of fraud.

When a bank statement is legitimately generated by a banking system, the resulting PDF contains a single revision. However, if someone modifies it with a free online editor, the file keeps the full history of changes. The PDF format is designed to support incremental updates: instead of rewriting the entire document, new objects, a new cross-reference table and a new end marker are appended. This means the original content remains intact inside the same file, accessible through a simple byte analysis.

The first signal we look for is the number of %%EOF markers. A genuine PDF usually has one or two (in linearized files). More than two indicate multiple save sessions. But this signal is weak on its own: digital signatures, form filling or annotations also add revisions. What matters is chaining the revisions via the /Prev reference in the trailers. Each revision contains a pointer to the previous one. If we find that a later revision replaces an object of type page content stream, we have strong proof that the document was altered after its original creation.

Another key signal is the /ID pair. The PDF specification assigns a permanent identifier that never changes and another that is updated on each write. If both are identical, the file was never modified; if they differ, at least one edit took place. An experienced forger can force a full rewrite to make them match, but that removes digital signatures and leaves coherent metadata that may be suspicious in other contexts.

Metadata offers another clue: the /Info dictionary in the trailer and the XMP packet embedded in the document catalog often become desynchronized after a superficial edit. For example, the XMP may indicate the PDF was created with iText and never modified, while /Info shows an online editor and a later modification date. This divergence is an indicator of human intervention, though not conclusive on its own: legitimate editorial processes can also produce it.

A signal that survives metadata cleanup is the presence of multiple embedded font prefixes. When an editor adds new text, it usually embeds a subset of the same typeface with a different prefix. Two distinct prefixes for the same font family (e.g., /ABCDEF+Helvetica and /QWERTY+Helvetica) indicate that glyphs were added in two separate moments. This can happen innocently when merging two PDFs, but combined with other signals it becomes highly suspicious.

If the statement is digitally signed, the signature's /ByteRange reveals whether there are bytes outside the protected range. A simple arithmetic calculation shows which part of the file was not signed. Even if the signature is cryptographically valid, it may be displaying content added after signing. This is one of the strongest pieces of evidence because it does not depend on keys or certificates, only on numbers.

None of these signals is infallible alone. A knowledgeable forger can remove multiple revisions by rewriting the PDF from scratch, or rasterize everything to hide fonts. However, these countermeasures are mutually exclusive: rewriting destroys signatures, rasterizing removes vector text and leaves a document that looks like a scan. The strength of PDF forensic analysis lies in combining several independent signals to build a risk profile.

This is where enterprise technology makes the difference. Q2BSTUDIO offers cybersecurity and pentesting services that include the evaluation of document verification processes. In addition, we develop custom software that integrates byte-level PDF analysis into automated workflows. Thanks to artificial intelligence and AI agents, these solutions can learn manipulation patterns and detect anomalies in real time. Cloud AWS/Azure infrastructure guarantees scalability and high availability for massive verification processes, while BI/Power BI dashboards allow risk signals to be visualized clearly for compliance teams.

A practical example: imagine a bank that receives thousands of statements daily. With a custom system developed by Q2BSTUDIO, each PDF is analyzed by automatically extracting the number of revisions, metadata status, embedded fonts and signature range. The system assigns a risk score based on the combination of signals. High-score cases are sent for manual review, while low-score ones are processed automatically. This drastically reduces review time and improves fraud detection accuracy.

At Q2BSTUDIO we understand that document verification is not just about tools, but about process design. Our custom software services adapt to each client's specific needs, whether a fintech, an insurer or a public body. The combination of cybersecurity to protect sensitive data, AI to automate analysis and cloud to scale on demand forms a robust ecosystem against document fraud.

The goal is not to offer a single 'fraud detected' verdict, but to present a set of signals that allows analysts to make informed decisions. As a key principle in computer security states: there is no single piece of evidence, only a chain of evidence. And that chain is much harder for a forger to break than a simple password or a digital seal.

We invite any organization that handles financial documentation to explore how technology can transform their verification processes. Contact Q2BSTUDIO for an initial consultation and discover how our AI, cloud AWS/Azure and BI/Power BI solutions can help you build a robust and scalable forgery detection system.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.