A bank transfer, a hotel reservation, a refund, a WhatsApp conversation or even authorization from a superior. Screenshots have become a common resource to demonstrate that something has happened in the digital environment. However, relying solely on them entails increasing risks and can open the door to new forms of image fraud.

ESET warns that current image editing and generation tools allow increasingly convincing fake captures to be modified or created from scratch. The problem is that a capture only shows an image of what supposedly appeared on a screen, but does not allow us to verify by itself who created it, if it has been manipulated or if the operation it reflects actually took place. This ease of altering content is making image fraud increasingly difficult to detect with the naked eye.

“We have become accustomed to accepting a screenshot as confirmation that a payment has been made, a reservation exists or a conversation took place, but today that trust can work against us,” explains Josep Albors, head of Research and Awareness at ESET Spain. “The proliferation of deepfakes and other image manipulation and generation tools allows us to create fake captures that are increasingly more convincing and difficult to identify with the naked eye.”

From false payment receipt to investment scams

One of the most common examples can occur on second-hand buying and selling platforms. A supposed buyer sends the seller a screenshot that apparently confirms that he has made a transfer and urges him to send the product. However, the money never arrives because the receipt has been manipulated. This is a clear example of image fraud based on the appearance of legitimacy offered by an apparently authentic capture.

A variant consists of showing a false notification in which it is assured that the payment is withheld and that it is necessary to previously pay a commission or update some type of account to receive it. Both the initial payment and this supposed procedure are false.

Captures can also be used to lend credibility to other frauds. In investment groups, for example, scammers may share images of supposed accounts with high profits to convince other people to invest. Reservations, invoices or return receipts can also be falsified to claim a product or a refund that does not correspond. In all these cases, image fraud seeks to generate a feeling of trust that leads the victim to make a decision.

Even a seemingly innocent request can hide an attempted account takeover. A cybercriminal can ask the victim to capture a verification or password recovery code and use that information to later access the service. Therefore, the risk associated with image fraud is not limited to the falsification of documents or receipts, but can also facilitate access to personal information and accounts.

When a false capture causes a decision within the company

The risk does not only affect consumers. Customer service, administration, finance or human resources departments routinely receive screenshots as supporting documentation.

A customer can present an image as proof of a payment that never occurred and request a return or replacement of a product. An employee may receive a screenshot that appears to contain a manager’s authorization to make an urgent transfer. Conversations may also be manipulated to support a claim or attempt to regain access to an account.

In the corporate environment, image fraud can have especially relevant consequences when a manipulated image triggers an economic operation or an action on company systems and data.

“The real risk appears when a capture triggers a decision that is later difficult to reverse, such as authorizing a payment, returning money, delivering a product or providing sensitive information. Therefore, when there is money, data or access at stake, the verification should always be carried out in the source system and not be based exclusively on an image sent by another person,” says Albors.

How to check if an operation is real

ESET recommends applying a simple rule: use the capture as a clue or complementary documentation, but never as the only evidence when the operation can be verified in another way. This precaution is especially important given the increasing sophistication of the image fraudwhich can make a counterfeit virtually indistinguishable from legitimate content.

In the case of a payment, it must be verified directly in the corresponding banking application, payment platform or service. If it is an online purchase or sale, the information must be reviewed within the marketplace itself, accessing it from its official application or website and not from links sent by the other person.

The same goes for reservations, returns or invoices. Whenever possible, it is advisable to compare the information with reference numbers, original emails, transaction records or confirmations coming directly from the company that supposedly carried out the operation.

The main defense against fraud with images is, therefore, not to confuse a visual representation with proof that an event has really occurred. A capture can serve as a clue, but confirmation should come whenever possible from the original source. In a scenario in which generating and manipulating images is becoming increasingly easier, verifying information before acting becomes one of the best tools to avoid falling into a scam.

For organizations, ESET recommends the following:

  • Compare captures with internal records before approving payments, returns or sensitive changes.
  • Request original verifiable documents or communications when it is necessary to investigate an incident.
  • Avoid irreversible decisions based solely on an image, especially in financial areas, customer service or account recovery.
  • Train employees so that they know the limitations of this type of evidence and know when they should perform additional checks.
  • Automate, when possible, the consultation of source systems, reducing dependence on manually provided documentation.