Fake Proof of Payment: The Screenshot That Buys Three Days
Nobody fakes a payment to steal money. They fake it to buy time — long enough to collect the goods and be somewhere else when the bank tells you nothing arrived.

The truck is at the loading dock. The driver is on the phone to somebody. The buyer has just sent a screenshot of their banking app showing the transfer going out, with your reference number in it, timestamped four minutes ago. Your warehouse manager wants to know whether to load.
This is not a document fraud in the way most of this blog uses the phrase. Nothing forensic is happening. It works because of a gap in the plumbing of money that most people have never had to think about: the sender can see a payment long before the recipient can, and the gap between those two moments is hours to days.
Key takeaways
- A payment has four states — initiated, accepted, cleared, settled — and a screenshot only ever evidences the first.
- Reference numbers are generated at initiation. They exist whether or not the payment ever completes, which is why quoting one proves nothing.
- The only check that ends the argument is looking at your own account. Not their screenshot, not their reference, not their "confirmation" PDF.
- Reversal windows on push payments and cheques run for days, so even seen the money is not always the end of the story.
The four states of a payment
Ask most people whether a payment has happened and they will treat it as binary. It is not.
Initiated. The sender pressed the button. Their app shows a confirmation and a reference. Nothing has left anywhere yet.
Accepted. Their bank has queued it. Still fully reversible by the sender in many schemes, and still invisible to you.
Cleared. Funds have actually left the sender's account. Visible to them. Frequently still not visible to you, depending on the rail and the cut-off times involved.
Settled. The money is in your account and available. This is the only state that is any of your business, and it is the only one you can verify without trusting anyone.
Every fraud in this family lives in the space between one and four. The screenshot is real. The app is real. The reference number is real. The payment is real as an instruction. It simply gets cancelled, recalled, or never funded — and by the time your bank confirms nothing arrived, the goods have left and the buyer's phone is off.
Why the artifacts are so convincing
There is no craft required here, which is what makes it high-volume.
Screenshots need no forgery at all in the easy case: initiate a real transfer, screenshot the confirmation, cancel it. Everything in the image is genuine. Where editing is involved, it is usually a single amount or account number changed in an image editor, and the tells are the ordinary ones — a font that does not match the rest of the interface, a digit sitting a pixel off the baseline, compression artifacts that differ inside a rectangle. We covered why screenshots are the cheapest forgery in the book and why they still work.
"Confirmation" PDFs are usually generated from a template, and they are the weakest artifact in the set. Real bank documents come out of institutional systems with consistent producer strings, consistent fonts, and a structure that matches every other document that bank has ever issued. A confirmation assembled in a word processor last night rarely matches any of that.
Remittance advices are simply typed. There is no authority behind them at all — a remittance advice is a courtesy note saying "we have paid you", not evidence that anyone did.
Reference numbers deserve their own line, because quoting one is the single most effective move in the whole script. It sounds like a lookup key. It sounds checkable. It is generated at state one, it is meaningless to your bank, and by the time anyone tries to trace it the answer has stopped mattering.
Where it bites hardest
Freight and logistics. A load is collected against a payment screenshot because the driver is waiting and the dock is blocked. The commercial pressure is the attack surface, not the document.
Wholesale and cash-and-carry. Goods released on a same-day transfer that never lands. High-value, portable, resaleable stock is the target.
Vehicles and equipment. Private and trade sales, where the buyer is standing there with keys in reach.
Rentals and deposits. A "paid" deposit screenshot securing a property or a booking that is then re-let.
Marketplaces. A screenshot posted in chat to trigger dispatch before the platform's own settlement.
The common factor is not the industry. It is a moment of physical or contractual handover that the seller is under pressure to complete now, and a payment rail that cannot confirm now.
The one check that ends it
Look at your own account.
That is the whole control, and everything else on this page is commentary. Money that has settled is visible to you without anybody sending you a picture of it. If it is not visible to you, it has not settled, and no image, reference number or confirmation document changes that fact.
The scripts exist to move you off that check, and they are worth recognising as a set:
- "It's showing as sent on my side." Yes. State one.
- "It's a bank delay, they're always slow on Fridays." Possibly true, and irrelevant to whether you should release goods.
- "Here's the reference, you can check it with your bank." Your bank cannot look up a payment that has not arrived.
- "I'll send the confirmation letter." A document the sender produces is not confirmation.
- "The driver has another collection, we need to load now." The urgency is the product.
None of these are lies exactly, which is why they work on decent people. They are all true statements that do not answer the question.
Making it a rule instead of a judgement call
Individual staff will not hold this line under pressure at 4pm on a Friday. They should not have to. Turn it into a policy that removes the decision:
Release on settlement, never on evidence of payment. Write it down, and make sure the person at the dock knows it is not theirs to override.
Use payment rails that settle fast, for exactly this reason. Instant-payment schemes exist in most markets now and they collapse the window this fraud lives in. Where they are available, "I'll wait for it to land" costs seconds rather than days.
Give the front line a script and the authority to use it. "Our policy is that we release when the funds show in our account. I can hold this for you." That sentence, backed by a manager who will not undercut it, ends the conversation.
For anything high value, verify the counterparty as well as the payment. A first-time buyer taking a large quantity of resaleable goods with unusual urgency is a pattern before it is a payment problem. The same logic as vendor onboarding, applied in the other direction.
Escalate on any payment document that arrives as an image. A screenshot is not a document. If someone genuinely needs to evidence a payment, a bank-issued statement covering the period is a real artifact; a photograph of a phone is not.
Even settled is not always final
One uncomfortable footnote. Seeing the money is the right test, but on some rails it is not the last test.
Cheques can bounce well after the funds appear. Card payments can be charged back for months. In several push-payment schemes, reimbursement rules mean a payment made by a victim of fraud can be reversed out of a receiving account. Depending on the rail and the jurisdiction, "it arrived" and "it is mine" can be days or weeks apart.
For most trades this is theoretical. For high-value, first-time, unusually urgent transactions it is not, and the right response is the boring one: know which rail you are on, know its reversal window, and size your risk to it.
Where documents come back in
The screenshot is only ever the opening. Once a buyer or supplier is behaving this way, there is usually a small pile of supporting paper — a bank letter, a company registration, a proof of address, a signed order — and that material is where the operation is much weaker. Producing a convincing PDF from an institution you do not work for is genuinely hard, and it is exactly what a forensic scan is built to interrogate.
Check your account first. Then check their paperwork. In that order.
Frequently asked questions
Can a bank transfer screenshot be faked?
Easily, and often it does not even need editing — a real transfer can be initiated, screenshotted, and cancelled before it clears. Everything in the image is genuine and the payment still never arrives.
Does a payment reference number prove a payment was made?
No. References are generated when a payment is initiated and exist regardless of whether it completes. Your bank cannot use a sender's reference to confirm money that has not arrived.
How long should I wait before releasing goods?
Until the funds are visible and available in your own account. On instant-payment rails that is seconds; on slower rails it can be a working day or more. The wait is a function of the rail, not of how much you trust the buyer.
What if the buyer is genuinely in a hurry?
Genuine buyers can use a payment method that settles quickly, or accept a hold. Urgency that cannot tolerate a settled payment is itself the finding — pressure to skip the one check that works is the mechanism, not a coincidence.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
One Character Off: How Lookalike Domains Get Paid
The most effective domain in payment fraud is not a hacked one. It is a real domain, correctly configured, that differs from your supplier's by a single character nobody reads.
How to Verify a Company Is Legitimate: A Field Checklist
Registry records, domain age, phone lines, and the corroboration habit: a field-tested sequence for checking whether a company is what it claims to be.
Fake Professional Licenses: When the Credential Is the Con
Nurses, engineers, contractors, financial advisers — fabricated license certificates are cheap to make and expensive to trust. How to verify a professional credential at the source.