TL;DR: A fake pay stub is a payroll PDF altered after issuance or generated from scratch to inflate income for lending or onboarding. Visual review misses competent fakes. The durable check is whether net pay appears as a matching bank-statement deposit, plus file signals that separate edited-after-creation stubs from generated ones. FinCEN has long listed employment and income fraud, including altered earnings documentation, in mortgage loan fraud SARs.
What a Fake Pay Stub Actually Is

A fake pay stub is a payroll document that misstates wages, hours, employer identity, or withholding so an applicant looks more qualified than they are. Lenders use stubs to underwrite ability to repay. Banks and fintechs use them at onboarding to corroborate employment. In both settings the stub is a claim. Proof is the cash that posted.
Two production methods dominate. Edited-after-creation starts with a real stub from a payroll run. Someone later changes gross pay, net pay, year-to-date totals, or the employer line and re-exports the PDF. Layout and logo often survive. Generated-from-scratch stubs never passed through payroll. They come from templates, consumer PDF tools, or generative models. The numbers can be internally consistent. The file history still does not match a payroll engine.
Those paths fail different checks. An edited stub often breaks arithmetic or shows a modification after the stated pay date. A generated stub may recompute every line and still fail issuer matching, recycled-pattern detection, or the deposit cross-check. Treating every fake as a crude visual forgery is how competent files get through.
FinCEN's mortgage loan fraud assessment treated employment and income fraud as a core fraud-for-property pattern and, in sampled SAR narratives, listed altered or fraudulent earnings documentation alongside altered bank statements. The typology is not new. The quality of the PDF is. The same file now shows up in personal loans, auto finance, BNPL limit increases, small-business underwriting, and KYC refresh when a customer will not connect payroll data directly.
Tells That Still Work — and the Ones That Don't
Some reviewer tells still catch sloppy files. None of them is a verdict on its own.
Arithmetic still earns its keep. Gross minus taxes minus deductions should equal net. Hours times rate should equal period gross when both appear. Year-to-date figures should move with the pay calendar. Withholding should be plausible for the stated gross and jurisdiction. Edited stubs often change the income line and leave adjacent fields behind. Generated stubs increasingly get the math right, which is why math is a screen, not a close.
Employer existence is another screen. Registry filings and a non-residential address reduce the chance the employer was invented. A real employer does not prove the stub came from that employer's payroll. Stolen templates show up on genuine company names.
Visual tells degrade fastest. Mixed fonts, misaligned decimals, placeholder labels, and stretched logos still appear on low-effort edits. Generative output does not leave those marks. Zooming on a number is a reasonable habit. It is not a detection program. Generative AI document fraud has already moved the problem off the page and into the file.
The highest-yield manual check remains the deposit match. Net pay should appear on the bank statement on or near the pay date, in a similar amount, with a payer description that fits the claimed employer or payroll provider. The CFPB's Ability-to-Repay / Qualified Mortgage compliance guide requires creditors who rely on income to verify it with reasonably reliable third-party records, and to confirm that inflows used as income are actually the consumer's income — not an unidentified deposit.
Coordinated kits pair a fake stub with a manipulated statement. That is why the two documents cannot be reviewed in isolation, and why document fraud in banking is now a package problem. Matching deposits are necessary. They are not sufficient if both files were edited after creation. Two or three consecutive stubs still help: cross-period YTD continuity is harder to sustain than a single page, though stubs generated in one sitting can still look internally consistent.
How Detection Actually Works
Reliable detection reads the file's story, not the reviewer's impression of the page. Six classes of signal cover the gap visual review cannot.
Production method asks how the PDF came into existence. Payroll platforms, consumer editors, and generative pipelines leave different fingerprints in fonts, compression, text layers, and producer tags. An edited-after-creation stub often retains an original production path and then shows a later intervention. A generated stub never had a payroll origin to retain.
Timestamp trail compares file creation and modification to the stated pay period. A modification after the pay date is not proof of fraud by itself — some employers export stubs from HR tools — but batch creation or timestamps that cannot exist for the claimed cycle is a reason to escalate. Screenshots strip this trail. Treat a flattened image as a loss of evidence, not a clean bill of health.
Issuer matching asks whether the claimed employer and payroll source are consistent with known issuance patterns: entity existence, identifier format, and whether the layout behaves like output from a real payroll run rather than a generic template. A genuine employer with a recycled stub is a different problem from a shell employer.
Consistency covers internal math and cross-document agreement. Gross, tax, deductions, net, and YTD have to close. Name, address, and employer have to agree with the ID and the bank statement in the same file. Net pay has to have a deposit story. Generated packages are built to look consistent, which is why consistency without the other checks is easy to game.
Model artifacts are computational traces associated with generative output. They are not something a reviewer can be trained to see on a zoomed PDF. Recycled patterns catch reuse: the same template or structural skeleton appearing across unrelated applicants, even when each stub looks unique to an underwriter who only sees one file.
Edited files tend to fail production method, timestamp trail, and consistency first. Generated files tend to fail issuer matching, model artifacts, and recycled patterns first. Both should fail the deposit cross-check unless the bank statement was manipulated in parallel — which is itself a document-fraud problem.
What to Do With a Suspect File
Do not treat a single tell as a decline. Treat a cluster as a reason to stop relying on the page.
Escalate when math, deposits, and file history disagree. Ask for consecutive stubs and the matching statement pages for the same pay dates. Additional PDFs from the same kit do not resolve a mismatch. Break-test the claim against a source the applicant does not control: payroll-linked verification, an independently sourced employer contact, or a tax transcript. Resistance to any second source belongs in the case notes even if the PDF looks clean.
Reject the document as evidence when the file history shows post-creation editing or generation and the deposits do not corroborate net pay. That is a decision that this file cannot support the income figure, not an accusation. Underwriting and onboarding can offer another documentation path without pretending the stub is real.
Suspicious activity reporting sits on a different track from the credit decision. FinCEN's November 2024 alert on deepfake media flagged AI-generated documents used to circumvent customer identification programs. A generated pay stub in an onboarding packet sits in that family of risk even when the product is a deposit account rather than a mortgage. The FBI's 2024 Internet Crime Report recorded $16.6 billion in reported losses. Income-document fraud is one slice of that landscape, and it is the slice that moves a loan when a reviewer trusts a page that never went through payroll.
When the file is ambiguous, x-ray the file before the next manual round. Watchdoc scores the six checks and shows the evidence instead of asking another analyst to zoom on the same PDF. The first file in the playground does not require an email.
Where Sphinx Fits
Sphinx Watchdoc is the document-forensics layer for this file type. It scores the stub, shows an x-ray of why the score landed, and does it at $0.45 per document with no seats and no platform fee. Across more than 1 million documents processed, Sphinx reports a 94.3% correct verdict, 2.8x more forgeries caught than the baseline teams were using, and under 28 seconds to clear clean files. The Watchdoc playground is free for a first look. For the product story behind those checks, see the Sphinx Doc Fraud launch note. Match the stub to deposits using how to spot a fake bank statement, then treat the pair as one origination problem in loan document fraud detection.
Frequently Asked Questions
How do you spot a fake pay stub?
Recompute gross-to-net and year-to-date math, then match net pay to a bank-statement deposit on or near the pay date. Add file-level checks for production method and timestamps. Visual review of fonts and logos still catches sloppy edits and misses generated pages.
What is the difference between an edited pay stub and an AI-generated one?
An edited-after-creation stub started as a real payroll PDF and was changed later, so original layout and some file history often remain while specific fields no longer reconcile. A generated stub was assembled from a template or a model and never ran through payroll, so the math can close while issuer matching, model artifacts, and recycled patterns fail.
Can a fake pay stub still match a bank statement?
Yes, if the statement was altered in the same kit or if deposits were arranged to mimic payroll. Matching ACH is the strongest single check on a stub reviewed alone, and it is not sufficient when both documents were manipulated. Treat the package as one case.
Do lenders still need to look at pay stubs if payroll data can be connected directly?
Direct payroll or tax-transcript verification is stronger evidence than any PDF. Many applicants still submit stubs, and many products still accept them. Treat an unverified stub as a claim and run deposit and file checks on every file, not only the ones that look odd.
Should a mismatched pay stub automatically decline the application?
A mismatch means the document cannot support the stated income. The credit or onboarding decision can still offer another documentation path. Separate that decision from BSA reporting: if the activity meets SAR criteria, file. Do not use a prettier replacement stub from the same applicant as independent confirmation.

.png)