News
12 min read

How to Spot Forged Documents and Manipulated PDFs

Recognise forged PDFs, certificates and commercial register extracts in your SME verification process: technical checks and structured processes for your security.

A magnifying glass rests on a printed document with digital security features, with a laptop showing an open PDF file analysis reflected in the background.
A magnifying glass rests on a printed document with digital security features, with a laptop showing an open PDF file analysis reflected in the background.

The growing threat of document fraud in the German Mittelstand

Advancing digitalisation in the German Mittelstand brings considerable efficiency gains, but at the same time it opens up new, high risk attack surfaces for criminals. Professional forgers increasingly rely on generative AI tools today to create forged invoices, manipulated PDFs, forged certificates or falsified commercial register extracts. These high quality imitations are barely distinguishable from genuine documents with the naked eye in a hectic working day. For your company that means a high risk: without structured, automated verification processes, manipulated documents can infiltrate your entire supply chain unnoticed and trigger critical financial approvals.

That this is no theoretical scenario is confirmed by the persistently high case numbers in the police crime statistics of the German Federal Criminal Police Office (BKA). This high number of fraud offences shows how omnipresent the threat of fraudulent activity is in business life today. Managing directors and IT leads in mid-sized businesses face the urgent task of professionalising their verification processes comprehensively. Modern, reliable protection today requires far more than a manual visual inspection by your staff if you want to successfully avert far reaching financial damage and legal consequences.

In your company, manipulated documents can cause considerable operational and financial damage at three critical interfaces in particular:

  • Purchasing and finance: manipulated invoices with bank details changed unnoticed (known as payment fraud) lead directly to misdirected transfers to criminals.
  • Human resources and HR: forged certificates and fraudulently obtained proof of qualification during new hires damage the quality of work and put a lasting strain on the whole team.
  • Compliance and partnerships: falsified commercial register extracts fake ownership structures and endanger the legally sound protection of your supply chain.

To counter these dangers effectively and sustainably, proactive verification at the technological level is indispensable for your operations. This concerns not only internal compliance officers or security officers, it is an essential pillar of a holistic cybersecurity strategy for mid-sized businesses. CAVRIX reliably supports you in checking digital documents, images and emails for authenticity in real time using modern, automated verification methods, and in blocking fraudulent attacks in good time.

The anatomy of manipulated PDFs: metadata and structure in focus

To reliably expose forged documents such as manipulated PDFs, certificates or commercial register extracts in your verification process, a purely visual inspection is long since no longer enough. Criminals use highly developed tools to alter sensitive passages of text without this being immediately obvious on screen. Structured file forensics is therefore indispensable for your IT security and fraud prevention. Through targeted analysis of metadata and hidden structural layers you can systematically uncover and verify suspicious editing traces.

Manipulated PDF files frequently leave characteristic anomalies in their metadata and in their internal object structure. For internal auditors and compliance officers this in depth check is a useful tool. However, it delivers indications and not proof: metadata can be changed or removed with freely available tools, and a technically clean PDF can still be wrong in substance. An inconspicuous finding is therefore never a proof of authenticity, only the removal of one point of suspicion.

We recommend that you align every verification process with the following six checks as standard:

  • Analysis of the creation dates: comparing the creation date (CreationDate) with the modification date (ModDate) reveals timing discrepancies that would be impossible if the file had been generated from original sources.
  • Verification of the PDF producer: the creation tool named in the metadata has to match the supposed issuer. Free online editors as the "producer" of an official certificate are a clear warning sign.
  • Tracing hidden structural layers: PDFs allow incremental updates in which changes are appended to the document instead of overwriting the original. If several such sections are present, earlier versions can be reconstructed. Conversely, anyone who has the file rewritten removes this history entirely. A PDF with only one section is therefore no evidence that nothing was changed.
  • Validation of digital signatures: check whether an electronic signature or an electronic seal is intact and whether the certificate traces back to a qualified trust service provider from the EU trust list. Under the eIDAS Regulation, only the qualified electronic signature is legally equivalent to a handwritten signature, a simple or advanced signature is not.
  • Checking the XML metadata (XMP): a deep look into the XMP data stream often reveals the history of editing steps and the software suites used.
  • Analysis of embedded fonts: characters inserted later often use deviating or only partially embedded fonts. Several subsets of the same font within one document are a typical indication of subsequent intervention.

One note on how to weigh this up: image forensics methods such as Error Level Analysis (ELA) are often promoted online as a simple forgery test. Professionally they are considered disputed, because compression artefacts, scaling and repeated saving regularly lead to misinterpretation. So do not rely on colourful ELA renderings, rely on verifiable structural features and on comparison with the issuer. By linking these forensic analyses with organisational controls you protect your company from financial damage and reputational loss. Integrating such routines into your overall cybersecurity ensures that forged documents stand no chance in the Mittelstand.

Plausibility and logical context: checking the whole picture systematically

Professional document forgeries today often shine with a flawless look, because attackers use high resolution templates and digital tools. That makes it all the more important for you to check the logical context and the substantive plausibility in a structured way. Despite a perfect graphical surface, fraudulent documents almost always show contradictions in content, because the logical connections in the background are not thought through consistently. If, for example, a commercial register number does not match the stated local court, or the issue date of a certificate predates the founding date of the issuing institution, you expose the manipulation immediately.

  • VAT logic: check whether the VAT rates shown and the calculated tax totals match exactly in mathematical terms. Criminals frequently fail at correct rounding or at the logic of tax exemptions.
  • Timing plausibility: compare the invoice or issue date with the actual service period. A backdated document whose metadata reveals a recent creation date is highly suspicious.
  • Deviating bank details: watch out for sudden account changes at known suppliers or deviating IBAN country codes that do not match the official company headquarters.
  • Register consistency: compare data from commercial register extracts directly with the official portals to make sure that the object of the company, the managing directors and the registered capital match.

To catch such discrepancies systematically, you should embed these checks firmly in the daily routines of your mid-sized business. Only through seamless logical validation do you prevent expensive invoice fraud and protect your liquidity. An automated pre check ensures that such anomalies stand out immediately, before damage occurs, and thereby strengthens overall cybersecurity across the whole company.

Exposing forged certificates: what your HR department has to watch for

Recruiting qualified specialists is decisive for the success of your company, yet the danger of application fraud is rising. Manipulated documents, forged diplomas and embellished employment references can be produced with minimal effort in the digital age. If your HR department overlooks forged evidence, you face not only costly wrong decisions but also considerable security risks for your entire IT and operational organisation. A systematic verification process protects your SME from expensive bad hires and compliance breaches.

  • Visual defects: watch for uneven typography, inconsistent fonts within one document or blurred logos of the issuer.
  • Contradictions in content: compare the details in the certificate precisely with the CV and check whether issue dates and employment periods fit together logically.
  • Technical irregularities: PDF documents often show untidy formatting when texts have been inserted later or metadata has been manipulated.
  • Missing verification features: many universities issue certificates with a QR code, a check number or an electronic seal. If these features are absent, that is a reason to follow up, but not proof, because not every issuer uses such procedures.

To minimise these risks, your HR department should establish proven checking methods. Alongside the purely visual inspection, direct comparison and follow up with the issuer are the most effective. Obtaining a reference or confirmation of authenticity directly from the university or the previous employer quickly uncovers inconsistencies. Bear the legal framework in mind: under Section 26 (1) of the German Federal Data Protection Act (BDSG), applicant data may only be processed to the extent necessary for the decision on establishing an employment relationship. Enquiries with former employers therefore usually require the applicant's consent.

For internal compliance officers and IT leads, verifying the authenticity of documents is a central building block of risk mitigation. Since fraud prevention and digital verification have to be integrated seamlessly into modern security structures, IT security is a matter for the board in mid-sized businesses. Through automated digital verification processes and verified workflows you relieve your HR teams and protect your company sustainably from the dangers of manipulated documents.

Commercial register extracts under scrutiny: reliably fending off identity fraud

A forged commercial register extract is a powerful tool for criminals to hijack the identity of real companies or to present entirely invented shell companies as reputable business partners. In the hectic day to day business of German SMEs, manipulated documents often only come to light when invoices go unpaid or deliveries fail to arrive. Fraudsters frequently use outdated templates from long deleted companies or manipulate existing PDF extracts to enter false authorised representatives. For managing directors and IT leads this means an enormous risk. Careful checking of documents before signing a contract effectively protects your company from financial damage and strengthens supply chain security in the sense of modern compliance requirements.

Check criterionTarget state (official)Signs of manipulation
Name of the local courtThe court named must be the one with jurisdiction over the company's head office.Naming local courts without jurisdiction or historical designations after territorial reforms.
Register numberEvery number (HRB or HRA) is uniquely assigned in the official justice portal.Digit sequences that lead to a completely different company in the register or do not exist at all.
Format and layoutConsistent typefaces, clean formatting of the XML or PDF documents of the state justice administration.Graphically untidy edges, uneven line spacing or text elements pasted in later.

To rule out manipulation, a direct online comparison via the joint register portal of the German federal states at handelsregister.de is the safest method. Retrieving register information there has been free of charge since August 2022. Via this platform you can view the current status of the entries and verify the details on the PDF document presented to you. If the designation of the local court or the register number does not match the official entries, an attempted fraud is likely. Internal security officers should integrate these verifications into the purchasing process as standard in order to avert financial and legal risks. At CAVRIX we support mid-sized companies with tailored solutions in the areas of cybersecurity and digital verification, so that you can effectively protect your business processes from identity theft and fraud.

Establishing a verification process in your company: how to protect your workflows

The systematic verification of digital records must not be left to chance in your business. To stop manipulation effectively, you have to integrate fixed control points directly into the daily routines of your core departments. Defining clear responsibilities and standardised workflows is a management task, so that no unchecked document passes through business critical processes. According to the Bitkom study Wirtschaftsschutz 2025, 87 percent of the companies surveyed in Germany were affected by data theft, espionage or sabotage. 22 percent reported damage from phishing, 4 percent damage from deepfakes. That shows that fraud prevention and IT security have to be understood as a matter for the board if you want to avert financial damage to your business.

  • Purchasing: before approving new suppliers or large orders, commercial register extracts and bank details have to be validated through automated data consistency checks, in order to rule out fraudulent invoice changes early on.
  • Finance: invoices in PDF format go through a technical check for altered metadata or account data manipulated after the fact before payments are released, so that forged records and payment flows are blocked immediately.
  • HR (human resources): certificates and proofs of qualification from applicants are systematically checked for authenticity and logical consistency by compliance officers as part of a standardised verification process, in order to minimise the risk of forged details.

Through clearly defined responsibilities and standardised checklists you establish a reliable security culture. These controls can be combined seamlessly with modern compliance policies. Without such a structure you risk manipulated commercial register extracts or forged certificates going unnoticed and creating long term liability risks.

Reliable protection, however, requires a combination of organisational policies and automated technical systems. Experienced teams such as the one at CAVRIX support you in embedding these verification processes seamlessly into your IT infrastructure, in order to ensure continuous security in the spirit of NIS2 or ISO 27001. For individual advice on digital verification processes in mid-sized businesses and on securing your data flows, our team is available to you at any time via direct contact at info@cavrix.de.

Digital verification with CAVRIX: your shield in the Mittelstand

The growing professionalism of forgeries in business dealings makes systematic protection indispensable. The German Federal Office for Information Security (BSI) states in its current situation report that the threat level in cyberspace remains worryingly high. With the modular offerings from CAVRIX for cybersecurity and compliance, your company gains a reliable set of instruments to fend off fraudulent activity such as manipulated PDFs, forged evidence or manipulated commercial register extracts at an early stage. Our solutions plug seamlessly into your existing structures in order to preserve the integrity of your digital supply chains and business processes throughout.

These protection mechanisms are controlled efficiently via the CAVRIX Command Center. This intuitive user interface allows your team to monitor the security status in real time, to react to points of suspicion directly in the chat tools you already use and to generate complete evidence for official audits. By linking our deep expertise in verifying digital records with proactive security monitoring, we close dangerous security gaps before financial or regulatory damage occurs.

  • Automated metadata analysis to identify subsequent PDF manipulation.
  • Comparison of certificate chains and digital signatures directly in the operational workflow.
  • Centralised alerts for conspicuous deviations in contracts or extracts.
  • Audit proof archiving of the verification steps. For records relevant for tax purposes, the requirements for immutability and traceability follow from the German GoBD, not from NIS2.

With this holistic approach you minimise the liability risk of the management and strengthen the trust of your business partners. For individual questions about your verification processes or for detailed advice on securing your IT infrastructure, you can reach our experts at any time by email at info@cavrix.de.

Frequently asked questions

How can I check the metadata of a PDF file for manipulation?

You can evaluate PDF metadata with special viewers or PDF checking tools. Watch for inconsistencies between the creation date and the last modification date. If an official document names a simple presentation program or an unusual image editing tool as the 'producer', that is an indication of subsequent editing. But bear in mind: metadata can be changed or deleted with freely available tools. It delivers points of suspicion that you should confirm by following up with the issuer.

How do I recognise a forged employment reference during recruitment?

Watch for formal inconsistencies such as inconsistent fonts, crooked lines or pixelated logos of former employers. It is also striking when consistently very good assessments meet a CV full of gaps. Such features are points of suspicion and not evidence. If you suspect something, contact the issuer directly and use a contact channel you have researched independently rather than the number given in the document.

How can the authenticity of a commercial register extract be verified?

A commercial register extract can most reliably be verified by carrying out a direct online comparison via the joint register portal of the German federal states at handelsregister.de. Compare the data held there, such as the register number, the competent local court and the authorised representatives, with the document in front of you in order to expose forgeries from shell companies.

What role does the plausibility check play in a company?

The plausibility check compares the document with the business context. A document is implausible if, for example, tax rates do not match the country of issue, the IBAN deviates from the existing master data or service periods show logical contradictions. Such deviations are often the first signs of document fraud.

How does CAVRIX protect my company from document fraud?

CAVRIX protects your company through a comprehensive service portfolio. We combine our managed services such as cybersecurity and compliance with the Command Center. That helps you establish proactive security checks, automated data consistency checks and NIS2 compliant verification processes directly in your everyday workflows.

Can I recognise manipulated documents without expensive software?

Yes, many forgeries can be exposed through simple organisational checks alone. These include visual inspection under magnification, the free comparison of register numbers via handelsregister.de and the manual review of PDF metadata. The most effective free measure remains following up with the issuer via a contact channel researched independently. For consistent quality, automating these checks is advisable.

Where does your company stand?

30 minutes, free, no commitment. We show you where you stand.