Fake screenshots threaten online transaction verification as AI makes forgeries easier

Security experts warn that images of payments and reservations are increasingly unreliable as AI-driven editing tools enable convincing fabrications, urging businesses and consumers to verify transactions through direct system checks instead of screenshots.

Screenshots have become a routine way to document payments, bookings, messages and other digital activity, but security researchers warn that they are no longer reliable proof on their own. ESET says editing software and generative AI have made it far easier to fabricate images that look like bank transfers, reservations, refunds or private conversations, creating fresh opportunities for fraud.

Mario Micucci, a computer security researcher at ESET Latin America, told the company that “A screenshot may look convincing, but that does not necessarily mean the payment, booking or conversation is genuine.” The broader point, ESET argues, is that a screenshot only shows what appeared on a screen at a particular moment; it does not prove who made it or whether the underlying transaction ever happened.

That risk is especially acute in online selling, where a buyer can send an image that appears to confirm a bank transfer and pressure a merchant to ship goods before checking the money has arrived. According to guidance from payment-fraud specialists and merchant-focused reporting, the safer approach is to verify funds directly through the bank or payment app rather than relying on an image sent by the other party. Similar scams can involve claims that cash is being held back until a supposed fee is paid, a tactic used to extract an extra transfer from the victim.

ESET also points to romance scams, bogus travel expenses and fake refund claims, all of which can be supported by manipulated screenshots that appear authentic at first glance. In other cases, fraudsters use altered images of investment returns or positive reviews to create the illusion of legitimacy. Security writers have noted that generative AI has lowered the technical barrier still further, making polished forgeries cheaper and quicker to produce.

The problem is not limited to consumers. Customer service, payments and fraud teams can be drawn into time-consuming investigations when screenshots are presented as evidence of completed orders, missing refunds or urgent approvals from senior staff. ESET says even failed attempts can consume resources because staff must then check account histories, transaction logs and delivery records to establish what actually happened. One added concern is the sharing of verification codes: a legitimate company should not need a customer to pass on authentication or recovery credentials to complete an ordinary request.

For individuals, the advice is to treat screenshots as supporting material, not confirmation. For businesses, ESET recommends checking original records, asking for verifiable messages or email trails, using direct links to source systems and, where possible, connecting internal tools by API to trusted platforms. Its central warning is simple: a convincing image may show where to look, but the answer should come from a system the sender cannot control.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.