Homepage
>
Ressources
>
Developers launch MacDoc, an illegal fake passport generator

Developers launch MacDoc, an illegal fake passport generator

An investigation into MacDoc, the fake passport generator built by the same engineers behind OnlyFake, the tool already shut down by US authorities.

Author and Co-Founder at Koncile
By 
Jules Ratier
Last updated: 
September 8, 2026
 - 
8 min read

In February 2026, US authorities shut down OnlyFake, a widely used fake document generator. Weeks later, an identical service reopened under the name MacDoc. Its forgeries are getting past the KYC checks of major institutions including PayPal, Airbnb and Coinbase.

Note: this article is published for informational purposes, to document a fraudulent operator so that fake documents can be better understood and better fought. We have deliberately withheld certain sources and website addresses to avoid amplifying them.

Turnkey fake passport photos

Get a photograph of a fake passport or ID card from any country in the world: that is what the illegal site MacDoc sells. From USD15 per document, paid in cryptocurrency (USDT, which EU crypto-asset service providers have been required to delist since 1 August 2026), you get a file that simulates a photo of your document.

The site's purpose is plainly illegal. It fakes a realistic photograph, as if the document had been shot lying on a table or a piece of fabric, with a set of filters reproducing the imperfections of a phone camera.

What sets it apart is that it is fully reachable through Google, not hidden on the darknet. It also dresses itself in the trappings of legitimacy, with a fully redesigned website and animations you would expect from a real startup.

The site focuses on American fake documents: passports, driver's licenses from every US state, and Social Security cards. It can now also generate passports from many other countries, including France and the rest of Europe.

Specimen of a fake Italian passport generated by MacDoc

Get a photograph of a fake passport or ID card from any country in the world: that is what the illegal site MacDoc sells. From 15 euros per document, paid in cryptocurrency (USDT, which EU crypto-asset service providers have been required to delist since 1 August 2026), you get a file that simulates a photo of your document.

The site's purpose is plainly illegal. It fakes a realistic photograph, as if the document had been shot lying on a table or a piece of fabric, with a set of filters reproducing the imperfections of a phone camera.

What sets it apart is that it is fully reachable through Google, not hidden on the darknet. It also dresses itself in the trappings of legitimacy, with a fully redesigned website and animations you would expect from a real startup.

The site focuses on American fake documents: passports, driver's licenses from every US state, and Social Security cards. It can now also generate passports from many other countries, including France and the rest of Europe.

Airbnb, Coinbase, PayPal, Robinhood: over 120 companies affected

On forums, MacDoc (operating under the OnlyFake name) advertises itself by posting screenshots and emails from accounts opened with fake documents, showing that even the largest companies are affected, and not necessarily equipped with effective forgery detection.

We counted more than 120 companies. Cryptocurrency platforms appear to be the most exposed: Coinbase, Kraken, Bybit, KuCoin, but also neobanks and payment services such as Revolut, N26, Payoneer and eToro, online casinos and betting sites such as Betfair and Stake, hosting providers such as Hetzner and OVH, and freelance marketplaces such as Freelancer and Upwork.

Screenshots of account creation on Ledn, a crypto lending service

The most striking part is that specific KYC vendors are sometimes named. Persona, a specialist in identity verification, is explicitly mentioned in the Ledn case, along with Sumsub, Onfido, KycAid and Itsme. Fraudsters sometimes use their real face together with a document generated by MacDoc.

Below is a map of the players affected, though it could clearly be extended to other sectors such as insurance, real estate, or any B2B sale that requires collecting key corporate documents.

A near-identical relaunch of OnlyFake, shut down by the courts

MacDoc is not actually new. It is a near-verbatim relaunch of OnlyFake, taken down by US federal prosecutors and the FBI in 2026.

The site's creator, Yurii Nazarenko, was charged and pleaded guilty to operating OnlyFake. He was extradited from Romania to the United States in September 2025 and agreed to forfeit 1.2 million dollars, which reportedly matches the site's lifetime revenue. OnlyFake's original domains have been inactive since February 2026.

Who is behind this "new version" of OnlyFake is of course unknown. It cannot be Mr Nazarenko, who is currently facing US prosecution. Most likely part of his team was never charged and picked the original site back up, with very few changes.

When creating an account, the user has to accept an "offer" in the form of a two-page PDF. The new operator did not even bother to update the "OnlyFake" title, and reused the pseudo-contract as it was:

The site tries to reassure its users by invoking, in broken English, a reference to Dutch law, arguing that the services offered are legal.

In accordance with the current legislative regulation, in the State of the Netherlands, the activity of selecting templates, photographic materials and content, the conformity of which is not created by a falsified government-issued document or other sample with the mandatory marking of such, is not prohibited and punishable by law.

This is false on several counts. First, because Dutch law says the exact opposite. Article 234 of the Dutch Criminal Code, titled Stoffen of voorwerpen tot vervalsen bestemd, specifically criminalises producing or holding materials intended to commit forgery. Far from opening the loophole the site claims, Dutch law closes it explicitly. Second, any citizen of the United States or of a European Union member state who produces a forged document and uses it is plainly exposed to prosecution.

No AI, just stacked Photoshop layers

So how does MacDoc work? Journalists sometimes describe AI-generated fake documents, but that is still difficult today, because the most widely used general-purpose models (GPT, Claude, Grok, Gemini, DeepSeek) enforce a blanket ban on forgery. And even without those safety filters, they are still unable to generate a document with sufficient internal consistency and photographic quality. Rendering text inside images, both the letterforms and their placement, remains crude. Anti-fraud filters in LLMs are in fact getting stronger, to the point where they now get in the way of legitimate fraud research.

MacDoc's technology stays fairly basic. The user fills in a form, and the values are applied to an ID document image as stacked layers. The tool then applies blur, noise and grain filters to produce a photographic look. The result is convincing enough to the naked eye. Finally, it generates fake phone camera metadata, complete with capture date and handset details, to simulate a genuine photograph.

MacDoc reproduces exactly what template farms do, those sites selling documents in editable formats such as Photoshop .psd. One telling detail: MacDoc's own sample file, itself inherited from OnlyFake, still carries the traces of all its Photoshop layers, offering a rare look inside the forgery workshop. Curious that this file had not been cleaned up at the time of writing.

The tool takes forgery all the way, generating fake MRZ strips, the lines of fixed-width characters printed at the bottom of a passport's data page and on the back of an ID card. It computes the correct validity windows by country and document revision, and generates national numbers structured according to official formats. There is, in other words, an algorithm behind every fake passport and every fake ID card template.

Even the photos are not generated. The internal call returns a stored image, one file traced under the name JohnWick.png, evidence of a frozen library rather than on-demand creation. Signatures are simply drawn with a font. Final files are stored on Amazon S3 and served through expiring links, and removing the watermark, which is the paid and actually usable version, goes through a server call.

Who uses the fakes, and why?

Hard data on how widely MacDoc is used is difficult to obtain. Semrush offers a few useful signals: the site is used mostly in the United States, and ran an aggressive backlink buying strategy to climb Google's rankings, with more than a million links to date.

Semrush data on traffic to Onlyfake.org

According to the forums, the primary fraudulent use is opening accounts under false identities, which blocks internal investigations from tracing the ultimate beneficial owner. Platforms and sites that fall for these documents take on serious legal exposure, and potentially breach their obligations on anti-money laundering, terrorist financing and international sanctions, whether US sanctions lists or EU asset freezing rules.

At Koncile, we have seen the phenomenon reach our own chatbot. Visitors who had skimmed too quickly and understood only that we do OCR and document fraud detection asked us to change the age on their ID card, both up and down. Some went as far as requesting a document built from scratch to claim a nationality.

B2C fraud may be hiding something more serious and more insidious: forged documents inside business-to-business relationships, between professional customers and suppliers. The volume may be smaller, but the stakes are far higher.

Why do these fakes clear standard checks?

A MacDoc document is clean on the surface. The image looks like a phone photo, it reads correctly, its MRZ is well formed, the national number has the right structure. It can clear basic checks. Most detection tools start with visual analysis: they run machine learning models trained to spot known anomalies in photo files, such as compression analysis, detection of pasted patches or rectangles, and grain tests.

The tool then reads the file's metadata, such as the creating software or the modification date, to detect alterations. It can also compare against the metadata of authentic documents of the same type. That method is powerful, but works better on other document families such as bank statements, proof of address, payslips and other natively digital PDFs.

The fraud forums are unambiguous: they show KYC checks at fintechs, online banks and crypto institutions being defeated by these documents. They specifically name Ledn, a crypto lending service, which nonetheless relies on Persona.

So why are these fraud checks failing? "There is no such thing as 100% detection" is not a sufficient answer. The reality is that the tool is built around a solid understanding of KYC controls, precisely in order to circumvent them.

First: the tool ships an actual metadata editor to fake device capture, including handset brand, timestamp and GPS coordinates. It offers a long list of phone models.

Screenshot of MacDoc's fake phone metadata feature

Second: the tool gets past forensic analysis, which looks for compression artefacts, local retouching, rewritten areas and typical editing patterns, simply by starting from a genuine source document. These detections are often ineffective, and frequently unreliable on this type of document.

Anomaly detection through consistency checking is arguably one of the most powerful methods, but it requires specifying precisely which checks are relevant for each document type, which can overwhelm compliance teams facing the sheer variety of documents their customers can produce across nationalities.

MacDoc does not, in principle, make internal consistency errors. MRZ strips, for instance, are auto-generated by the tool, which then lets the user customise each field.

Fake Argentinian ID card on MacDoc

Do these fake documents have detectable flaws?

A trained analyst with the right tooling will find plenty of flaws in this kind of document, which we hope will deter would-be forgers. We will cover five known cases, though at least a dozen anomalies could be listed.

Formatting of the data. Address, name, number and code formats are very often wrong. The problem is that the tool hands control to the user to type their own address into the form, and the user usually has no idea of the exact, uniform format the administration follows: order of address components, character count of alphanumeric codes, presence or absence of punctuation, acceptance of special characters, and so on. This kind of deviation is well documented and almost always triggers alerts in anti-fraud tools.

Traces in the metadata. The file emitted directly by MacDoc carries plenty of metadata traces. Even though the tool claims to generate fake surface metadata, fraud detection tools progressively record the compression signatures and identifiers they encounter. Alerts fire systematically.

2D-DOC, Data Matrix, QR codes and other barcodes. Every document carrying a QR code or a 2D-DOC code, as used in France, is a problem for forgers. A 2D-DOC Data Matrix can be read with a dedicated tool using a public key, published by the administration for third-party verifiers such as Koncile. Inside it, you can recognise the electronic signature of France Titres, the agency that issues French identity documents. It is even possible to generate a Data Matrix containing a cardholder's identity data.

What is impossible is producing a code carrying a valid electronic signature without the private key, which only the administration holds.

Forgers therefore have two options:

  • generate a Data Matrix that displays the holder's information but whose cryptographic signature is invalid; or
  • copy and paste a Data Matrix stolen from another ID card. In that case the cryptographic signature checks out, so the code can be verified as issued by France Titres, but the data it contains simply will not match the holder's details.

The example below shows a Data Matrix that was visibly taken from another ID card:

Data Matrix code on the back of a French ID card
Redacted extract from the Data Matrix read off a French ID card

Visible flat areas left by the layers.

Because they work in layers, image editors leave graphic cut-out traces that algorithms can detect. It is quite clear in the example below: the digits stand out against a perfectly smooth, uniform surface. Detection algorithms can then reconstruct the layers after the fact.

Close-up of an ID card

Font checking. Identity documents use proprietary typefaces that are not publicly available. Anti-fraud tools compare selected characters against known references extracted from tens of thousands of trusted documents.

You can see it in the following case, taken from a MacDoc document: the chosen font gets close to the genuine typeface, but the naked eye can still tell the difference.

Your questions about MacDoc

Is MacDoc legal?

Generating a fake identity document or a fake supporting document to deceive an organisation is illegal in virtually every jurisdiction. Operators often argue that they do not create forgeries, only content, and make the user "consent" at every generation. That changes nothing about the actual use, which falls squarely under the law. The founder of OnlyFake, MacDoc's predecessor, pleaded guilty in US federal court and faces up to 15 years in prison.

Does MacDoc really use artificial intelligence?

Not in the generative sense. Analysis of the tool points to a rules-and-database engine: templates, structured national numbers, MRZ transliteration, photos drawn from a frozen library. It is infrastructure AI, not an AI inventing a passport.

How does Koncile detect a document produced by this kind of tool?

By combining forensic image analysis, a full read of the metadata, and above all business consistency checks: recomputing amounts, verifying regulatory rates, cross-referencing the documents in a single file. Every anomaly feeds a fraud score built from more than 150 signals.

Which documents are forged most often?

Payslips, tax assessment notices, insurance claims history statements, bank statements and identity documents. They are targeted because they serve as supporting evidence in high-stakes decisions: renting, lending, insurance, onboarding.

Is Koncile's fraud detection available via API?

Yes. Detection works both on the platform and through the API, under an Enterprise contract, and it carries OCR extraction in the same flow.

Is MacDoc the same thing as OnlyFake?

In practice, yes. MacDoc is OnlyFake's new brand, relaunched after the service was dismantled. Same operators, same forums, same Telegram channels, same generation engine. Only the domain name and the site's styling have changed. The site even presents itself as the best alternative to OnlyFake.

What happened to OnlyFake?

OnlyFake was targeted by US federal prosecutors and the FBI. Its creator, Yurii Nazarenko, was extradited from Romania in September 2025, pleaded guilty and faces up to 15 years in prison. OnlyFake's original domains have been inactive since February 2026. But the service did not disappear: it reopened under the name MacDoc.

Sources

  • US Department of Justice (DOJ), press release on the charges and guilty plea of OnlyFake's creator
  • 404 Media, the original investigation that exposed OnlyFake
  • Cybersecurity press (The Register, BleepingComputer, The Hacker News)
  • Threat intelligence reporting on the OnlyFake and MacDoc template farms
  • MacDoc's own website
  • Field feedback from our client conversations and from our own platform

The agents that automate your documents

Get ahead on automation. See how Koncile can simplify your operations.
Discover Koncile
Discover Koncile
Our latest ARTICLES

Real life insights on document automation

All our ressources
All our ressources
News

Developers launch MacDoc, an illegal fake passport generator

In February 2026, US authorities shut down OnlyFake, a widely used fake document generator. Weeks later, an identical service reopened under the name MacDoc. Its forgeries are getting past the KYC checks of major institutions including PayPal, Airbnb and Coinbase.

Read the article
FEATURE

Document deepfakes: catch the fakes slipping past your checks (2026)

In 2026, document fraud has a new face: the document deepfake, a fake generated entirely by AI. According to Shufti's Identity Fraud Index 2026, it's the fastest-growing fraud category, with an annualized increase estimated at nearly 3,900%. What sets these fakes apart: they're clean on the surface. Here's how to detect the ones still slipping past your checks.

Read the article
Comparative

Top 10 Best Document Fraud Detection Software in 2026

Document fraud has outgrown Photoshop. In 2026, the fastest-growing threat is the AI-generated fake: invoices, bank statements and payslips produced from scratch, pixel-perfect, with clean and consistent metadata. Here is our comparison of the 10 best document fraud detection software platforms every finance and risk team should know, and how to choose the right one.

Read the article
Comparative

5 Best French OCR Solutions to Extract Data from Your Documents

Five French OCR solutions now make it possible to automatically extract data from your invoices, contracts, and accounting documents using optical character recognition, with hosting based in France. Here's our overview.

Read the article
FEATURE

MCP OCR: How Koncile Lets AI Agents Extract Documents Natively

Until recently, connecting an OCR engine to an AI assistant meant writing custom code, managing API calls manually, and building the glue between your language model and your document processing pipeline. With the Model Context Protocol (MCP), that entire layer disappears. At Koncile, we built an MCP OCR server so that Claude, Cursor, or any compatible AI agent can extract, read, and manage documents without a single line of integration code

Read the article