MacDoc: a fraud as easy to make as it is to detect

Dernière mise à jour :

August 11, 2026

5 minutes

In February 2026, US authorities announced the end of OnlyFake, the best known fake document generator on the market. A few weeks later, the same service reopened under a new name, MacDoc, presenting itself as the best OnlyFake alternative. Its fakes are already circulating in the files that insurers, landlords and lenders receive. The real question is no longer whether these fakes exist, but whether your checks can catch them.

An investigation into MacDoc, the fake-document generator that succeeded OnlyFake: what it is, how it works, and how to spot its forgeries.

Screenshot of the MacDoc website with a banner (FRAUD FRAUD FRAUD …) and the company logo

The takedown that stopped nothing

On paper, the case was closed. US authorities and the FBI announced that Yurii Nazarenko, known online under the alias John Wick, had been charged and had pleaded guilty to operating OnlyFake.

According to the Department of Justice, the service produced at least 10,000 fake digital documents between 2021 and 2024 and generated several hundred thousand dollars. Its creator, extradited from Romania in September 2025, faces up to 15 years in prison and agreed to forfeit 1.2 million dollars. The historical OnlyFake domains have been inactive since February 2026.

A clean takedown, in appearance. Except OnlyFake is not dead. The same service reopened, within weeks, under the name MacDoc, with a redesigned website but an unchanged engine.

How we know MacDoc is OnlyFake with a new coat of paint

The continuity is not a guess, it can be read in the operators' own traces.

The same accounts, on the same Russian language forums, redirected their ads to the new domains. Above all, they went back to edit their old OnlyFake ads to point them at MacDoc. Yet on a forum, only the original author can edit their own posts: this is the demonstration, in the most administrative way possible, that the accounts behind OnlyFake and those behind MacDoc are the same. The support Telegram channels did not change, and a historical admin domain stayed visually identical to OnlyFake until its last capture, in September 2025.

The product gives itself away too. Interface, layout, dropdown lists, hologram option and metadata editor are identical to those of OnlyFake. Some contact links still reference handles containing the word onlyfake. The MacDoc domains were registered through a known anonymization service and hosted behind Cloudflare. On the Koncile team, we found exactly the same software traces as on the old service.

What you find when you open the hood

Contrary to what its marketing suggests, MacDoc is not a powerful generative AI. The engine does not create a passport from scratch, it assembles it from rules and databases. It computes correct validity windows by country and revision year, generates national numbers structured according to official formats (Italian codice fiscale, Malaysian MyKad, Argentine CUIT), handles Cyrillic to Latin transliteration for the MRZ, and pulls from country specific name databases.

The photos are not even generated: the internal call returns a stored image, a file found under the name JohnWick.png, proof of a fixed library rather than on demand creation. Signatures are drawn by simple font rendering. The final files are stored on Amazon S3 servers and served via expiring links, and removing the watermark, the paid and actually usable version, goes through a separate server call.

For a defender, this is the decisive point. A tool built on templates and rules produces regular documents, therefore regular fingerprints. What is reproducible is detectable.

The site's legal veneer

MacDoc takes care of its legal alibi. On every document generation, a popup asks the user to confirm they will not use it illegally. This acknowledgment has one purpose: to manufacture a plausible deniability artifact and shift criminal liability onto the user, at the exact moment of production.

The site also hides behind a pseudo legal framework, claiming that selecting templates and content would not be prohibited. The argument is thin. In practice, the real use, KYC bypass and building fraudulent case files, falls under the law, and a French or American user remains subject to their own jurisdiction, whatever the site's hosting.

Who uses it, and why it concerns you

The vast majority of uses of this kind of tool are fraudulent: opening accounts under a false identity, passing a KYC check, building a case file with fake supporting documents. The recipients of these documents, companies and case handlers, are the real victims.

At Koncile, we saw the phenomenon reach into our own chatbot. Visitors, having read too quickly that we do OCR and document fraud detection, asked us to change the age on their ID card, up or down. Some went as far as requesting a fake built from scratch to claim a nationality. The signal is clear: the demand for fake documents has become ordinary, and it lands on the desk of the organizations that receive these documents.

Why these fakes pass classic checks

A document produced by MacDoc is clean on the surface: it looks good, it reads correctly, its MRZ is well formed, its national number has the right structure. That is precisely why it passes basic checks. Most detection tools rely first on visual analysis and on reading the file's metadata, such as the authoring software or the modification date.

The problem is that these signals are not enough, and MacDoc knows it: the tool literally ships a metadata editor to disguise them. Based on what we observe on pay slips, only 30 to 40% of fakes also reveal a metadata anomaly. In other words, most clean fakes slip through a control that only looks at the file and its metadata.

Koncile's angle is different. A document generated from a template reproduces the form, but rarely the internal logic and the context. That is where it gives itself away. We combine three technologies.

Forensic image analysis. Detection of compression artifacts, local retouching, rewritten areas, and editing patterns typical of documents created by tools like MacDoc.

Metadata inspection. Authoring software, inconsistent timestamps, suspicious layers, comparison with the metadata of authentic documents of the same type. It is the foundation, but we do not stop there, precisely because this signal can be disguised.

Contextual anomaly detection, co-built with business experts. This is our real difference. On a pay slip, we recompute the totals, we check that contribution rates are applied correctly and that gross and net are consistent. To properly falsify a pay slip, you would have to recompute everything correctly, everywhere, which fraudsters rarely do. On an invoice, the same logic catches an invoice manipulation by reconciling totals and line items. Across the documents of a single file, we check that it is really the same person, that the dates match, that nothing is logically impossible.

Each detected inconsistency feeds a fraud score from 0 to 1, computed from more than 150 checkpoints. Above a threshold, the document is flagged and the anomaly is escalated to the right handler with its context. It is this layer of logical and regulatory consistency that catches a nice but fake MacDoc document where a purely visual or metadata analysis would let it through. Our clients activate it where document fraud costs the most: rental guarantees and tenant files, consumer credit, insurance and KYC onboarding.

The other fake document generators to know

MacDoc is not alone. The ecosystem of generators and template farms counts dozens of players, and it shares the same logic of permanent rebranding. Among the names that come up most often:

  • OnlyFake: the direct predecessor of MacDoc, a historical reference in the field before its takedown.
  • VerifTools: a fake document marketplace seized by the FBI and Dutch police in August 2025, back online on a new domain in under 24 hours.
  • Doc Juicer: a generator focused notably on pay slips.
  • Fakedocshop: a subscription based template farm.

What all these services have in common: they sell form, not consistency. And a domain seizure or an arrest removes a URL or a person, never the network or the capability. That is precisely what makes them detectable by an analysis that goes beyond pixels and metadata.

Your questions about MacDoc and document fraud

Is MacDoc legal?

Generating a fake ID or a fake supporting document to deceive an organization is illegal in almost every jurisdiction. Operators often argue that they do not create fakes, only content, and make the user consent on every generation. This changes nothing about the real use, which falls under the law. The founder of OnlyFake, MacDoc's predecessor, in fact pleaded guilty before US justice and faces up to 15 years in prison.

Why do MacDoc fakes pass classic checks?

Because they are clean on the surface: realistic visual rendering, valid MRZ, well formed numbers, and metadata disguised by the tool itself. Checks based only on visual analysis or metadata see nothing wrong. It is the logical and contextual inconsistencies, invisible to those methods, that give them away.

Does MacDoc really use artificial intelligence?

Not in the generative sense. Analysis of the tool shows a rule based, database driven engine: templates, structured national numbers, MRZ transliteration, photos from a fixed library. It is AI in the infrastructure sense, not an AI that invents a passport. Which, for a defender, is rather good news: a systematic tool produces regular, detectable fingerprints.

How does Koncile detect a document generated by this kind of tool?

By combining forensic image analysis, metadata inspection and above all business logic consistency checks: recomputing amounts, verifying regulatory rates, cross checking across the documents of a file. Each anomaly feeds a fraud score from 0 to 1 built from more than 150 signals.

Which documents are the most falsified?

Pay slips, tax notices, insurance statements, bank statements and ID documents. They are targeted because they serve as supporting documents in high stakes decisions: renting, credit, insurance, onboarding.

Is Koncile fraud detection available via API?

Yes. Detection works on the platform and via API, under an Enterprise contract, and bundles OCR extraction into the same flow.

Is MacDoc the same as OnlyFake?

Yes, in practice. MacDoc is the new brand of OnlyFake, relaunched after the service was taken down. It is the same operators, on the same forums, with the same Telegram channels and the same generation engine. Only the domain name and the website's look changed. The site even presents itself as the best OnlyFake alternative.

What happened to OnlyFake?

OnlyFake was targeted by US authorities and the FBI. Its creator, Yurii Nazarenko, was extradited from Romania in September 2025, pleaded guilty and faces up to 15 years in prison. The historical OnlyFake domains have been inactive since February 2026. But the service did not disappear: it reopened under the name MacDoc.

Sources

  • US Department of Justice (DOJ), press release on the charge and guilty plea of the creator of OnlyFake
  • 404 Media, initial investigation that revealed OnlyFake
  • Cybersecurity press (The Register, BleepingComputer, The Hacker News) on the VerifTools seizure
  • Threat intelligence on the OnlyFake and MacDoc template farms
  • Official MacDoc website
  • Field feedback from our client conversations and our own platform

Move to document automation

With Koncile, automate your extractions, reduce errors and optimize your productivity in a few clicks thanks to AI OCR.

Author and Co-Founder at Koncile
Jules Ratier

Co-fondateur at Koncile - Transform any document into structured data with LLM - jules@koncile.ai

Jules leads product development at Koncile, focusing on how to turn unstructured documents into business value.