Skip to main content

How Scammers Use Canva and Design Tools to Fake Bank Documents

ByUpdated September 4, 2026
Reviewed by
Fact checked by
How Scammers Use Canva and Design Tools to Fake Bank Documents

A forged bank statement used to look like exactly what it was: a photocopy with the numbers whited out and retyped, or a scanned image with visibly mismatched fonts. That is no longer the baseline. Free, browser-based design tools built for making social media graphics and event flyers, Canva chief among them, now let anyone drag a bank's logo onto a template, swap in a name and a balance, and export a document that looks, at a glance, like it came from a real financial institution. The tools were never built for forgery. They were built for speed and polish, and speed and polish are exactly what a convincing fake needs.

The documents built this way show up wherever a scammer needs a stranger to believe a specific financial fact quickly: a landlord who wants proof a prospective tenant can pay rent, a romantic partner who claims to be a wealthy investor, a company employee asked to wire money against an urgent-looking invoice. The FBI's Internet Crime Complaint Center (IC3) logged more than 1 million complaints and $20.877 billion in reported losses in 2025 alone, a 26 percent increase from the year before. Business email compromise, romance fraud, and real estate and rental fraud, three categories that lean heavily on a forged or falsified document, are tracked as separate categories in the bureau's own numbers, and all three grew.

This article looks at why a Canva-quality forgery now beats casual visual review, walks through real prosecuted cases involving faked bank documents and fabricated balances, compares what a genuine statement looks like against a forged one, and lays out concrete steps for checking whether a financial document is real before anyone sends money because of it.

KEY TAKEAWAYS

  • IC3 recorded $20.877 billion in reported fraud losses in 2025, a 26 percent increase over 2024, with business email compromise, romance fraud, and rental fraud all growing.
  • Free, template-based design tools have collapsed the skill and time needed to produce a convincing fake bank statement, proof-of-funds letter, or payment screenshot.
  • No verified prosecuted case names Canva specifically as the forgery tool; the real DOJ case against Daejon Love describes fabricated bank and investment balances made with unnamed phone applications.
  • A separate, documented Canva-related scam uses the platform to host phishing links rather than to forge statement images, and the two techniques should not be confused.
  • A payment confirmation screenshot from Zelle, Venmo, or Cash App is never proof a transfer happened; only a matching deposit in your own banking app confirms it.
  • File metadata that names a design tool or word processor instead of a bank statement system is a meaningful red flag, though its absence does not prove a document is genuine.
  • The most reliable defense is procedural, not visual: call the bank using a number you looked up yourself, request the original file, and use a bank or title company verification channel before acting on any document.

Why a Forged Bank Document Now Fools a Casual Reader

Every PDF and image carries some digital residue of the software that made it. Document-forensics analysts who study forged bank statements for a living note that one of the fastest ways to catch a fake is invisible on screen: a file whose metadata records a design tool, a photo editor, or a word processor as the program that last touched it, rather than the automated statement-rendering system a real bank actually uses. Banks generate monthly statements from core-banking systems built for that single purpose. Nobody at a bank opens a design app to produce your statement, and no legitimate proof-of-funds letter was ever laid out on a template meant for a birthday flyer.

From a Steep Learning Curve to Drag and Drop

Convincing forgery used to require real skill: cloning tools, layer masking, matching a font by eye. That skill barrier kept the volume of good fakes relatively low. A template-based design tool removes most of it. A scammer starts from a blank canvas, drops in text boxes for a name, an account number, and a balance, positions a logo pulled from a search result, and exports a PDF or image in minutes. None of this is a flaw unique to any one design platform; it is true of most modern drag-and-drop tools. Separately, and worth keeping distinct from statement forgery, security researchers have also documented scammers abusing Canva's own file-hosting to deliver phishing links.

Two different Canva-related scams, not one. Faking the image or PDF of a bank statement inside a design tool is one technique. A separate one, documented by Pen Air Federal Credit Union, uses Canva's own trusted domain to host a file, which helps a phishing message slip past email security filters; a link inside that hosted document then redirects the victim to a fake login page built to harvest credentials. See Pen Air's write-up on the link-hosting version of this trick.

The Documents Scammers Fake Most

A handful of document types come up again and again in cases involving fabricated finances. Each one exists to answer a specific question the victim would otherwise ask before handing over money, access, or trust.

Document typeWhat it is meant to proveScam types where it shows up
Bank statement or balance screenshotAccess to money that does not actually existRomance scams, business loan and credit fraud
Proof-of-funds letterAbility to close a purchase or cover a leaseRental scams, real estate transactions
Payment confirmation screenshotThat a payment (Zelle, Venmo, Cash App) was already sentRental and marketplace scams
Invoice or wire instructionsLegitimacy of a request to redirect a paymentBusiness email compromise

The Scale of the Problem, in the FBI's Own Numbers

IC3's 2025 Internet Crime Report breaks total losses down by category, and the categories most reliant on a fabricated document all moved in the same direction: up. Business email compromise, in which a fake invoice or fake wire instruction redirects a real payment, produced 24,768 complaints and $3,046,598,558 in losses in 2025, up from $2,770,151,146 in 2024 and $2,946,830,270 in 2023. Confidence and romance fraud, where a fabricated bank balance is often the proof a scammer offers of being who they claim to be, produced 23,159 complaints and $929,287,469 in losses, up roughly 38 percent from $672,009,052 in 2024. Real estate fraud, which IC3 defines to explicitly include rental and timeshare property schemes, produced 12,368 complaints and $275,110,419 in losses, up from $173,586,820 in 2024.

Older victims absorbed a disproportionate share of this. IC3 recorded 201,266 complaints from people age 60 and older in 2025, a 37 percent increase, totaling $7.748 billion in losses, a 59 percent increase, with an average loss of $38,500 and 12,444 people who individually lost more than $100,000. Within that age group, confidence and romance fraud alone cost $584,032,745 across 10,188 complaints, business email compromise cost $568,048,472 across 4,566 complaints, and real estate fraud cost $123,671,936 across 2,473 complaints.

IC3's report also names artificial intelligence as an accelerant behind this trend. The bureau received more than 22,000 complaints in 2025 referencing AI, tied to $893,346,472 in adjusted losses. AI-linked business email compromise losses topped $30 million, with the report noting that chat generators "can quickly create official-sounding emails mimicking a company's CEO or other officials." AI-linked romance and confidence fraud losses topped $19 million, including more than $5 million tied specifically to voice-cloned distress calls impersonating a relative in trouble. AI-linked investment fraud losses reached $632,041,188, and IC3 cautions that many victims never realize how much AI was involved in the scheme that targeted them.

Case File: The Man Who Faked NFL Fame and Bank Balances

In August 2026, federal prosecutors in Oregon charged Daejon Labrayae Love and Taylor Jamie Chan with defrauding more than two dozen women out of over $1.3 million. According to the Department of Justice's press release, Love met victims through internet dating apps while posing as a San Francisco 49ers player and a wealthy real estate investor, and Chan posed as his financial adviser. The scheme ran from February 2022 through August 2026, reaching victims across Oregon, Washington, Idaho, and California.

The DOJ's own language describes the document side of the scheme directly: "Love also used phone applications to create fictitious bank and investment accounts and balances which Love showed victims to legitimize the scheme." Reporting on the underlying affidavit describes fake documents, including bank account information, shown to victims to reflect millions of dollars in supposed investment gains, and in one case a falsified payroll check showing $50,000 in monthly income for a victim identified in court records as A.T., who ultimately lost $87,500. Chan and Love also hosted three-way video calls in which they walked victims through falsified investment gains on screen.

The case is a real, recent example of exactly the pattern this article is about: a fabricated financial document, generated with ordinary consumer software rather than named by name in the charging documents, used to make an invented balance look real long enough for a victim to wire money.

That is federal charging language, not marketing copy.

Case File: Altered Bank Statements as Loan Fraud

Not every case involves a romance scam. In May 2024, a federal jury in the Southern District of Florida convicted Elaine Escoe, 39, of Delray Beach, of wire fraud for submitting altered bank statements in support of an application for a business line of credit. Per the U.S. Attorney's Office announcement, "the altered bank statements obscured the true name of the bank account along with inflated cash balances." Escoe faced up to 20 years in prison, with sentencing scheduled for August 14, 2024, before U.S. District Judge Melissa Damian. The case was announced by then-U.S. Attorney Markenzy Lapointe and investigated by the FBI's Miami field office.

No romance. No dating app. Same forged-document technique, aimed at a lender instead of a person.

An Older Precedent: Fake Letters of Credit

A 2019 case shows this is not a new technique, only a newly easy one. James Pierce, 43, of Spring, Texas, pleaded guilty in the U.S. District Court for the District of Columbia to wire fraud and conspiracy for a scheme in which he and co-conspirators falsely claimed a relationship with a Dominican Republic bank capable of issuing SWIFT messages proving victims had access to credit. According to the Justice Department's release, victims paid six-figure fees and received "fake Bank 1 documentation falsely showing that it had transmitted the promised bank instruments." When the real SWIFT confirmations never arrived, victims were fraudulently induced to pay again to have the documents "re-issued." Pierce pleaded guilty before Chief Judge Beryl A. Howell, in a case prosecuted by the Justice Department's Fraud Section and investigated by the FBI.

When the Fake Document Targets a Company, Not a Person

Business email compromise applies the same idea, a document that looks official enough to act on, to a company's accounts payable process instead of an individual's trust. In April 2026, four defendants, Kelvin Owusu Nkwantabisa (also known as Kevin Brown or "KO"), John Jouissance, Leshea Moore (also known as Deborah Green), and Justice Amoh (also known as Samuel Andrews), were sentenced to prison in the Southern District of Florida for a scheme that stole more than $38 million from victims in the United States and abroad since at least August 2022. According to the DOJ announcement, the group gained unauthorized access to victims' email accounts, monitored legitimate transactions in progress, and then impersonated trusted business partners to redirect the payments. U.S. Attorney Jason A. Reding Quiñones called it "organized international fraud carried out through deception, stolen trust, and financial manipulation," adding that "business email compromise schemes can devastate companies and individuals in a matter of hours."

No forged bank statement was needed there. A forged sense of urgency was enough.

Weeks earlier, in the Eastern District of New York, Animashaun Adebo (known as "Kazeem") pleaded guilty to wire fraud conspiracy for running a series of business email compromise and related romance schemes that caused more than $50 million in losses to individuals and small businesses in New York City and across the country, laundered through shell-company bank accounts. U.S. Attorney Joseph Nocella Jr. said, per the DOJ release, that "the defendant and his network of criminal associates perpetrated sophisticated frauds targeting victims here in Brooklyn and throughout the country," and that "schemes like these cause enormous hardship and financial losses to victims every year."

IC3's own 2025 report includes several dated, named-institution examples of exactly this pattern. In March 2025, a senior citizen in Missouri closing on a property received a spoofed email purporting to be from the title company, complete with wire instructions for over $1.3 million to a fraudulent account; the bureau's Recovery Asset Team froze the funds. In April 2025, a city government office in Oregon lost more than $6 million to a scheme using the same fraudulent recipient account, though that wire was successfully recalled. In August 2025, home buyers received an email impersonating their own closing attorneys and wired more than $449,000 before catching the fraud. Attackers running schemes like these sometimes pair a forged document with a separate account-takeover technique, including hijacking a victim's phone number, covered in our guide to SIM swap fraud, to intercept the verification codes that would otherwise stop them.

Real Statement vs. Forged Statement: What Actually Differs

None of the signals below is proof by itself, and a careful forger can strip or fake some of them. But document-forensics analysts who study forged financial paperwork describe a consistent pattern worth knowing before you rely on any statement, letter, or screenshot you did not generate yourself.

SignalWhat a genuine bank statement typically showsWhat a forged one often shows
File metadataProducer or Creator field tied to the bank's own statement systemProducer or Creator field naming a design tool, photo editor, or word processor
Transaction mathRunning balance reconciles exactly, entry by entryTotals that do not add up once you check the arithmetic line by line
TypographyConsistent kerning, alignment, and font across the whole documentSubtly mismatched fonts or spacing where text boxes were dropped in
Contact informationA number you can find independently on the bank's own website or cardA phone or account-recovery number that exists only inside the document
Independent confirmationThe bank will confirm the account and balance if you call them directlyNo channel to confirm the document except the sender who provided it

How to Verify a Bank Document Is Real

Verification does not require special software or a forensic background. It requires refusing to trust the document on its own terms and instead confirming its contents through a channel the sender does not control.

Three habits cover most of it.

Call the Bank Using a Number You Look Up Yourself

Never call a phone number printed inside the statement, letter, or email itself. Look up the bank's fraud or customer-service line independently, on the back of your own card or by typing the institution's known web address directly into your browser, and call from there before wiring money, approving a lease, or extending credit based on what the document claims.

The number in the document cannot be trusted. A phone number printed inside a forged statement, invoice, or verification email often connects to the person running the scam, not the bank. Find the number independently, then call.

Check the File's Metadata

On a computer, right-clicking a PDF and viewing its properties, or opening it in a PDF reader's document-information panel, will often show a Producer or Creator field recording the software used to generate it. A statement whose metadata names a design tool, a photo editor, or a generic word processor, instead of a bank's own document system, is a meaningful red flag. The absence of a red flag is not proof of authenticity on its own, since metadata can sometimes be stripped or altered, but its presence is a strong reason to stop and verify further before proceeding.

Ask for the Original File and Use the Bank's Verification Portal

Request the original PDF or the original email rather than a forwarded screenshot or a photo of a screen; both of those strip metadata and are simple to alter without leaving a visible trace. When money is involved, especially in a real estate closing, a business wire, or a large loan, ask the sender to have the bank transmit the document directly, or ask your own bank whether it can confirm the sending institution and account through its own back-channel verification process. Many banks and title companies now offer such portals or numbers specifically because forged wire instructions and closing documents have become common enough to require one.

A payment screenshot is not proof of payment. A "sent" confirmation from Zelle, Venmo, or Cash App uses the same fonts and layout for every user, which makes the amount and recipient name simple to alter after the fact. The only reliable confirmation that money actually moved is a matching deposit inside your own banking app, never a screenshot someone else sent you.

Where These Fakes Show Up: Rentals, Dating Apps, and Company Inboxes

Rental listings are one of the most common places a fabricated document changes hands in both directions. The FTC's December 2025 analysis found nearly 65,000 rental scams reported since 2020, totaling roughly $65 million in losses, with adults age 18 to 29 three times more likely than other adults to report losing money this way. In the 12 months ending June 2025, about half of reported rental scams originated with a fake ad on Facebook. The FTC describes fraudulent landlords pressuring renters to pay before an in-person viewing and pressuring applicants to "prove creditworthiness" by sending screenshots or signing up for paid credit-check memberships, exactly the moment where a fabricated proof-of-funds letter or a faked payment confirmation does its work in either direction.

Dating apps and social media generate a comparable volume of fabricated financial paperwork, usually built around a fictional investment. The FTC's April 2026 data put total social-media-originated scam losses at $2.1 billion in 2025, an eightfold increase since 2020, with investment scams accounting for $1.1 billion of that total. Romance scams that began on social media specifically cost victims $298 million in 2025, and nearly 60 percent of all romance-scam victims said the scam started on social media rather than a dating app. The long-running version of this con, in which a stranger builds trust over weeks before introducing a fake investment platform, is covered in detail in our explainer on pig butchering scams, and the advertising side of the same funnel, fake investment ads designed to look credible on a feed, is covered in how fake investment ads use digital marketing tricks. Once a person clicks one of those ads or profiles, the same tracking technology that powers ordinary online advertising often follows them across the web; our piece on what tracking cookies reveal about you explains how that targeting works.

The pattern extends beyond the United States. In the United Kingdom, the Financial Conduct Authority reported almost 5,000 fake-FCA scams in the first six months of 2025, 4,465 reports compared with 10,379 for all of 2024, with 480 victims sending money in that half-year alone compared with 991 for the whole of 2024. Fraudsters posing as the FCA claim to have recovered funds from an illegally opened crypto wallet in the victim's name, or offer to help recover money already lost to an earlier scam, then ask for payslips, passport copies, bank details, or online banking passwords to "process" the recovery. Nearly two-thirds of reports came from people age 56 and older. The regulator's own guidance is unambiguous: "We will never ask you to transfer money to us or for sensitive banking information such as account PINs and passwords."

The Bottom Line

Design software did not invent financial fraud, and no single prosecuted case in this article names one specific tool as the instrument of the forgery. What changed is the amount of time and skill a convincing fake now requires, which is close to none. A landlord, a romantic partner, or an accounts-payable clerk looking at a polished PDF on a phone screen has no reasonable way to tell, from the document alone, whether it came from a bank's own system or a free design template.

The fix is not learning to spot every visual tell. Some forgeries will always be good enough to pass that test.

It is refusing to act on a financial document until its contents are confirmed through a channel the sender does not control: a phone number you looked up yourself, a bank's own verification process, or the original file rather than a screenshot. IC3's $20.877 billion in reported 2025 losses, and the specific, real, named cases described here, all trace back to the same moment: someone believed a document instead of confirming it.

Key Terms Used in This Guide

Pig Butchering

A long-con scam that combines a fabricated romantic or friendly relationship with a fake investment platform, gradually escalating deposits over weeks or months before the scammer disappears with the funds.

Learn more

Business Email Compromise (BEC)

A scam in which a criminal gains access to, or convincingly spoofs, a real business email account to redirect a legitimate payment or invoice to a fraudulent account.

Learn more

SIM Swap

A fraud technique where a criminal convinces or bribes a mobile carrier employee to transfer a victim's phone number onto a SIM card the criminal controls, intercepting SMS-based verification codes.

Learn more

Was this article helpful?

Comments

Get weekly Scams & Fraud Protection tips

No spam — one email a week, unsubscribe anytime.