1/2/2024 0 Comments Reddit uploading image tool![]() On Reddit’s side - Reddit should make such verifications private, where users have to verify their identity by sending such pictures in private messages to moderators and not in public posts. A marketplace seller showcasing editable selfie with ID card A seller offering face swap and selfie making services for sale What can be done to stop potential abuse of these images Some fake id marketplaces started listing selfies with an editable ID card in hand and swappable background for sale. ![]() ![]() The image format of a person holding a piece of paper or a card in their hand is the base template of KYC verification images. A Telegram post advertising verified crypto exchange accounts for sale Marketplaces for such images Or these accounts are involved in large-scale coordinated frauds like the case of FELIXO token. These accounts are then either sold on underground markets & forums to other people who might use them to launder money or receive funds from illicit activities. Such manipulated images are used by fraudsters to generate synthetic identities, which they use to create accounts on different crypto exchanges and other platforms. These subreddits provide an endless daily supply of images for KYC fraudsters to work with. This account is usually with real KYC /cYeKswopBL- FELIXO Token Global □ July 4, 2020 Here below you can see a typical example of that.Ī typical fraudster Registers all these fake kYC documents with his referral link.Ī typical fraudster tries to collect all earned FLX in one account via FIP transfers. The attackers were using photoshopped images to create thousands of accounts to earn a referral bonus. But if they’d have used pictures of random individuals scraped from these subreddits or other similar sources, they’d have got away with it.įelixo Token detected similar incidents from KYC fraudsters in the past. They got caught in this instance because they used the same body wearing the same t-shirt. North Korean hackers photoshopped multiple faces onto the same body, wearing the same t-shirt, as part of ID images they allegedly used to try to cash out stolen cryptocurrency on exchanges that had KYC requirements. We have already seen North Korean actors photoshopping faces and ID cards on the same images to get their KYC done in crypto exchanges. Add proper lighting and glare on the picture and it should pass as legit. Various countries' editable id card PSD files on saleĪll it takes is an average skilled person to photoshop those edited PSD files in place of username paper. Most of the country’s government-issued id cards, driving licenses, and passports are easily editable PSD files that have been available in underground markets since forever. Verification pictures from these subreddits can easily be manipulated to look like verification pictures required by online services during KYC verification. Most of them were using similar format images for KYC verifications. I've come across a few KYC (Know Your Customer) image databases of small fintech, crypto companies. And in the end, I was asked to upload a selfie of myself while holding a government-issued id card for verification.Īs someone who has spent months exploring exposed S3 buckets, Azure blobs, and exposed databases. Recently I signed up for an online banking service that required me to upload a picture of myself and identity documents for signing up.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |