← Back to Blog fraud prevention

Spotting Fake POPs: How Fraudsters Edit Bank Screenshots in SA

July 01, 2026

The Growing Threat: Manipulated Proof of Payment Screenshots

In South Africa, Electronic Funds Transfers (EFTs) have become a cornerstone of daily commerce. From small businesses to large retailers, accepting EFTs is convenient for both merchants and customers. However, this convenience comes with a significant risk: proof of payment (POP) fraud. Fraudsters are increasingly sophisticated, using readily available tools to manipulate bank screenshots, making it incredibly difficult for merchants to distinguish between genuine and fake payments.

As a South African merchant or small business owner, understanding how these fraudsters operate is your first line of defence. This article will delve into the common methods used to edit bank screenshots and, more importantly, equip you with the knowledge to spot these deceptive tactics and protect your hard-earned revenue.

Why Fraudsters Manipulate Proof of Payments

The motivation behind POP manipulation is simple: to obtain goods or services without actually paying for them. With the rise of online transactions and the trust placed in digital proofs, fraudsters exploit the time lag between a payment being 'made' and funds reflecting in the recipient's account. By presenting a fake POP, they pressure merchants into releasing products or services prematurely, leaving the business out of pocket.

Common Techniques Fraudsters Use to Edit Bank Screenshots

Fraudsters employ a range of tools and techniques, from basic photo editing to more advanced methods. Here are the most prevalent:

1. Photo Editing Software (Photoshop, GIMP, Mobile Apps)

This is arguably the most common method. With software like Adobe Photoshop, GIMP (a free alternative), or even user-friendly mobile editing apps, fraudsters can alter almost any detail on a legitimate bank screenshot. They can:

  • Change Amounts: A common trick is to change a small payment amount (e.g., R100) to a much larger one (e.g., R10,000).
  • Alter Dates and Times: Modifying the transaction date to make it appear current, or adjusting the time to create a sense of urgency.
  • Edit Beneficiary/Recipient Names: Changing the recipient's name to match the merchant's business name, even if the actual payment was sent elsewhere.
  • Manipulate Sender Details: Falsifying the sender's name or account number.
  • Add Fake Reference Numbers: Inserting a reference number that wasn't part of the original transaction.

These edits can be surprisingly convincing, especially to an untrained eye. They might take a legitimate POP from a prior transaction and simply update the date, amount, and reference.

2. Browser Developer Tools ("Inspect Element")

More tech-savvy fraudsters use browser developer tools, often referred to as "Inspect Element." This allows them to temporarily modify the content displayed on a webpage (such as an online banking portal) before taking a screenshot. While the actual bank account balance or transaction history remains unchanged on the bank's servers, the visual representation on the screen can be altered to show a fake payment. For example, they might navigate to their online banking statement, use "Inspect Element" to change an old transaction's details to reflect a new, fake payment, and then take a screenshot.

3. Fake Banking App Templates or Generators

There are illicit websites and apps designed to generate realistic-looking bank POPs. These tools often mimic the interfaces of popular South African banks like FNB, Capitec, Absa, Nedbank, Standard Bank, and TymeBank. Fraudsters simply input the desired details (amount, date, reference, sender/recipient names), and the tool generates a convincing screenshot. These are particularly dangerous because they often look very polished and authentic at first glance.

4. Reusing Old, Legitimate POPs

Sometimes, fraudsters don't even create a POP from scratch. They might have an old, legitimate proof of payment from a previous transaction. They then simply edit the date, amount, and reference number to match the current transaction, hoping the merchant won't scrutinise the finer details.

How to Spot a Manipulated Proof of Payment Screenshot: Red Flags for Merchants

While fraudsters are getting better, their edits often leave subtle clues. Here's what South African merchants should look out for:

1. Visual Inconsistencies and Poor Quality

  • Mismatched Fonts or Sizes: Look closely at the font used for amounts, dates, or names. Do they match the rest of the text on the screenshot? Are they slightly bolder, thinner, or a different size? Bank systems use consistent fonts.
  • Pixelation or Blurriness: Edited areas might appear slightly pixelated, blurry, or have a different resolution compared to the rest of the screenshot. This is especially true if text has been pasted over.
  • Misaligned Text or Elements: Are the numbers or text perfectly aligned? Fraudsters sometimes struggle to get perfect alignment, leading to slight shifts or gaps.
  • Shadows or Outlines: Occasionally, you might see faint shadows or outlines around edited text, indicating it was pasted onto the image.
  • Unusual Spacing: Look for inconsistent spacing between characters or words, particularly in edited numerical values.

2. Incorrect or Missing Details

  • Wrong Bank Logos/Branding: Does the POP truly reflect the sender's bank? Sometimes fraudsters mix elements, e.g., an FNB POP with Capitec's colour scheme.
  • Incomplete Information: A legitimate POP usually includes the full sender and recipient account numbers (often partially masked), transaction reference, date, time, and the bank's logo. If any critical information is missing or looks incomplete, be suspicious.
  • Generic References: Fraudsters might use very generic references like "Payment" or "Goods" instead of the specific reference you provided.
  • Mismatched Details: Double-check the sender's name against your customer records, and ensure your account number (as the beneficiary) is correct.

3. Suspicious Timings and Pressure Tactics

  • Late Night/Weekend Payments: While possible, be extra vigilant if a POP arrives late at night, on a weekend, or a public holiday, especially if coupled with immediate demands for goods/services.
  • Urgency and Pressure: Fraudsters often try to rush you into releasing goods/services, claiming they need them urgently or that they're waiting outside. This pressure is a major red flag designed to bypass your verification process.
  • Immediate POP Request: While many customers send POPs quickly, be cautious if the POP arrives suspiciously fast after the 'payment' was supposedly made, leaving no time for processing.

4. Screenshot Anomalies

  • Cropped Awkwardly: Is the screenshot cropped in an unusual way, perhaps to hide a part that wasn't edited?
  • Photo of a Screen: Some fraudsters take a photo of their screen with their phone instead of a direct screenshot. This often results in glare, poor quality, and distorted perspectives.

Beyond Visual Inspection: Proactive Measures to Protect Your Business

While vigilance is key, manual verification can be time-consuming and prone to human error, especially for busy merchants. Relying solely on visual checks is no longer sufficient in the face of increasingly sophisticated fraud.

1. Always Verify Funds in Your Account

The golden rule: never release goods or services until the funds have *actually cleared* in your bank account. This is the most foolproof method, but often impractical for businesses needing to process orders quickly.

2. Use Unique Transaction References

For every transaction, provide your customer with a unique reference number. This makes it harder for fraudsters to reuse old POPs or generate new ones with generic references. When checking your bank statement, confirm this specific reference appears.

3. Contact Your Bank (If Time Allows)

If you're highly suspicious about a large transaction, you can call your bank (e.g., FNB, Capitec, Absa, Nedbank, Standard Bank, TymeBank) to verify if a payment was indeed made to your account. Be aware that this can be time-consuming and may not be feasible for every transaction.

4. Implement a Reliable Verification System: VeriPop

This is where technology provides a crucial advantage. Solutions like VeriPop are specifically designed for South African merchants to instantly verify the authenticity of proof of payment screenshots. Instead of relying on your eye, VeriPop uses advanced algorithms and machine learning to:

  • Detect Manipulations: Our system can identify pixel-level alterations, font inconsistencies, and other signs of editing that are invisible to the human eye.
  • Verify Against Bank Data: VeriPop can confirm whether the payment details on the screenshot align with actual bank transaction patterns, even for major South African banks like Capitec, FNB, Absa, Nedbank, Standard Bank, and TymeBank.
  • Provide Instant Results: Get real-time verification, allowing you to process legitimate orders quickly and confidently, without the risk of waiting for funds to clear.

By integrating VeriPop into your workflow, you add an essential layer of security, protecting your business from the financial losses and reputational damage caused by POP fraud.

Conclusion

Fraudsters are constantly evolving their tactics, making it increasingly challenging for South African merchants to keep up. Understanding how they edit bank screenshots – whether through Photoshop, Inspect Element, or fake generators – is crucial. By knowing the red flags and implementing robust verification processes, you can significantly reduce your vulnerability to EFT fraud.

Don't let fraudsters undermine your hard work. Stay vigilant, educate yourself, and leverage modern solutions like VeriPop to ensure every proof of payment you receive is genuinely verified, safeguarding your business for the future.

Β© 2026 VeriPop. All rights reserved.
Proudly built in South Africa